A curated collection of 150+ tools and techniques for red teaming and penetration testing, organized by MITRE ATT&CK framework categories covering reconnaissance, initial access, execution, privilege escalation, defense evasion, credential access, lateral movement, command and control, exfiltration, and impact.
Open source. Open possibilities.
Discover quality open-source projects, submit projects anonymously, and claim and edit your own project.
A little curiosity. A world of open source.
THE FIRST COLLECTIONMaigret is an OSINT command-line tool that builds a dossier on a person from a username alone, checking 3000+ sites, extracting profile data, and exporting reports in HTML, PDF, JSON, CSV and graph formats.
A curated collection of Web Application Security payloads and bypasses for pentesting and CTFs, covering vulnerability descriptions, exploitation techniques, and Burp Intruder file sets.
Sherlock is a command-line tool that hunts down social media accounts by username across 400+ networks. It supports multiple usernames, site filtering, proxy use, and output in text, CSV, or XLSX formats, with installation via pip/pipx, Docker, or system packages.
bettercap is a Go-based, extensible security framework for reconnaissance and MITM attacks across WiFi, BLE, HID, CAN-bus, and IPv4/IPv6 networks, with a REST API, web UI, and JavaScript plugins.