Showing 1-28 of 561 tool(s)
Page 1 of 21
Red Team Grimoire
Red Team Operations

Red Team Grimoire

Advanced Red Team tactics and scripts crafted from real-world offensive security assessments.

DeepWeb CTI Links
Threat Intelligence

DeepWeb CTI Links

Collection of Cyber Threat Intelligence sources from the deep and dark web.

PEASS-ng
Privilege Escalation

PEASS-ng

Scripts to detect privilege escalation vectors on Windows, Linux, and macOS systems.

PyCript
Web Application Security

PyCript

Burp extension to encrypt/decrypt traffic with custom logic in Python, Go, Node.js, etc.

Pentest Mapper
Web Application Security

Pentest Mapper

Burp extension to map API flows and link them to custom security test checklists.

InterceptSuite
Web Application Security

InterceptSuite

Intercepts and inspects TLS/SSL traffic across all protocols beyond HTTP/S.

EvilTree
Security Auditing

EvilTree

Python remake of "tree" with keyword/regex search and match highlighting in files.

ipsw
Mobile Security

ipsw

CLI framework to analyze Apple firmware and interact with iOS/macOS devices.

wwwtree
Post-Exploitation

wwwtree

Tool to locate, host, and transfer exploits/scripts to victim machines during privilege escalation.

Villain
Command and Control (C2)

Villain

C2 framework for managing reverse shells and sharing sessions across Villain instances.

Post-Exploitation

Adaptix Framework

Extensible post-exploitation and adversary emulation framework for penetration testers.

Wynis
Security Auditing

Wynis

PowerShell script for auditing Windows security using BEST practices automatically.

Swego
Web Application Security

Swego

Go webserver with many features, simple like Python's SimpleHTTPServer.

Deepkfake Offensive Toolkit
Adversary Simulation

Deepkfake Offensive Toolkit

Generates real-time deepfakes for testing ID verification and social engineering scenarios.

reFlutter
Mobile Security

reFlutter

Framework for reverse engineering Flutter apps using patched lib for dynamic analysis.

GJoy Dex Analyzer
Mobile Security

GJoy Dex Analyzer

Native Dalvik bytecode decompiler for fast APK and DEX analysis without Java VM.

Deep Live Cam
AI Security

Deep Live Cam

Deepfake software for AI-generated media creation and realistic adversary simulations.

Chiasmodon
Reconnaissance and OSINT

Chiasmodon

OSINT tool to gather data from domains, apps, IPs, emails, organizations, and URL

GuardRail OSS
AI Security

GuardRail OSS

Framework enhancing AI outputs via conditional logic and emotional intelligence (AiEQ).

Social Analyzer
Reconnaissance and OSINT

Social Analyzer

Finds and analyzes user profiles on 1000+ sites with confidence-based detection scoring.

SpyNote
Mobile Security

SpyNote

SpyNote is an Android RAT malware used to spy on and control infected mobile devices.

Oblivion
Reconnaissance and OSINT

Oblivion

Monitors real-time data leaks and alerts if user credentials have been exposed.

WiFi DensePose
AI Security

WiFi DensePose

Real-time, camera-free human pose detection using WiFi CSI and machine learning.

Agent Name Service
AI Security

Agent Name Service

Secure AI agent registry based on OWASP GenAI ANS Protocol for safe agent interaction.

DSPy.ts
AI Security

DSPy.ts

AI framework in JS/TS for building smart, private apps directly in the browser.

FACT
AI Security

FACT

MCP tool replacing vectors with prompts for fast, auditable LLM-powered data retrieval.

HosTaGe
Mobile Security

HosTaGe

Lightweight honeypot to detect malicious networks on mobile devices like smartphones.

CAIDO
Web Application Security

CAIDO

Modern, lightweight web security proxy with clean UI and modular design for web testing.

GPT - RedTeam.Blue