security and data integrity tool for monitoring and alerting on file & directory changes.
An extensively configurable tool providing a summary of the changes between two files or directories
In-depth comparison of files, archives, and directories
Net2PCAP is a simple network-to-pcap capture file for Linux
Hetty is an HTTP toolkit for security research
the Python-based interactive packet manipulation program & library. Supports Python 2 & Python 3
Toolbox for HPE iLO4 & iLO5 analysis
NAT-aware multipath tracerouting tool
Burp Suite Community Edition,manual tools for exploring web security. Proxy your HTTPS traffic, edit and repeat requests, decode data
Ruby command-line interface to Burp Suite's REST API
Burp Commander written in Go
Burp Automator - A Burp Suite Automation Tool.Dynamic Application Security Testing (DAST)
A collection of scripts used to interact with the Burp Rest API
obfuscated meterpreter shells
Binary code static analyser, with IDA integration
cpu_rec is a tool that recognizes cpu instructions in an arbitrary binary file. It can be used as a standalone tool, or as a plugin for binwalk
Firmware Analysis Tool
Firmware Analysis and Comparison Tool
vulnerabilities in hypervisors
American fuzzy lop is a security-oriented fuzzer that employs a novel type of compile-time instrumentation and genetic algorithms to automatically discover clean, interesting test cases that trigger new internal states in the targeted binary.
GUSTAVE is a fuzzing platform for embedded OS kernels. It is based on QEMU and AFL (and all of its forkserver siblings). It allows to fuzz OS kernels like simple applications
a bare metal (type 1) VMM (hypervisor) with a python remote control API
A tool dedicated to the research of vulnerabilities in hypervisors by creating unusual system configurations.
CollabFuzz: A Framework for Collaborative Fuzzing
a free and open source tool for investigating the Dark Web
Extract accounts info from personal pages on various sites for OSINT purpose
GitHub Recon
C2/post-exploitation framework
secures secrets used by privileged users and machine identities
The Secure Production Identity Framework For Everyone (SPIFFE) Project defines a framework and set of standards for identifying and securing communications between application services
Simple and flexible tool for managing secrets
KSOPS - A Flexible Kustomize Plugin for SOPS Encrypted Resources
GitHub’s official command line tool
HTTP Desync Attack
A production ready example Django app that's using Docker and Docker Compose
Proof of Concept Exploit for vCenter CVE-2021-21972
PyTorch package for the discrete VAE used for DALL·E
DALL·E: Creating Images from Text
OpenAI Baselines: high-quality implementations of reinforcement learning algorithms
A Deep Learning based project for colorizing and restoring old images (and video!)
Perceptual Similarity Metric and Dataset
The Ceph File System, or CephFS
Network Automation
Network Source of Truth & Network Automation Platform
Nornir plugin to enable other Nautobot network automation plugins
Pluggable multi-threaded framework with inventory management to help operate collections of devices
Mobile application testing toolkit
Serverless honeytoken
Cloud Pentesting
log analytics,SIEM
ship data to ELK, Graylog, Loggly or some other SIEM
supports TCP and TLS based network transport and message buffering
common data sources such as the Windows Eventlog, flat files and syslog
parse and generate CSV, W3C, GELF, JSON, XML and KVP formats
Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent dedicated for containerized environments written in Golang
Merlin is a cross-platform post-exploitation Command & Control server and agent written in Go.
Cobalt Strike Python API
Python tool to explore PDF files
Volatility 3: The volatile memory extraction framework