Highlights
-
securevibes Public
A security system to protect your vibecoded apps
-
cyber-safari Public
A fun POC that is built to understand AI security agents.
-
-
DVWA Public
Forked from digininja/DVWADamn Vulnerable Web Application (DVWA)
PHP GNU General Public License v3.0 UpdatedJun 19, 2025 -
-
appsec-ai-artifacts Public
A repo that contains some sample artifacts
-
kubebot Public
A security testing Slackbot built with a Kubernetes backend on the Google Cloud Platform
-
nuclei Public
Forked from projectdiscovery/nucleiFast and customizable vulnerability scanner based on simple YAML based DSL.
Go MIT License UpdatedFeb 8, 2023 -
-
-
django-DefectDojo Public
Forked from DefectDojo/django-DefectDojoDefectDojo is a DevSecOps and vulnerability management tool.
-
-
brutesubs Public
An automation framework for running multiple open sourced subdomain bruteforcing tools (in parallel) using your own wordlists via Docker Compose
-
tko-subs Public
A tool that can help detect and takeover subdomains with dead DNS records
-
SonarSearch Public
Forked from Cgboal/SonarSearchA MongoDB importer and API for Project Sonars DNS datasets
-
-
charts Public
Forked from helm/chartsCurated applications for Kubernetes
Go Apache License 2.0 UpdatedDec 18, 2019 -
Amass Public
Forked from owasp-amass/amassIn-depth DNS Enumeration and Network Mapping
-
git-all-secrets Public
A tool to capture all the git secrets by leveraging multiple open source git searching tools
-
goaltdns Public
Forked from subfinder/goaltdnsA permutation generation tool written in golang
-
goGetBucket Public
Forked from eur0pa/goGetBucketA penetration testing tool to enumerate and analyse Amazon S3 Buckets owned by a domain.
-
repo-supervisor Public
Forked from okta-graveyard/repo-supervisorScan your code for security misconfiguration, search for passwords and secrets. 🔍
-
subfinder Public
Forked from projectdiscovery/subfinderSubFinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing.
-
-
action-builder Public
Forked from stingaa/action-builderA collection of GitHub Actions that can be used to automate the testing, building, and deployment of custom GitHub Actions using workflows
-
WAScan Public
Forked from infosecsecurity/SpaghettiWAScan - Web Application Scanner
-
SSRFmap Public
Forked from swisskyrepo/SSRFmapAutomatic SSRF fuzzer and exploitation tool
-
wfuzz Public
Forked from xmendez/wfuzzWeb application fuzzer
-
snallygaster Public
Forked from hannob/snallygasterTool to scan for secret files on HTTP servers
-
serverless_toolkit Public
Forked from ropnop/serverless_toolkitA collection of useful Serverless functions I use when pentesting