Skip to content
View psyray's full-sized avatar

Block or report psyray

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Fully autonomous AI hacker to find actual exploits in your web apps. Shannon has achieved a 96.15% success rate on the hint-free, source-aware XBOW Benchmark.

TypeScript 21,740 2,186 Updated Feb 13, 2026

An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.

Python 547 104 Updated Feb 14, 2026

A standalone and self-hosted implementation of the central server used by Ecovacs vacuum robots.

Python 8 Updated Feb 11, 2026

Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing

Python 3,000 472 Updated Jun 24, 2024

Dump LSASS via physical memory read primitives in vulnerable kernel drivers

C 254 27 Updated Feb 2, 2026

Global threat map. Learn wars, conflicts, military bases and history of nations.

TypeScript 1,198 196 Updated Feb 13, 2026

gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.

Python 329 28 Updated Jan 14, 2026

LDAP Swiss Army Knife

Java 51 8 Updated Dec 5, 2023

Browse and edit PFS filesystems on APA-formatted hard drive

C 119 24 Updated Jul 12, 2025

Agentic AI Infrastructure for magnifying HUMAN capabilities.

TypeScript 8,195 1,144 Updated Feb 10, 2026

PentestAgent is an AI agent framework for black-box security testing, supporting bug bounty, red-team, and penetration testing workflows.

Python 1,504 346 Updated Feb 13, 2026

TokenSmith generates Entra ID access & refresh tokens on offensive engagements. It is suitable for both covert adversary simulations and penetration tests with the tokens generated working out of t…

Go 379 44 Updated Jan 23, 2025

Exploit AD CS misconfiguration allowing privilege escalation and persistence from any child domain to full forest compromise

PowerShell 125 12 Updated Dec 2, 2023

A Windows Named Pipe Multi-tool / Proxy

C++ 292 20 Updated Dec 7, 2025

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Python 7,359 1,165 Updated Aug 28, 2025

AI Code Security Anti-Patterns distilled from 150+ sources to help LLMs generate safer code.

HTML 499 85 Updated Jan 21, 2026

A simple Python script to do quick, targeted recon of a given domain.

Python 68 13 Updated Apr 17, 2025

PoC Exploit for the NTLM reflection SMB flaw.

Python 674 127 Updated Feb 9, 2026

Security automation with n8n ideas: 100+ Red/Blue/AppSec workflows, integrations, and ready-to-run playbooks.

581 111 Updated Sep 20, 2025

A collection of tools to interact with Microsoft Security Response Center API

Python 113 21 Updated Jan 11, 2024

A PowerShell variant of the amazing patch_review.py by kevthehermit

PowerShell 185 21 Updated Oct 23, 2025

Simple HTTP server to list and manipulate files.

Python 5 Updated Jan 9, 2026

A collection of Vulnerability Research and Reverse Engineering writeups.

11 2 Updated Dec 20, 2025

Extracts browser-stored data such as refresh tokens, cookies, saved credentials, credit cards, autofill entries, browsing history, and bookmarks from modern Chromium-based and Gecko-based browsers …

C 531 77 Updated Jan 26, 2026

Automated OSINT on SwaggerHub

Python 243 38 Updated Jan 16, 2024

Monitor your targets and hunt fresh assets in real time.

Go 142 37 Updated Jan 14, 2026

Nuclei scripts created by @rxerium for zero days / actively exploited vulnerabilities.

Python 77 16 Updated Feb 5, 2026

Disk Usage/Free Utility - a better 'df' alternative

Go 14,758 454 Updated Jan 13, 2026

A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak sensitive device-activity patterns. (WhatsApp /…

TypeScript 4,671 636 Updated Dec 31, 2025
Next