Skip to main content
buildradar
Sign in
Topic · red-team

red-team

Tracked open-source repos tagged red-team, sorted by stars.

68 repos
  • gitjacker@liamg

    🔪 :octocat: Leak git repositories from misconfigured websites

    1,607+0Star change over the last 7 days
  • inventory@trickest

    Asset inventory of over 800 public bug bounty programs.

    1,604+1Star change over the last 7 days
  • GooFuzz@m3n0sd0n4ld

    GooFuzz is a tool to perform fuzzing with an OSINT approach, managing to enumerate directories, files, subdomains or parameters without leaving evidence on the target's server and by means of advanced Google searches (Google Dorking).

    1,583-1Star change over the last 7 days
  • Goby@gobysec

    Attack surface mapping

    1,516+0Star change over the last 7 days
  • recon-skills@uphiago

    Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh

    1,224+18Star change over the last 7 days
  • A Huge Learning Resources with Labs For Offensive Security Players

    1,169+2Star change over the last 7 days
  • DeimosC2@DeimosC2

    DeimosC2 is a Golang command and control framework for post-exploitation.

    1,160+0Star change over the last 7 days
  • codex-redteam-mode@chAng-L19

    针对于红队攻击思维做出的red team模式(破限项目,封号概不负责)##可自行适配其他Agent。项目问题请提issue

    1,055+23Star change over the last 7 days
  • resolvers@trickest

    The most exhaustive list of reliable DNS resolvers.

    1,048+2Star change over the last 7 days
  • KubeHound@DataDog

    Tool for building Kubernetes attack paths

    996+2Star change over the last 7 days
  • Security automation with n8n ideas: 100+ Red/Blue/AppSec workflows, integrations, and ready-to-run playbooks.

    957+5Star change over the last 7 days
  • TangledWinExec@daem0nc0re

    PoCs and tools for investigation of Windows process execution techniques

    957-1Star change over the last 7 days
  • GhostESP@GhostESP-Revival

    The open-source wireless research platform for ESP32.

    948+31Star change over the last 7 days
  • Dark-Moon@ASCIT31

    Autonomous AI pentesting engine, continuous offensive security across web, cloud, identity, CI/CD, IaC, databases, Active Directory, Kubernetes and IoT firmware. Agentic reasoning plus real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts or creds, nothing leaves your perimeter.

    892+13Star change over the last 7 days
  • evilwaf@matrixleons

    evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

    890+0Star change over the last 7 days
  • An insane list of all dorks taken from everywhere from various different sources.

    824+1Star change over the last 7 days
  • Sandman@Idov31

    Sandman is a NTP based backdoor for hardened networks.

    818+1Star change over the last 7 days
  • js cookie逆向利器:js cookie变动监控可视化工具 & js cookie hook打条件断点

    785-1Star change over the last 7 days
  • numasec@FrancescoStabile

    The AI Agent for Cyber Security.

    754+137Star change over the last 7 days
  • Red-Team-Exercises@JoasASantos
    726-1Star change over the last 7 days
  • cain-agent@cdxiaodong

    Real-world AI penetration testing engineer for authorized assessments — built-in cloud module covering AWS/Azure/GCP + Aliyun/Tencent/Huawei clouds. Built on Claude Agent SDK

    722Star change over the last 7 days
  • FofaMap@asaotomo

    一款证据驱动的 FOFA 资产测绘智能体:支持自然语言侦察、AI 反思、CLI / MCP / Skill / REST API,以及经人工审批的 Nuclei 扫描。

    720+11Star change over the last 7 days
  • urlcrazy@urbanadventurer

    Generate and test domain typos and variations to detect and perform typo squatting, URL hijacking, phishing, and corporate espionage.

    692+0Star change over the last 7 days
  • titus@praetorian-inc

    High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

    691+7Star change over the last 7 days
  • graphql-cop@dolevf

    Security Auditor Utility for GraphQL APIs

    688+0Star change over the last 7 days
  • KoviD@carloslack

    Red-Team LKM

    655+0Star change over the last 7 days
  • adscan@ADScanPro

    Free Active Directory pentesting tool for Linux. Automates AD and LDAP enumeration, Kerberoasting, ASREPRoast, password spraying, ADCS/ESC1, DCSync, RBCD, gMSA, shadow credentials, NTLM relay and credential dumping across 104 techniques, mapping BloodHound-compatible attack paths to Domain Admin. NIS2 / ISO 27001 reports. No Windows needed.

    642+14Star change over the last 7 days
  • arsenal-ng@halilkirazkaya

    The classic launcher, evolved. Fast, Go-based command library equipped with 200+ cybersecurity cheat-sheets. Just install and start hacking.

    632+10Star change over the last 7 days
  • h5i@h5i-dev

    Fast, security-first headless browser for AI agents. Pure Rust, no Chromium or V8. Built for scraping, web testing, and red teaming, with direct HTTP traffic control and auditable sessions.

    628+48Star change over the last 7 days
  • gato-x@AdnaneKhan

    GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.

    588+5Star change over the last 7 days
← Back to topics