red-team
Tracked open-source repos tagged red-team, sorted by stars.
- #31★ 1,607+0Star change over the last 7 days
- #32★ 1,604+1Star change over the last 7 days
- #33
GooFuzz is a tool to perform fuzzing with an OSINT approach, managing to enumerate directories, files, subdomains or parameters without leaving evidence on the target's server and by means of advanced Google searches (Google Dorking).
★ 1,583-1Star change over the last 7 days - #34★ 1,516+0Star change over the last 7 days
- #35
Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh
★ 1,224+18Star change over the last 7 days - #36
A Huge Learning Resources with Labs For Offensive Security Players
★ 1,169+2Star change over the last 7 days - #37★ 1,160+0Star change over the last 7 days
- #38
针对于红队攻击思维做出的red team模式(破限项目,封号概不负责)##可自行适配其他Agent。项目问题请提issue
★ 1,055+23Star change over the last 7 days - #39★ 1,048+2Star change over the last 7 days
- #40★ 996+2Star change over the last 7 days
- #41
Security automation with n8n ideas: 100+ Red/Blue/AppSec workflows, integrations, and ready-to-run playbooks.
★ 957+5Star change over the last 7 days - #42
PoCs and tools for investigation of Windows process execution techniques
★ 957-1Star change over the last 7 days - #43★ 948+31Star change over the last 7 days
- #44
Autonomous AI pentesting engine, continuous offensive security across web, cloud, identity, CI/CD, IaC, databases, Active Directory, Kubernetes and IoT firmware. Agentic reasoning plus real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts or creds, nothing leaves your perimeter.
★ 892+13Star change over the last 7 days - #45
evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).
★ 890+0Star change over the last 7 days - #46
An insane list of all dorks taken from everywhere from various different sources.
★ 824+1Star change over the last 7 days - #47★ 818+1Star change over the last 7 days
- #48
js cookie逆向利器:js cookie变动监控可视化工具 & js cookie hook打条件断点
★ 785-1Star change over the last 7 days - #49★ 754+137Star change over the last 7 days
- #50★ 726-1Star change over the last 7 days
- #51
Real-world AI penetration testing engineer for authorized assessments — built-in cloud module covering AWS/Azure/GCP + Aliyun/Tencent/Huawei clouds. Built on Claude Agent SDK
★ 722—Star change over the last 7 days - #52
一款证据驱动的 FOFA 资产测绘智能体:支持自然语言侦察、AI 反思、CLI / MCP / Skill / REST API,以及经人工审批的 Nuclei 扫描。
★ 720+11Star change over the last 7 days - #53
Generate and test domain typos and variations to detect and perform typo squatting, URL hijacking, phishing, and corporate espionage.
★ 692+0Star change over the last 7 days - #54
High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.
★ 691+7Star change over the last 7 days - #55
Security Auditor Utility for GraphQL APIs
★ 688+0Star change over the last 7 days - #56★ 655+0Star change over the last 7 days
- #57
Free Active Directory pentesting tool for Linux. Automates AD and LDAP enumeration, Kerberoasting, ASREPRoast, password spraying, ADCS/ESC1, DCSync, RBCD, gMSA, shadow credentials, NTLM relay and credential dumping across 104 techniques, mapping BloodHound-compatible attack paths to Domain Admin. NIS2 / ISO 27001 reports. No Windows needed.
★ 642+14Star change over the last 7 days - #58
The classic launcher, evolved. Fast, Go-based command library equipped with 200+ cybersecurity cheat-sheets. Just install and start hacking.
★ 632+10Star change over the last 7 days - #59
Fast, security-first headless browser for AI agents. Pure Rust, no Chromium or V8. Built for scraping, web testing, and red teaming, with direct HTTP traffic control and auditable sessions.
★ 628+48Star change over the last 7 days - #60
GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.
★ 588+5Star change over the last 7 days