#infosec (30 Repositories)
Ranked open-source repositories tagged with #infosec, scored by pull request acceptance likelihood and maintainer engagement velocity.
12.3%
41.7h
30 repositories tagged #infosec
praetorian-inc/brutus
Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native nerva/naabu pipeline integration.
wazuh/wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
vulnersCom/nmap-vulners
Nmap NSE scripts that turn a service scan into CVEs, CVSS scores and known exploits — fingerprints software from HTTP responses and checks every detected CPE against the Vulners database.
digininja/DVWA
Damn Vulnerable Web Application (DVWA)
rderaison/bromure
Proper sandboxing for agentic coding and web browsing
reconmap/reconmap
Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With built-in command automation, output parsing, and AI‑assisted summaries, it delivers faster, more structured, and high‑quality security assessments.
rix4uni/medium-writeups
This repository updates latest Bug Bounty medium writeups every 10 minutes, https://readmedium.com/Medium_URL, https://archive.ph/Medium_URL, https://freedium.cfd/Medium_URL
rix4uni/cvemapping
This repo Gathers all available cve exploits from github.⚠️ Be careful Malware.
edoardottt/secfiles
My useful files for penetration tests, security assessments, bug bounty and other security related stuff
AndrewDryga/emisar
An MCP that lets AI tools securely connect to your infrastructure, write IaaS code, debug issues, and assist during incidents - without risking production stability. Built for security teams to approve and infrastructure teams to experience like magic.
curtbraz/PhishAPI
Comprehensive Web Based Phishing Suite for Rapid Deployment and Real-Time Alerting!
infobyte/faraday
Open Source Vulnerability Management Platform
eslam3kl/SQLiDetector
Simple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests with 14 payloads and checking for 152 regex patterns for different databases.
AnonCatalyst/Ominis-OSINT
This Python application is an OSINT (Open Source Intelligence) tool called "Ominis OSINT - Web Hunter." It performs online information gathering by querying Google for search results related to a user-inputted query. The tool extracts relevant information such as titles, URLs, and potential mentions of the query in the results.
wh0amitz/PetitPotato
Local privilege escalation via PetitPotam (Abusing impersonate privileges).
EdOverflow/bugbountyguide
Bug Bounty Guide is a launchpad for bug bounty programs and bug bounty hunters.
0xSteph/pentest-ai-agents
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.
Pnwcomputers/ULTIMATE-CYBERSECURITY-MASTER-GUIDE
This repository provides a centralized resource for operational cyber defense and offense, compiling Theory, Tools, Operating Procedures, and Step-by-Step Guides across various critical security domains. Content is sourced from industry-leading books and technical presentations, focusing on practical application rather than JUST theory.
ameenmaali/qsfuzz
qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.
pablosnt/rekono
Offensive security platform that automates attack surface discovery and vulnerability management
Roave/SecurityAdvisories
:closed_lock_with_key: Security advisories as a simple composer exclusion list, updated daily
Zyrexnn/Cybermes
Autonomous Offensive Security, Bug Bounty & Red Teaming Agent Framework powered by Hermes Agent, specialized reasoning skills, and multi-model LLM orchestration.
wh0amitz/S4UTomato
Escalate Service Account To LocalSystem via Kerberos
mufeedvh/moonwalk
Cover your tracks during Linux Exploitation by leaving zero traces on system logs and filesystem timestamps.
0xffsec/handbook
A living document for penetration testing and offensive security.
klarna-incubator/gram
Gram is Klarna's own threat model diagramming tool
Moopinger/smugglefuzz
A rapid HTTP downgrade smuggling scanner written in Go.
QubesOS/qvm-create-windows-qube
Spin up new Windows qubes quickly, effortlessly and securely on Qubes OS
mhmdiaa/second-order
Second-order subdomain takeover scanner
andreiverse/grc2
grim reaper c2