All tags
Catalogue tag

#offensive-security

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

20 records
Tagged “offensive-security”Ranked by health index
npm
91Excellenthealth index
CyberStrikeus/CyberStrike
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
TypeScript · Python★ 1,266↓ 2,624/moJul 23, 2026
AGPL-3.0Jul 23, 2026 · metrics 2.10.0
PyPI
91Excellenthealth index
usestrix/strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Python · Go · TypeScript★ 48.3KAug 5, 2026
Apache-2.0Aug 5, 2026 · metrics 2.10.0
Go
87Excellenthealth index
goshs-labs/goshs
Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP callbacks · TLS · Auth · Share links. A powerful python3 -m http.server replacement.
Go · JavaScript★ 953Aug 13, 2026
MITAug 13, 2026 · metrics 2.10.0
npm
87Excellenthealth index
pensarai/apex
AI-powered offensive security testing using autonomous agents, directly in your terminal.
TypeScript★ 307↓ 7,921/moSep 6, 2026
Apache-2.0Sep 6, 2026 · metrics 2.10.0
Go
87Excellenthealth index
praetorian-inc/brutus
Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native nerva/naabu pipeline integration.
Go★ 304Aug 7, 2026
Apache-2.0Aug 7, 2026 · metrics 2.10.0
npm
84Excellenthealth index
KeygraphHQ/shannon
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
TypeScript★ 46.4K↓ 3,414/moAug 5, 2026
AGPL-3.0Aug 5, 2026 · metrics 2.10.0
Go · PyPI
84Excellenthealth index
adithyan-ak/AgentHound
Offensive security framework for AI agent infrastructure - recon, credential looting, model exfiltration, poisoning, and attack-path analysis across MCP, A2A, gateways, and AI services. BloodHound for the agentic stack.
Go · TypeScript★ 270Aug 22, 2026
Apache-2.0Aug 22, 2026 · metrics 2.10.0
npm
78Goodhealth index
Null-Square/Null-CLi
Open-source AI pentest and compliance-readiness CLI by NullSquare.
TypeScript · JavaScript★ 81↓ 147/moAug 4, 2026
Custom licenseAug 4, 2026 · metrics 2.10.0
Go · Maven
77Goodhealth index
seqra/seqra
The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.
Kotlin · Go★ 110Jul 17, 2026
Apache-2.0Jul 17, 2026 · metrics 2.10.0
PyPI
73Goodhealth index
ASCIT31/Dark-Moon
Autonomous AI pentesting engine, continuous offensive security across web, cloud, identity, CI/CD, IaC, databases, Active Directory, Kubernetes and IoT firmware. Agentic reasoning plus real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts or creds, nothing leaves your perimeter.
Python · TypeScript · Shell★ 802Aug 4, 2026
GPL-3.0Aug 4, 2026 · metrics 2.10.0
npm
69Goodhealth index
KryptSec/oasis
Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.
TypeScript★ 29↓ 39/moAug 28, 2026
MITAug 28, 2026 · metrics 2.10.0
Go
67Goodhealth index
sayseven7/frameseven
Offensive web security scanner — OWASP Top 10 · MCP server · CLI · Go
Go★ 11Aug 8, 2026
MITAug 8, 2026 · metrics 2.10.0
Go
63Moderatehealth index
fooHQ/foojank
C2 framework for ethical hackers conducting red team and purple team engagements. Extensible. Observable. Scalable.
Go★ 4Jul 22, 2026
Apache-2.0Jul 22, 2026 · metrics 2.10.0
Go
57Moderatehealth index
puck-security/geiger
Detection tells you a key is real; geiger tells you whether it's dangerous.
Go★ 34Jul 28, 2026
MITJul 28, 2026 · metrics 2.10.0
53Moderatehealth index
0xSteph/pentest-ai-agents
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.
Shell★ 2,067Aug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
PyPI
51Moderatehealth index
infinition/Bjorn
Bjorn is a powerful network scanning and offensive security tool for the Raspberry Pi with a 2.13-inch e-Paper HAT. It discovers network targets, identifies open ports, exposed services, and potential vulnerabilities. Bjorn can perform brute force attacks, file stealing, host zombification, and supports custom attack scripts.
Python★ 6,203Aug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
PyPI
45Weakhealth index
Veedubin/AttackLM
Security AI trainer/tuner and research toolkit. Fine-tune LLMs on MITRE ATT&CK-grounded data (QLoRA, GaLore, DeepSpeed, FP8, BitNet). 24K+ training pairs, 18 sources, 100% per-record provenance. Inversion-audit harness (Carlini 2021, 2022; MUSE 2024; LiRA). Terminal GUI for SSH use. 368+ tests.
Python★ 1↓ 11K/moJul 18, 2026
Custom licenseJul 18, 2026 · metrics 2.10.0
22At Riskhealth index
Frissi0n/GTFONow
Automatic privilege escalation for misconfigured capabilities, sudo and suid binaries using GTFOBins.
Python★ 638Aug 3, 2026
MITAug 3, 2026 · metrics 2.10.0
20At Riskhealth index
mthcht/ThreatHunting-Keywords
Awesome list of keywords and artifacts for Threat Hunting sessions
PowerShell · HTML · Python★ 669Aug 4, 2026
No licenseAug 4, 2026 · metrics 2.10.0
PyPI
19Criticalhealth index
FuzzingLabs/secpipe
MCP server for AI-driven security pipelines
Python★ 803Aug 4, 2026
Custom licenseAug 4, 2026 · metrics 2.10.0