PyPI · Go · npm94Exceptionalhealth index
Python · Cypher★ 5,348↓ 7,794/moAug 28, 2026
npm91Excellenthealth index
CyberStrikeus/CyberStrikeOpen-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
TypeScript · Python★ 1,266↓ 2,624/moJul 23, 2026
Go · Maven91Excellenthealth index
praetorian-inc/titusHigh-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.
Go · Java★ 638Jul 19, 2026
PyPI91Excellenthealth index

usestrix/strixOpen-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Python · Go · TypeScript★ 48.3KAug 5, 2026
npm · RubyGems90Excellenthealth index

dradis/dradis-ceDradis Framework: Collaboration and reporting for IT Security teams
Ruby · HTML★ 841Sep 5, 2026
npm88Excellenthealth index

asamassekou10/ship-safeCLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript★ 830↓ 5,893/moSep 6, 2026
Go87Excellenthealth index

goshs-labs/goshsFeature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP callbacks · TLS · Auth · Share links. A powerful python3 -m http.server replacement.
Go · JavaScript★ 953Aug 13, 2026
npm87Excellenthealth index

pensarai/apexAI-powered offensive security testing using autonomous agents, directly in your terminal.
TypeScript★ 307↓ 7,921/moSep 6, 2026
Go87Excellenthealth index

praetorian-inc/brutusFast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native nerva/naabu pipeline integration.
Go★ 304Aug 7, 2026
npm84Excellenthealth index

KeygraphHQ/shannonShannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
TypeScript★ 46.4K↓ 3,414/moAug 5, 2026
PyPI83Excellenthealth index
Python★ 6,698↓ 917/moAug 29, 2026
Go · npm83Excellenthealth index
xalgord/xalgorixAutonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.
Go · TypeScript★ 768Jul 17, 2026
RubyGems81Excellenthealth index

0dayInc/pwnPWN is an open security automation framework that aims to stand on the shoulders of security giants, promoting trust and innovation.
Ruby★ 78Sep 5, 2026
TypeScript · JavaScript★ 81↓ 147/moAug 4, 2026
PyPI · crates.io78Goodhealth index
Python★ 14.6K↓ 32.4K/moAug 19, 2026
Go★ 1,045Jul 30, 2026
Python · JavaScript★ 1,093↓ 188/moJul 17, 2026
RAJANAGORI/NightingaleNightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes preconfigured with all essential tools and utilities required for efficient Vulnerability Assessment and Penetration Testing (VAPT), streamlining the setup process for security professionals.
Dockerfile · Shell · Python★ 313Aug 4, 2026
Go★ 3Sep 5, 2026
go-appsec/toolboxCollaborative application security testing between humans and agents via CLI and MCP
Go★ 37Jul 17, 2026
ASCIT31/Dark-MoonAutonomous AI pentesting engine, continuous offensive security across web, cloud, identity, CI/CD, IaC, databases, Active Directory, Kubernetes and IoT firmware. Agentic reasoning plus real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts or creds, nothing leaves your perimeter.
Python · TypeScript · Shell★ 802Aug 4, 2026

zan8in/afrogA Security Tool for Bug Bounty, Pentest and Red Teaming.
Go · HTML★ 4,371Aug 28, 2026
TypeScript★ 9↓ 15K/moSep 5, 2026

KryptSec/oasisOpen-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.
TypeScript★ 29↓ 39/moAug 28, 2026
Go★ 3Jul 17, 2026

mukul975/Anthropic-Cybersecurity-Skills817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Python★ 27.3KAug 5, 2026
Go★ 11Aug 8, 2026
Dockerfile · HTML · CSS★ 2,738Aug 4, 2026
ddddddO/packemonPacket monster (っ‘-’)╮=͟͟͞͞◒ ヽ( '-'ヽ) TUI tool for sending packets of arbitrary input and monitoring packets on any network interfaces (default: eth0). Windows/macOS/Linux
Go★ 305Jul 20, 2026
npm62Moderatehealth index

Hyperyond/HoverOpen-source Vibe Testing suite: an MCP server for the coding agent you already run, a VS Code review cockpit, and CI. Your agent explores your app and crystallizes each flow into a plain @playwright/test spec you own — record == replay, runs in CI with zero AI.
TypeScript★ 11↓ 742/moSep 5, 2026