全部标签
目录标签

#offensive-security

公开记录中带有此标签的全部仓库——标签来自其 GitHub 主题或软件包注册表发布的关键词。健康度量遵循与记录其余部分相同的版本化方法论。

20 条记录
标签为“offensive-security”按健康指数排序
npm
91优秀健康指数
CyberStrikeus/CyberStrike
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
TypeScript · Python★ 1,266↓ 2,624/月2026年7月23日
AGPL-3.02026年7月23日 · 指标 2.10.0
PyPI
91优秀健康指数
usestrix/strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Python · Go · TypeScript★ 48.3K2026年8月5日
Apache-2.02026年8月5日 · 指标 2.10.0
Go
87优秀健康指数
goshs-labs/goshs
Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP callbacks · TLS · Auth · Share links. A powerful python3 -m http.server replacement.
Go · JavaScript★ 9532026年8月13日
MIT2026年8月13日 · 指标 2.10.0
npm
87优秀健康指数
pensarai/apex
AI-powered offensive security testing using autonomous agents, directly in your terminal.
TypeScript★ 307↓ 7,921/月2026年9月6日
Apache-2.02026年9月6日 · 指标 2.10.0
Go
87优秀健康指数
praetorian-inc/brutus
Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native nerva/naabu pipeline integration.
Go★ 3042026年8月7日
Apache-2.02026年8月7日 · 指标 2.10.0
npm
84优秀健康指数
KeygraphHQ/shannon
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
TypeScript★ 46.4K↓ 3,414/月2026年8月5日
AGPL-3.02026年8月5日 · 指标 2.10.0
Go · PyPI
84优秀健康指数
adithyan-ak/AgentHound
Offensive security framework for AI agent infrastructure - recon, credential looting, model exfiltration, poisoning, and attack-path analysis across MCP, A2A, gateways, and AI services. BloodHound for the agentic stack.
Go · TypeScript★ 2702026年8月22日
Apache-2.02026年8月22日 · 指标 2.10.0
npm
78良好健康指数
Null-Square/Null-CLi
Open-source AI pentest and compliance-readiness CLI by NullSquare.
TypeScript · JavaScript★ 81↓ 147/月2026年8月4日
自定义许可证2026年8月4日 · 指标 2.10.0
Go · Maven
77良好健康指数
seqra/seqra
The open source taint analysis engine for the AI era. A formal dataflow analysis tool you can customize and self-host, built so AI agents drive your application security analysis without burning tokens on every scan. AI-ready open source alternative to Semgrep Pro and CodeQL.
Kotlin · Go★ 1102026年7月17日
Apache-2.02026年7月17日 · 指标 2.10.0
PyPI
73良好健康指数
ASCIT31/Dark-Moon
Autonomous AI pentesting engine, continuous offensive security across web, cloud, identity, CI/CD, IaC, databases, Active Directory, Kubernetes and IoT firmware. Agentic reasoning plus real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts or creds, nothing leaves your perimeter.
Python · TypeScript · Shell★ 8022026年8月4日
GPL-3.02026年8月4日 · 指标 2.10.0
npm
69良好健康指数
KryptSec/oasis
Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.
TypeScript★ 29↓ 39/月2026年8月28日
MIT2026年8月28日 · 指标 2.10.0
Go
67良好健康指数
sayseven7/frameseven
Offensive web security scanner — OWASP Top 10 · MCP server · CLI · Go
Go★ 112026年8月8日
MIT2026年8月8日 · 指标 2.10.0
Go
63中等健康指数
fooHQ/foojank
C2 framework for ethical hackers conducting red team and purple team engagements. Extensible. Observable. Scalable.
Go★ 42026年7月22日
Apache-2.02026年7月22日 · 指标 2.10.0
Go
57中等健康指数
puck-security/geiger
Detection tells you a key is real; geiger tells you whether it's dangerous.
Go★ 342026年7月28日
MIT2026年7月28日 · 指标 2.10.0
53中等健康指数
0xSteph/pentest-ai-agents
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.
Shell★ 2,0672026年8月4日
MIT2026年8月4日 · 指标 2.10.0
PyPI
51中等健康指数
infinition/Bjorn
Bjorn is a powerful network scanning and offensive security tool for the Raspberry Pi with a 2.13-inch e-Paper HAT. It discovers network targets, identifies open ports, exposed services, and potential vulnerabilities. Bjorn can perform brute force attacks, file stealing, host zombification, and supports custom attack scripts.
Python★ 6,2032026年8月4日
MIT2026年8月4日 · 指标 2.10.0
PyPI
45薄弱健康指数
Veedubin/AttackLM
Security AI trainer/tuner and research toolkit. Fine-tune LLMs on MITRE ATT&CK-grounded data (QLoRA, GaLore, DeepSpeed, FP8, BitNet). 24K+ training pairs, 18 sources, 100% per-record provenance. Inversion-audit harness (Carlini 2021, 2022; MUSE 2024; LiRA). Terminal GUI for SSH use. 368+ tests.
Python★ 1↓ 11K/月2026年7月18日
自定义许可证2026年7月18日 · 指标 2.10.0
22存在风险健康指数
Frissi0n/GTFONow
Automatic privilege escalation for misconfigured capabilities, sudo and suid binaries using GTFOBins.
Python★ 6382026年8月3日
MIT2026年8月3日 · 指标 2.10.0
20存在风险健康指数
mthcht/ThreatHunting-Keywords
Awesome list of keywords and artifacts for Threat Hunting sessions
PowerShell · HTML · Python★ 6692026年8月4日
无许可证2026年8月4日 · 指标 2.10.0
PyPI
19危急健康指数
FuzzingLabs/secpipe
MCP server for AI-driven security pipelines
Python★ 8032026年8月4日
自定义许可证2026年8月4日 · 指标 2.10.0