Links
Duas listas: os repositórios que marco com estrela no GitHub, organizados por categoria (automático), e ferramentas externas que uso no dia a dia (curadas à mão).
Repos que sigo
Gerado a partir das minhas estrelas do GitHub pelo star-organizer; este site serve um snapshot versionado — a data ao lado diz de quando. como isto é gerado →
Isto é um hub pessoal: organizo-o para o meu uso diário, e deixo-o aberto a quem quiser explorar.
AI & LLM Tooling
97 repos
AI & LLM Tooling
97 reposollama/ollama
Get up and running with Kimi-K2.6, GLM-5.1, MiniMax, DeepSeek, gpt-oss, Qwen, Gemma and other models.
f/prompts.chat
f.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source — self-host for your organization with complete privacy.
open-webui/open-webui
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
anthropics/claude-code
Agentic coding tool that lives in your terminal, understands your codebase
garrytan/gstack
Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Manager, Doc Engineer, and QA
microsoft/generative-ai-for-beginners
21 Lessons, Get Started Building with Generative AI
TauricResearch/TradingAgents
TradingAgents: Multi-Agents LLM Financial Trading Framework
OpenHands/OpenHands
OpenHands: AI-Driven Development
addyosmani/agent-skills
Production-grade engineering skills for AI coding agents.
nomic-ai/gpt4all
GPT4All: Run Local LLMs on Any Device. Open-source and available for commercial use.
bytedance/deer-flow
An open-source long-horizon SuperAgent harness that researches, codes, and creates
openai/openai-cookbook
Examples and guides for using the OpenAI API
Egonex-AI/Understand-Anything
Turn any code into an interactive knowledge graph you can explore, search, and ask questions about. Works with Claude Code, Codex, Cursor, Copilot, Gemini CLI.
zylon-ai/private-gpt
Complete API layer for private AI applications on local models: RAG, skills, tools, MCP, text-to-sql, and more. Works with any OpenAI-compatible inference server.
crewAIInc/crewAI
Framework for orchestrating role-playing, autonomous AI agents. By fostering collaborative intelligence, CrewAI empowers agents to work together seamlessly, tackling complex tasks.
aaif-goose/goose
an open source, extensible AI agent that goes beyond code suggestions - install, execute, edit, and test with any LLM
anthropics/claude-cookbooks
A collection of notebooks/recipes showcasing some fun and effective ways of using Claude
Aider-AI/aider
aider is AI pair programming in your terminal
janhq/jan
Jan is an open source alternative to ChatGPT that runs 100% offline on your computer.
danielmiessler/Fabric
Fabric is an open-source framework for augmenting humans using AI.
danny-avila/LibreChat
Enhanced ChatGPT Clone: Features Agents, MCP, Skills, DeepSeek, Anthropic, AWS, OpenAI, Azure, Groq, Mistral, OpenRouter, Vertex AI, Gemini, Artifacts, AI model switching
openclaw/openclaw
Your own personal AI assistant. Any OS. Any Platform. The lobster way.
HKUDS/LightRAG
[EMNLP2025] LightRAG: Simple and Fast Retrieval-Augmented Generation
heygen-com/hyperframes
Write HTML. Render video. Built for agents.
ashishpatel26/500-AI-Agents-Projects
The 500 AI Agents Projects is a curated collection of AI agent use cases across various industries. It showcases practical applications and provides links to open-source projects for implementation.
blader/humanizer
Claude Code skill that removes signs of AI-generated writing from text
supermemoryai/supermemory
Memory and context engine + app that is extremely fast, scalable, and can be run fully locally. The Memory API for the AI era.
JCodesMore/ai-website-cloner-template
Clone any website with one command using AI coding agents
eyaltoledano/claude-task-master
An AI-powered task-management system you can drop into Cursor, Lovable, Windsurf, Roo, and others.
HKUDS/DeepTutor
DeepTutor: Lifelong Personalized Tutoring
mukul975/Anthropic-Cybersecurity-Skills
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 · agentskills.io standard
obra/superpowers
Agentic skills framework & software development methodology
VoltAgent/awesome-claude-code-subagents
A collection of 100+ specialized Claude Code subagents covering a wide range of development use cases
affaan-m/ECC
The agent harness performance optimization system
karpathy/llm-council
LLM Council works together to answer your hardest questions
czlonkowski/n8n-mcp
A MCP for Claude Desktop / Claude Code / Windsurf / Cursor to build n8n workflows for you
NousResearch/hermes-agent
The agent that grows with you
snarktank/ralph
Autonomous AI agent loop that runs repeatedly until all PRD items are complete
multica-ai/andrej-karpathy-skills
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
RightNow-AI/openfang
Open-source Agent Operating System
danielmiessler/LifeOS
General Purpose AI Harness for magnifying human capabilities
anthropics/skills
Public repository for Agent Skills
hardikpandya/stop-slop
A skill file for removing AI tells from prose
Arindam200/awesome-ai-apps
A collection of projects showcasing RAG, agents, workflows, and other AI use cases
msitarzewski/agency-agents
A complete AI agency at your fingertips
NVIDIA/SkillSpector
Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks.
contains-studio/agents
sharing current agents in use
Piebald-AI/claude-code-system-prompts
All parts of Claude Code's system prompt, 27 builtin tool descriptions, sub agent prompts (Plan/Explore/Task), utility prompts.
NangoHQ/nango
Build product integrations with AI.
nextlevelbuilder/ui-ux-pro-max-skill
An AI SKILL that provide design intelligence for building professional UI/UX multiple platforms
aliasrobotics/cai
Cybersecurity AI (CAI), the framework for AI Security
karpathy/autoresearch
AI agents running research on single-GPU nanochat training automatically
thedotmack/claude-mem
Persistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions.
Graphify-Labs/graphify
AI coding assistant skill (Claude Code, Codex, OpenCode, Cursor, Gemini CLI, and more). Turn any folder of code, SQL schemas, R scripts, shell scripts, docs, papers, images, or videos into a queryable graph.
HKUDS/ClawWork
ClawWork: OpenClaw as Your AI Coworker
gsd-build/gsd-2
A powerful meta-prompting, context engineering and spec-driven development system that enables agents to work for long periods of time autonomously without losing track of the big picture
paperclipai/paperclip
The open-source app everyone uses to manage agents at work
shareAI-lab/learn-claude-code
Bash is all you need - A nano claude code–like agent harness
gsd-build/get-shit-done
A light-weight and powerful meta-prompting, context engineering and spec-driven development system
shanraisshan/claude-code-best-practice
from vibe coding to agentic engineering - practice makes claude perfect
trailofbits/skills
Trail of Bits Claude Code skills for security research and vulnerability detection
wassupjay/n8n-free-templates
A curated set of 200+ plug-and-play n8n workflows that fuse classic automation with today's AI stack—vector DBs, embeddings, and LLMs.
mvanhorn/last30days-skill
AI agent skill that researches any topic across Reddit, X, YouTube, HN, Polymarket, and the web - then synthesizes a grounded summary
potpie-ai/potpie
Context Graph for AI Native SDLC
jgraph/drawio-mcp
drawio MCP server
abhigyanpatwari/GitNexus
GitNexus: The Zero-Server Code Intelligence Engine
tradesdontlie/tradingview-mcp
AI-assisted TradingView chart analysis — connect Claude Code to your TradingView Desktop for personal workflow automation
kepano/obsidian-skills
Agent skills for Obsidian. Teach your agent to use Obsidian CLI and open formats including Markdown, Bases, JSON Canvas.
shuvonsec/claude-bug-bounty
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
m1guelpf/chatgpt-telegram
Run your own GPTChat Telegram bot, with a single command!
anthropics/financial-services
Anthropic financial services cookbook
breferrari/obsidian-mind
An Obsidian vault that gives AI coding agents persistent memory. Claude Code, Codex CLI, Gemini CLI.
gadievron/raptor
Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent
AmintaCCCP/GithubStarsManager
AI-powered GitHub stars manager with semantic search, auto-categorization, and release tracking
awslabs/agentcore-samples
Amazon Bedrock Agentcore accelerates AI agents into production
nowork-studio/NotFair
Open-source Claude Code skills for SEO, GEO, Google Ads, Meta Ads
ericosiu/ai-marketing-skills
Open-source AI marketing skills — growth experiments, sales pipeline, content ops, outbound, SEO, and finance automation
SnailSploit/Claude-Red
claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology.
anthropics/claude-agent-sdk-demos
Claude Code SDK Demos
rohitg00/awesome-claude-code-toolkit
The most comprehensive toolkit for Claude Code -- 135 agents, 35 curated skills, 42 commands, 176+ plugins, 20 hooks, 15 rules, 7 templates, 14 MCP configs, 26 companion apps, 52 ecosystem entries
trailofbits/claude-code-config
Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits
supermemoryai/supermemory-mcp
Your memories are in ChatGPT... But nowhere else. Universal Memory MCP makes your memories available to every single LLM.
microsoft/azure-skills
Official agent plugin providing skills and MCP server configurations for Azure scenarios.
mbrg/power-pwn
An offensive/defense security toolset for discovery, recon and ethical assessment of AI Agents
mattprusak/autoresearch-genealogy
Structured prompts, vault templates, and archive guides for AI-assisted genealogy research. Built for Claude Code.
JoasASantos/n8n-CyberSecurity-Workflows
Security automation with 100+ Red/Blue/AppSec workflows and playbooks
danielmiessler/Substrate
An Open-source Framework for Human Understanding, Meaning, and Progress.
avinash201199/free-ai-agents-resources
Free AI Agents Resources – Your All-in-One 2026 Learning Hub
shannhk/hermes-agent-control-room
Control Room-first template for managing Hermes agents from one VPS agent to specialist teams and orchestrated workflows
automateyournetwork/netclaw
An AI agent that claws through your network
carlvellotti/claude-code-everyone-course
Claude Code for Everyone - Learn Claude Code in Claude Code
MHaggis/Security-Detections-MCP
MCP to help Defenders Detection Engineer Harder and Smarter
bobek-balinek/claude-lamp
Claude hooks integration with Moonside lamps
SCStelz/security-investigator
Automated security investigation tool using Microsoft MCP Servers, GitHub Copilot, Python Modules and custom copilot-instructions.
antropos17/Aegis
Open-source EDR for AI agents
cyberbuff/atomic-red-team-mcp
MCP server for Atomic Red Team
ugurkocde/AgentsForAdmins
Community-driven catalog of ready-to-use agents for the Security Copilot portal.
Security · Defensive
85 repos
Security · Defensive
85 reposdanielmiessler/SecLists
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, and more.
trufflesecurity/trufflehog
Find, verify, and analyze leaked credentials
deviantony/docker-elk
The Elastic stack (ELK) powered by Docker and Compose.
wazuh/wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
semgrep/semgrep
Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.
awslabs/git-secrets
Prevents you from committing secrets and credentials into git repositories
redcanaryco/atomic-red-team
Small and highly portable detection tests based on MITRE's ATT&CK.
SigmaHQ/sigma
Main Sigma Rule Repository
telekom-security/tpotce
T-Pot - The All In One Multi Honeypot Platform
zeek/zeek
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know
Cisco-Talos/clamav
ClamAV - antivirus engine
openbao/openbao
Software solution to manage, store, and distribute sensitive data including secrets and certificates
decalage2/awesome-security-hardening
A collection of awesome security hardening guides, tools and other resources
OISF/suricata
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community
cowrie/cowrie
Cowrie SSH/Telnet Honeypot
undergroundwires/privacy.sexy
Open-source tool to enforce privacy & security best-practices on Windows, macOS and Linux, because privacy is sexy
SwiftOnSecurity/sysmon-config
Sysmon configuration file template with default high-quality event tracing
ossec/ossec-hids
OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response
clong/DetectionLab
Automate the creation of a lab environment complete with security tooling and logging best practices
DefectDojo/django-DefectDojo
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
intuitem/ciso-assistant-community
CISO Assistant is a one-stop-shop GRC platform for Risk Management, AppSec, Compliance & Audit, TPRM, BIA, Privacy, and Reporting.
DependencyTrack/dependency-track
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
Cyb3rWard0g/HELK
The Hunting ELK
snort3/snort3
Snort++
salesforce/ja3
JA3 is a standard for creating SSL client fingerprints in an easy to produce and shareable way.
olafhartong/sysmon-modular
A repository of sysmon configuration modules
thinkst/opencanary
Modular and decentralised honeypot
NextronSystems/APTSimulator
A toolset to make a system look as if it was the victim of an APT attack
rbsec/sslscan
sslscan tests SSL/TLS enabled services to discover supported cipher suites
splunk/attack_range
A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk
activecm/rita-legacy
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
drk1wi/Portspoof
Portspoof
tsale/EDR-Telemetry
This project aims to compare and evaluate the telemetry of various EDR products.
Neo23x0/auditd
Best Practice Auditd Configuration
cisagov/cset
Cybersecurity Evaluation Tool
scipag/HardeningKitty
HardeningKitty - Checks and hardens your Windows configuration
chenjj/espoofer
An email spoofing testing tool that aims to bypass SPF/DKIM/DMARC and forge DKIM signatures.
Bert-JanP/Hunting-Queries-Detection-Rules
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
trailofbits/buttercup
Buttercup finds and patches software vulnerabilities
SecurityRiskAdvisors/VECTR
VECTR is a tool that facilitates tracking of your red and blue team testing activities to measure detection and prevention capabilities across different attack scenarios
OTRF/OSSEM
Open Source Security Events Metadata (OSSEM)
PlumHound/PlumHound
Bloodhound Reporting for Blue and Purple Teams
subat0mik/Misconfiguration-Manager
Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive and hardening guidance.
BinaryDefense/artillery
The Artillery Project is an open-source blue team tool designed to protect Linux and Windows operating systems through multiple methods.
ScarredMonk/SysmonSimulator
Sysmon event simulation utility for testing EDR detections and correlation rules.
scythe-io/purple-team-exercise-framework
Purple Team Exercise Framework
PHPIDS/PHPIDS
PHPIDS (PHP-Intrusion Detection System) is a simple to use, well structured, fast and state-of-the-art security layer for your PHP based web application
cyberdefenders/email-header-analyzer
E-Mail Header Analyzer
0x4D31/galah
An LLM-powered web honeypot.
OTRF/Microsoft-Sentinel2Go
Microsoft Sentinel2Go is an open source project developed to expedite the deployment of a Microsoft Sentinel research lab.
peasead/elastic-container
Stand up a simple Elastic container with Kibana, Fleet, and the Detection Engine
salesforce/hassh
HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations.
NextronSystems/ransomware-simulator
Ransomware simulator written in Golang
sublime-security/emailrep.io
emailrep.io Public API
srlabs/Certiception
An ADCS honeypot to catch attackers in your internal network.
narbehaj/ssl-checker
Python script that collects SSL/TLS information from hosts
DefensiveOrigins/AtomicPurpleTeam
Atomic Purple Team Framework and Lifecycle
redcanaryco/AtomicTestHarnesses
Public Repo for Atomic Test Harness
Cisco-Talos/DECEIVE
DECeption with Evaluative Integrated Validation Engine (DECEIVE): Let an LLM do all the hard honeypot work!
sametsazak/mergen
Mergen is an open-source, native macOS application for auditing and checking the security of your MacOS.
opendns/Security_Ninjas_AppSec_Training
OpenDNS application security training program
internetstandards/Internet.nl
Internet standards compliance test suite
HackingLZ/IndicatorOfCanary
Canary Detection
tolgadevsec/Awesome-Deception
An awesome list of resources on deception-based security with honeypots and honeytokens
internetstandards/toolbox-wiki
Internet.nl toolbox - how-to's for modern mail security standards (DMARC, DKIM, SPF and DANE)
coolstartnow/isms-builder
Self-hosted Information Security Management System — ISO 27001, NIS2, GDPR/DSGVO, BSI IT-Grundschutz
yuriskinfo/Fortinet-tools
Tools to help you with daily tasks of configuring/debugging/monitoring Fortinet products - Fortigate, FortiAnalyzer, Fortimanager.
Cisco-Talos/snort-faq
Snort FAQ
fortinet-ansible-dev/ansible-galaxy-fortios-collection
Ansible Galaxy FortiOS collection
Harvester57/Security-ADMX
Custom ADMX template focused on hardening Windows 10 & Windows 11 systems
40net-cloud/fortinet-azure-solutions
Azure Templates for getting you started with Fortinet solutions.
cisagov/cybersecurity-performance-goals
CISA's space for collaboration on the Cybersecurity Performance Goals
jeffbencteux/mailsecchk
POSIX script for mail security checks of domain names
msigley/PHP-HTTP-Tarpit
Confuse and waste bot scanners time.
mayhemiclabs/weblabyrinth
A system that creates a bogus web structure to entrap and delay web scanners
bsysop/servicenow
ServiceNow widge-simple-list misconfiguration scanner
DefensiveOrigins/DO-LAB
Defensive Origins lab
ondrejholecek/sniftran
Fortinet packet sniffer convertor
msdirtbag/MicrosoftPurpleTeamToolkit
Microsoft Purple Team Toolkit
fortinet/aws-cloudformation-templates
Cloud Formation Templates for getting you started in AWS with Fortinet.
KevinGuenay/fortigate-baseline
A baseline for FortiGates including best practices, security settings, checks, etc.
rapid7/insightvm-api-examples
InsightVM API examples
40net-cloud/fortinet-aws-solutions
Fortinet AWS solutions
gfoss/PowerShell-Honeyport
A powershell script for creating a Windows honeyport.
0xMuhammad/Bro-PCAP-Dissector
Bro script to dissect PCAP traces
Security · Windows & Active Directory
75 repos
Security · Windows & Active Directory
75 reposfortra/impacket
Impacket is a collection of Python classes for working with network protocols.
SpecterOps/BloodHound-Legacy
Six Degrees of Domain Admin
Orange-Cyberdefense/GOAD
game of active directory
Pennyw0rth/NetExec
The Network Execution Tool
GhostPack/Rubeus
Trying to tame the three-headed dog.
HotCakeX/Harden-Windows-Security
Harden Windows Safely, Securely using Official Supported Microsoft methods and proper explanation
ly4k/Certipy
Tool for Active Directory Certificate Services enumeration and abuse
0x6d69636b/windows_hardening
HardeningKitty and Windows Hardening Settings
cisagov/ScubaGear
Automation to assess the state of your M365 tenant against CISA's baselines
Cloud-Architekt/AzureAD-Attack-Defense
This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.
Microsoft365DSC/Microsoft365DSC
Manages, configures, extracts and monitors Microsoft 365 tenant configurations
davidprowe/BadBlood
BadBlood fills a Microsoft Active Directory Domain with a structure and thousands of objects. The output of the tool is a domain similar to a domain in the real world.
sense-of-security/ADRecon
ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment.
12Knocksinna/Office365itpros
PowerShell examples for articles published on office365itpros.com and practical365.com.
Gerenios/AADInternals
AADInternals PowerShell module for administering Azure AD and Office 365
jakehildreth/Locksmith
A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.
AD-Security/AD_Miner
AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the Bloodhound graph database to uncover security weaknesses
SkipToTheEndpoint/OpenIntuneBaseline
Community-driven baseline to accelerate Intune adoption and learning.
silverhack/monkey365
Monkey365 is an open-source security assessment tool for Microsoft 365, Azure, and Microsoft Entra ID.
KelvinTegelaar/CIPP
CIPP is a M365 multitenant management solution
EvotecIT/GPOZaurr
Group Policy Eater is a PowerShell module that aims to gather information about Group Policies but also allows fixing issues that you may find in them.
lkarlslund/ldapnomnom
Quietly and anonymously bruteforce Active Directory usernames at insane speeds from Domain Controllers by (ab)using LDAP Ping requests (cLDAP)
maester365/maester
Maester is a test automation framework to help you stay in control of your Microsoft security configuration.
Semperis/EntraGoat
A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.
microsoft/EntraExporter
PowerShell module to export a local copy of an Entra (Azure AD) tenant configuration.
cyberark/ACLight
A script for advanced discovery of Privileged Accounts - includes Shadow Admins
techspence/ScriptSentry
ScriptSentry finds misconfigured and dangerous logon scripts.
soteria-security/365Inspect
A PowerShell script that automates the security assessment of Microsoft 365 environments.
tomwechsler/Active_Directory_Advanced_Threat_Hunting
This repo is about Active Directory Advanced Threat Hunting
LETHAL-FORENSICS/Microsoft-Analyzer-Suite
A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID
ThomasKur/M365Documentation
Automatic Microsoft 365 Documentation to simplify the life of admins and consultants.
BloodHoundAD/BARK
BloodHound Attack Research Kit
JamesCooteUK/SharpSphere
.NET Project for Attacking vCenter
ANSSI-FR/ADTimeline
Timeline of Active Directory changes with replication metadata
mtth-bfft/adeleg
Active Directory delegation management tool
microsoftarchive/New-KrbtgtKeys.ps1
This script will enable you to reset the krbtgt account password and related keys while minimizing the likelihood of Kerberos authentication issues being caused by the operation.
zjorz/Public-AD-Scripts
AD Scripts
AzureAD/Azure-AD-Incident-Response-PowerShell-Module
The Azure Active Directory Incident Response PowerShell module provides a number of tools, developed by the Azure Active Directory Product Group in conjunction with the Microsoft Detection and Response Team.
zeronetworks/BloodHound-Tools
Collection of tools that reflect the network dimension into Bloodhound's data
microsoft/aka
Doc page listing all public aka.ms links for Microsoft admin portals
ugurkocde/IntuneAssignmentChecker
This script enables IT administrators to analyze and audit Intune assignments. It checks assignments for specific users, groups, or devices, displays all policies and their assignments.
techspence/ADeleginator
A companion tool that uses ADeleg to find insecure trustee and resource delegations in Active Directory
garrettfoster13/pre2k
A tool to query for the existence of pre-windows 2000 computer objects.
DanielChronlund/DCToolbox
Tools for Microsoft cloud fans
microsoft/zerotrustassessment
Repository for the Zero Trust Assessment project
cammurray/orca
The Microsoft Defender for Office 365 Recommended Configuration Analyzer (ORCA)
synacktiv/gpoParser
gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.
MG-Cloudflow/Intune-Toolkit
The Intune-Toolkit offers a basic & user-friendly interface to connect to Microsoft Graph, manage policy assignments, and handle backup and restore operations
OTRF/Blacksmith
Building environments to replicate small networks and deploy applications
adamfowlerit/msportals.io
MSPortals.io - Microsoft Administrator Sites, Training, and Licensing Resources
Cloud-Architekt/EntraOps
Community project to classify, identify and protect your privileges based on Enterprise Access Model (EAM)
ANSSI-FR/DFIR-O365RC
PowerShell module for Office 365 and Azure log collection
SpecterOps/TierZeroTable
Table of AD and Azure assets and whether they belong to Tier Zero
AirbusProtect/AD-Canaries
The purpose of this project is to publish and maintain the deployment PowerShell script that automates deployments for Active Directory Canary objects.
Azure/securedworkstation
Intune managed Secured workstation
samratashok/Deploy-Deception
A PowerShell module to deploy active directory decoy objects.
mihemihe/myADMonitor
myADMonitor is an open-source Active Directory changes tracking tool
f-bader/MSRC-PatchReview
PowerShell variant of patch_review.py by kevthehermit
ricardojoserf/WhoamiAlternatives
Different methods to get current username without using whoami
jonny-jhnson/Marvel-Lab
A collection of Powershell scripts that will help automate the build process for a Marvel domain.
PyroTek3/ADLab
Location of some Active Directory lab scripts I have created and find useful
jakehildreth/PowerPUG
A tiny tool built to help AD Admins tame the Protected Users group.
davidalonsod/Dalonso-Security-Repo
Share Information about Microsoft Security Products
0x706972686f/RMM-Catalogue
RMM Catalogue
Qazeer/FarsightAD
PowerShell script that aim to help uncovering (eventual) persistence mechanisms deployed by a threat actor following an Active Directory domain compromise
soteria-security/ADInspect
A PowerShell script that automates the security assessment of Microsoft Active Directory environments.
malcolmmcdonald1982/M365-Assessment-Toolkit
Free, open-source Microsoft 365 security assessment tool. Evaluates 23 findings, auto-remediates with rollback, generates professional reports, and simulates attack chains.
PwnDefend/Active_Directory_ADSI_Audit_Powershell
Active Directory ADSI Audit Powershell
nathanmcnulty/azd-maester
azd-maester
kayasax/SCIMTool
inspect EntraID SCIM flows for troubleshooting
Noble-Effeciency13/M365IdentityPosture
PowerShell security reporting framework for Microsoft 365 identity posture assessment. Analyzes Authentication Context, PIM, Conditional Access & more.
SalutAToi/AD-Tier-Administration
Powershell scripts to implement a Tier administration model in Active Directory
Marlyns-GitHub/AD-Tiering
Automating Active Directory Tiering
Trimarc/Create-Vulnerable-ADDS
Installs ADDS and configures a vulnerable domain via a powershell script
krooth/the-lazy-enterprise-AD
AD Lab setup for learning infosec
Security · Offensive
71 repos
Security · Offensive
71 reposswisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Z4nzu/hackingtool
ALL IN ONE Hacking Tool For Hackers
usestrix/strix
Open-source AI penetration testing tool to find and fix your app's vulnerabilities.
projectdiscovery/nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL.
robertdavidgraham/masscan
TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.
vxcontrol/pentagi
Fully autonomous AI Agents system capable of performing complex penetration testing tasks
peass-ng/PEASS-ng
PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
MatrixTM/MHDDoS
Best DDoS Attack Script Python3, (Cyber / DDos) Attack With 56 Methods
kgretzky/evilginx2
Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
PowerShellMafia/PowerSploit
PowerSploit - A PowerShell Post-Exploitation Framework
dstotijn/hetty
An HTTP toolkit for security research.
AlessandroZ/LaZagne
Credentials recovery project
OWASP/wstg
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications.
byt3bl33d3r/CrackMapExec
A swiss army knife for pentesting networks
LOLBAS-Project/LOLBAS
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
HavocFramework/Havoc
The Havoc Framework
apache/caldera
Automated Adversary Emulation Platform
guardicore/monkey
Infection Monkey - An open-source adversary emulation platform
S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
RedSiege/EyeWitness
EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.
madhuakula/kubernetes-goat
Kubernetes Goat is a Vulnerable by Design cluster environment to learn and practice Kubernetes security using an interactive hands-on playground
Ne0nd0g/merlin
Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
BC-SECURITY/Empire
Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.
cobbr/Covenant
Covenant is a collaborative .NET C2 framework for red teamers.
GhostPack/Seatbelt
Seatbelt is a C# project that performs a number of security oriented host-survey safety checks.
KeygraphHQ/shannon
Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities.
bluscreenofjeff/Red-Team-Infrastructure-Wiki
Wiki to collect Red Team infrastructure hardening resources
iagox86/dnscat2
dnscat2 - DNS tunnel
RhinoSecurityLabs/cloudgoat
CloudGoat is Rhino Security Labs' Vulnerable by Design AWS deployment tool
matro7sh/BypassAV
This map lists the essential techniques to bypass anti-virus and EDR
s0md3v/Smap
a drop-in replacement for Nmap powered by shodan.io
six2dez/OneListForAll
Rockyou for web fuzzing
SnaffCon/Snaffler
a tool for pentesters to help find delicious candy
gkbrk/slowloris
Low bandwidth DoS tool. Slowloris rewrite in Python.
DataDog/stratus-red-team
Granular, Actionable Adversary Emulation for the Cloud
bigb0sss/RedTeam-OffensiveSecurity
Tools & Interesting Things for RedTeam Ops
cider-security-research/cicd-goat
A deliberately vulnerable CI/CD environment. Learn CI/CD security through multiple challenges.
kgretzky/pwndrop
Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.
samugit83/redamon
An AI-powered agentic red team framework that automates offensive security operations
dafthack/DomainPasswordSpray
DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain.
0xInfection/TIDoS-Framework
The Offensive Manual Web Application Penetration Testing Framework.
GoSecure/pyrdp
RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact
magicsword-io/LOLDrivers
Living Off The Land Drivers
Yaxser/Backstab
A tool to kill antimalware protected processes
inguardians/peirates
Peirates - Kubernetes Penetration Testing tool
nikaiw/VMkatz
Extract Windows credentials directly from VM memory snapshots and virtual disks
0xacb/recollapse
REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications
alphasoc/flightsim
A utility to safely generate malicious network traffic patterns and evaluate controls.
myzxcg/RealBlindingEDR
Remove AV/EDR Kernel ObRegisterCallbacks, CmRegisterCallback, MiniFilter Callback, PsSetCreateProcessNotifyRoutine Callback, PsSetCreateThreadNotifyRoutine Callback, PsSetLoadImageNotifyRoutine Callback
RedTeamPentesting/pretender
Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing.
Arcanum-Sec/msftrecon
Recon tool for Microsoft/Azure environments
PyroTek3/PowerShell-AD-Recon
PowerShell Scripts I find useful
pop3ret/AWSome-Pentesting
My cheatsheet notes to pentest AWS infrastructure
orangetw/tsh
Tiny SHell is an open-source UNIX backdoor.
3ct0s/dystopia-c2
Windows Remote Administration Tool that uses Discord, Telegram and GitHub as C2s
vu-ls/Crassus
Windows privilege escalation via service misconfigurations
OWASP/DVSA
a Damn Vulnerable Serverless Application
infosecB/LOOBins
Living Off the Orchard: macOS Binaries (LOOBins) is designed to provide detailed information on various built-in living off the land macOS binaries and how they can be used by threat actors.
Orange-Cyberdefense/KeePwn
A python tool to automate KeePass discovery and secret extraction.
maldevel/gdog
A fully featured Windows backdoor that uses Gmail as a C&C server
BishopFox/cloudfoxable
Create your own vulnerable by design AWS penetration testing playground
dievus/ADPulse
Active Directory Vulnerability Scanner
vysecurity/IPFuscator
IPFuscator - A tool to automatically generate alternative IP representations
SafeBreach-Labs/EDRaser
EDRaser is a powerful tool for remotely deleting access logs, Windows event logs, databases, and other files on remote machines.
nirajkharel/AD-Pentesting-Notes
Active Directory Pentesting Notes
cycurity/wister
A wordlist generator tool, that allows you to supply a set of words, giving you the possibility to craft multiple variations from the given words, creating a unique and ideal wordlist.
darkweak/rudy
RUDY is an acronym used to describe a Denial of Service (DoS) tool used by hackers to perform slow-rate a.k.a. Low and slow attacks.
bvcyber/RedWizard
RedWizard
irsdl/auraditor
A Burp Suite extension for Lightning/Aura framework security testing with advanced action management, context editing, and comprehensive audit capabilities.
prjblk/aura-dump
Dumps Salesforce objects if provided with credentials.
randomstr1ng/virtual-sap-death-star
This repo contains research and PoCs to bypass security mechanisms of the Virtual SAP user and to tamper with the SAP Audit Log on a SAP kernel level.
Reference, Awesome Lists & Learning
41 repos
Reference, Awesome Lists & Learning
41 repossindresorhus/awesome
Awesome lists about all kinds of interesting topics
public-apis/public-apis
A collective list of free APIs
jwasham/coding-interview-university
A complete computer science study plan to become a software engineer.
trimstray/the-book-of-secret-knowledge
A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.
ripienaar/free-for-dev
A list of SaaS, PaaS and IaaS offerings that have free tiers of interest to devops and infradev
Hack-with-Github/Awesome-Hacking
A collection of various awesome lists for hackers, pentesters and security researchers
jaywcjlove/awesome-mac
This project is dedicated to collecting high-quality macOS software and organizing them systematically by different categories for easy search and use.
florinpop17/app-ideas
A Collection of application ideas which can be used to improve your coding skills.
bradtraversy/design-resources-for-developers
Curated list of design and UI resources from stock photos, web templates, CSS frameworks, UI libraries, tools and much more
veggiemonk/awesome-docker
A curated list of Docker resources and projects
OWASP/CheatSheetSeries
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
abhisheknaiidu/awesome-github-profile-readme
A curated list of awesome GitHub Profile which updates in real time
imthenachoman/How-To-Secure-A-Linux-Server
An evolving how-to guide for securing a Linux server.
liquidslr/leetcode-company-wise-problems
Lists of company wise questions. Every csv file in the companies directory corresponds to a list of questions on leetcode for a specific company based on the leetcode company tags.
projectdiscovery/nuclei-templates
Community curated list of templates for the nuclei engine to find security vulnerabilities.
iptv-org/awesome-iptv
A curated list of resources related to IPTV
Kristories/awesome-guidelines
Programming style, best practices, and coding conventions
onceupon/Bash-Oneliner
A collection of handy Bash One-Liners and terminal tricks for data processing and Linux system maintenance.
meirwah/awesome-incident-response
A curated list of tools for incident response
humanloop/awesome-chatgpt
Curated list of awesome tools, demos, docs for ChatGPT and GPT-3
fr0gger/Awesome-GPT-Agents
A curated list of GPT agents for cybersecurity
0x90n/InfoSec-Black-Friday
All the deals for InfoSec related software/tools this Black Friday
pedramamini/awesome-yara
A curated list of awesome YARA rules, tools, and people.
sergiomarotco/Network-segmentation-cheat-sheet
Best practices for segmentation of the corporate network of any company
onhexgroup/Conferences
Conference presentation slides
strandjs/IntroLabs
These are the labs for my Intro class. Yes, this is public. Yes, this is intentional.
jpantunes/awesome-cryptoeconomics
An awesome curated list of Cryptoeconomic research and learning materials
timvisee/send-instances
A list of public Send instances. Mirror
Arudjreis/awesome-security-GRC
Curated list of resources for security Governance, Risk Management, Compliance and Audit professionals and enthusiasts
nathanlesage/academics-on-mastodon
A list of various lists consisting of academics on Mastodon
dalisoft/awesome-hosting
List of awesome hosting sorted by minimal plan price
Adamkadaban/CTFs
CTF Cheat Sheet + Writeups / Files for some of the Security CTFs that I've done
merill/awesome-entra
Awesome list of all things related to Microsoft Entra
cyb3rmik3/MDE-DFIR-Resources
A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
reswob10/HomeLabResources
List of resources for buiding a home lab
Hellfire0x01/cert-cheatsheets
Certification Cheatsheets
fortinet/4D-Demo
4-D Demo configurations are a collection of configurations which complement the preceeding 3 Ds: Define, Design, and Deploy.
olafhartong/Presentations
My conference presentations
0xjet/ccc
A short graduate course on cybercrime, cyberespionage, and cyberoperations
yuriskinfo/awesome-Fortinet
Curated list of useful resources for those working with Fortinet products
fg0x0/XSS-Cheat-Sheets-2020
By the way you may need it.
Developer Tools
32 repos
Developer Tools
32 reposmicrosoft/terminal
The new Windows Terminal and the original Windows console host, all in the same place!
microsoft/playwright
Playwright is a framework for Web Testing and Automation. It allows testing Chromium, Firefox and WebKit with a single API.
alacritty/alacritty
A cross-platform, OpenGL terminal emulator.
scrapy/scrapy
Scrapy, a fast high-level web crawling & scraping framework for Python.
firecrawl/firecrawl
The API to search, scrape, and interact with the web at scale
mitmproxy/mitmproxy
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
lightpanda-io/browser
Lightpanda: the headless browser designed for AI and automation
googleworkspace/cli
Google Workspace CLI — one command-line tool for Drive, Gmail, Calendar, Sheets, Docs, Chat, Admin, and more
wezterm/wezterm
A GPU-accelerated cross-platform terminal emulator and multiplexer written by @wez and implemented in Rust
magic-wormhole/magic-wormhole
get things from one computer to another, safely
gnachman/iTerm2
iTerm2 is a terminal emulator for Mac OS X that does amazing things.
ahmedkhaleel2004/gitdiagram
Free, simple, fast interactive diagrams for any GitHub repository
faker-js/faker
Generate massive amounts of fake data in the browser and node.js
pyinstaller/pyinstaller
Freeze (package) Python programs into stand-alone executables
phw/peek
Simple animated GIF screen recorder with an easy to use interface
apache/jmeter
Apache JMeter open-source load testing tool for analyzing and measuring the performance of a variety of services
pinchtab/pinchtab
High-performance browser automation bridge and multi-instance orchestrator with advanced stealth injection and real-time dashboard
artilleryio/artillery
The complete load testing platform. Everything you need for production-grade load tests. Serverless & distributed.
dependabot/dependabot-core
Dependabot's core logic for creating update PRs.
Pagefind/pagefind
Static low-bandwidth search at scale
rorkai/App-Store-Connect-CLI
Fast, scriptable CLI for the App Store Connect API with automation capabilities
nextdns/nextdns
NextDNS CLI client (DoH Proxy)
aws/aws-lambda-go
Libraries, samples and tools to help Go developers develop AWS Lambda functions.
pester/Pester
Pester is the ubiquitous test and mock framework for PowerShell.
itsOwen/CyberScraper-2077
Powerful web scraper powered by LLM with OpenAI, Gemini & Ollama support
vasu-devs/JustHireMe
Local-first AI job intelligence workbench for scraping roles, ranking fit, and generating tailored application materials.
rdegges/ipify-api
A public IP API service
claffin/cloudproxy
Hide your scrapers IP behind the cloud. Provision proxy servers across different cloud providers to improve your scraping success.
projectdiscovery/notify
Notify is a Go-based assistance package that enables you to stream the output of several tools (or read from a file) and publish it to a variety of supported platforms.
bennypowers/nvim-regexplainer
Describe the regexp under the cursor
AnswerDotAI/fastsetup
Setup all the things
arvydas/blinkstick-python
BlinkStick Python interface to control devices connected to the computer
Homelab & Infrastructure
29 repos
Homelab & Infrastructure
29 reposawesome-selfhosted/awesome-selfhosted
A list of Free Software network services and web applications which can be hosted on your own servers
coollabsio/coolify
An open-source, self-hostable PaaS alternative to Vercel, Heroku & Netlify that lets you easily deploy static sites, databases, full-stack applications and 280+ one-click services on your own servers.
hashicorp/terraform
Terraform enables you to safely and predictably create, change, and improve infrastructure.
balena-io/etcher
Flash OS images to SD cards & USB drives, safely and easily.
tailscale/tailscale
Easiest, most secure way to use WireGuard and 2FA
certbot/certbot
Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any other CA that uses the ACME protocol.
hashicorp/vagrant
Vagrant is a tool for building and distributing development environments.
m1k1o/neko
A self hosted virtual browser that runs in docker and uses WebRTC.
Billionmail/BillionMail
BillionMail gives you open-source MailServer, NewsLetter, Email Marketing — fully self-hosted, dev-friendly, and free from monthly fees.
grokability/snipe-it
A free open source IT asset/license management system
dotnet/yarp
A toolkit for developing high-performance HTTP reverse proxy applications.
linuxserver/Heimdall
An Application dashboard and launcher
masterking32/MasterDnsVPN
Advanced DNS tunneling VPN for censorship bypass, optimized beyond DNSTT and SlipStream with low-overhead ARQ, resolver load balancing, high packet-loss stability and speed.
netalertx/NetAlertX
Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.
wger-project/wger
Self hosted FLOSS fitness/workout, nutrition and weight tracker
cloudflare/agentic-inbox
A self-hosted email client with an AI agent, running entirely on Cloudflare Workers
timvisee/send
Simple, private file sharing. Mirror of gitlab.com/timvisee/send
jedisct1/dsvpn
A Dead Simple VPN.
win-acme/win-acme
Automate SSL/TLS certificates on Windows with ease
onedr0p/cluster-template
A template for deploying a Talos Kubernetes cluster including Flux for GitOps
exentriquesolutions/nip.io
nip.io - dead simple wildcard DNS for any IP address
Madelena/hass-config-public
My Dashboards for Home Assistant - Advanced data visualizations, responsive design, a neat maximalist Metro Live Tile layout, and an ultraminimal tablet layout!
AdguardTeam/AdGuardDNS
Public DNS resolver that protects you from ad trackers
Corollarium/localtls
DNS server for providing TLS to webservices on local addresses
whazor/k8s-at-home-search
Your Gateway Drug to Kubernetes at Home!
askblaker/k3s.rocks
k3s.rocks
pl4nty/homelab
Powered by Kubernetes
Josh-Tracy/Kubernetes-Home-Lab
Kubernetes Home Lab
vidavidorra/renovate
Self-hosted Renovate using the Renovate GitHub Action
Security · DFIR
26 repos
Security · DFIR
26 reposmoonD4rk/HackBrowserData
Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).
mvt-project/mvt
MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.
volatilityfoundation/volatility
An advanced memory forensics framework
volatilityfoundation/volatility3
Volatility 3.0 development
unode/firefox_decrypt
Firefox Decrypt is a tool to extract passwords from Mozilla (Firefox, Waterfox, Thunderbird, SeaMonkey) profiles
log2timeline/plaso
Super timeline all the things
jtsylve/LiME
LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices.
RyanDFIR/hindsight
Browser forensics tool for Google Chrome (and other Chromium-based browsers)
andreas-mausch/whatsapp-viewer
Small tool to display chats from the Android msgstore.db database (crypt12)
tclahr/uac
UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems.
microsoft/avml
AVML - Acquire Volatile Memory for Linux
orlikoski/CyLR
CyLR - Live Response Collection Tool
keydet89/RegRipper3.0
RegRipper3.0
AndrewRathbun/DFIRArtifactMuseum
The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type.
vm32/Linux-Incident-Response
practical toolkit for cybersecurity and IT professionals.
EricZimmerman/MFTECmd
Parses $MFT from NTFS file systems
WiredPulse/PoSh-R2
PowerShell - Rapid Response... For the incident responder in you!
ANSSI-FR/DFIR4vSphere
Powershell module for VMWare vSphere forensics
strozfriedberg/sidr
Search Index Database Reporter
moaistory/WinSearchDBAnalyzer
Windows Search DB Analyzer
woanware/usbdeviceforensics
Python script for extracting USB information from Windows registry hives
resurrecting-open-source-projects/dcfldd
Enhanced version of dd for forensics and security
Koifman/LUMEN
Your Browser-based EVTX Companion
harelsegev/INDXRipper
Carve file metadata from NTFS index ($I30) attributes
reverseame/winesap
Volatility plugin to search for all Autostart Extensibility Points (AESPs)
threat-hunt-ai/threat-hunt-ai
AI-powered threat hunting, incident response, and detection engineering for FortiSIEM
Security · Threat Intel & Malware
22 repos
Security · Threat Intel & Malware
22 reposytisf/theZoo
A repository of LIVE malwares for your own joy and pleasure.
VirusTotal/yara
The pattern matching swiss knife
trickest/cve
Gather and update all available and newest CVEs with their PoC.
Yara-Rules/rules
Repository of yara rules
alexandreborges/malwoverview
Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan
Neo23x0/Loki
Loki - Simple IOC and YARA Scanner
mandiant/red_team_tool_countermeasures
Red team tool countermeasures YARA rules
microsoft/msticpy
Microsoft Threat Intelligence Security Tools
ThreatHuntingProject/ThreatHunting
An informational repo about hunting for adversaries in your IT environment.
hasherezade/tiny_tracer
A Pin Tool for tracing API calls etc
jesparza/peepdf
Powerful Python tool to analyze PDF documents
thalesgroup-cert/Watcher
Open Source AI-powered Cyber Threat Intelligence & Hunting Platform
mukul975/cve-mcp-server
Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan, VirusTotal, and more.
chronicle/GCTI
Google Cloud Threat Intelligence YARA rules
CERT-Polska/malduck
Malduck is your ducky companion in malware analysis journeys
urule99/jsunpack-n
Automatically exported from code.google.com/p/jsunpack-n
buguroo/cuckooautoinstall
Auto Installer Script for Cuckoo Sandbox
fr0gger/unprotect
Unprotect is a python tool for parsing PE malware and extract evasion techniques.
intel471/CU-GIR
Cyber Underground General Intelligence Requirements
timo123421/Automatic-Intelligence-feed
Automatic Intelligence feed
depalmar/AI-Powered-Ransomware-Intelligence-Agent
Automated n8n workflow for ransomware threat monitoring using ransomware.live API and Claude AI
wit0k/tarrask
Tarrask: Hafnium's persistence via hidden scheduled task
Security · OSINT & Privacy
18 repos
Security · OSINT & Privacy
18 repossherlock-project/sherlock
Hunt down social media accounts by username across social networks
HunxByts/GhostTrack
Useful tool to track location or mobile number
reconurge/flowsint
A modern platform for visual, flexible, and extensible graph-based investigations. For cybersecurity analysts and investigators.
simplifaisoul/osiris
Open Source Global Intelligence Platform - Real-Time OSINT Dashboard - A Palantir Alternative
koala73/worldmonitor
Real-time global intelligence dashboard with AI-powered news aggregation and monitoring
apurvsinghgautam/robin
AI-Powered Dark Web OSINT Tool
lanmaster53/recon-ng
Open Source Intelligence gathering tool aimed at reducing the time spent harvesting information from open sources.
EFForg/rayhunter
Rust tool to detect cell site simulators on an orbic mobile hotspot
niespodd/browser-fingerprinting
Analysis of Bot Protection systems with available countermeasures. How to defeat anti-bot system and get around browser fingerprinting scripts when scraping the web?
pirxthepilot/wtfis
Passive hostname, domain and IP lookup tool for non-robots
indianajson/can-i-take-over-dns
Can I take over DNS? — a list of DNS providers and how to claim vulnerable domains
elm1nst3r/GHOST-osint-crm
GHOST - Global Human Operations & Surveillance Tracking: Open-source investigation management platform
mitchmoser/sputnik
Open Source Intelligence Browser Extension
C3n7ral051nt4g3ncy/OSINT_Inception-links
Current links from the OSINT Inception start-me project
cipher387/OSINT-and-Cybersecurity-accounts-in-Mastodon
This repository brings together tool builders, bloggers, speakers, book authors, and other interesting Mastodon accounts
EvotecIT/DomainDetective
Domain Detective is a C# library, Tool and PowerShell module in one project. It is designed to help you find interesting information about a domain name.
C3n7ral051nt4g3ncy/TraceLabs-Flag-Categories-Guide
This is a guide to understand Flag categories for Trace Labs OSINT Search Party CTF events
Mustafa-Almohsen/Punycode-Converter
Full Homoglyph Punycode Viewer. This Python script allows you to explore all possible homoglyphs (look-alike characters) for letters, numbers, and some symbols, and instantly converts them into Punycode.
Misc & Other
12 repos
Misc & Other
12 reposFujiwaraChoki/MoneyPrinterV2
Automate the process of making money online.
kleampa/not-paid
Client did not pay? Add opacity to the body tag and decrease it every day until their site completely fades away
donlon/cloudflare-error-page
Customized Cloudflare error page generator (unofficial)
MicrosoftDocs/architecture-center
Open source documentation for the Azure Architecture Center on Microsoft Learn.
bijomaru78/eccm
Ethernet Cable Connection Manager
HackingDave/nightwire
A secure way to code via Signal
bit-of-a-shambles/open-tender-watch
Rails 8 app monitoring public procurement to detect corruption risk patterns across Portuguese and EU databases
WiredPulse/PowerShell
A series of scripts
merill/yako
A better new tab page for your browser
pathaksomesh06/Fleetly
Fleetly
Godi13/Godi13
Godi13 profile
GuidoBaijense/architecture-center-ca-backup
Open source documentation for the Azure Architecture Center on Microsoft Learn.
Finance & Trading
10 repos
Finance & Trading
10 reposvirattt/ai-hedge-fund
An AI Hedge Fund Team
maybe-finance/maybe
The personal finance app for everyone
Fincept-Corporation/FinceptTerminal
FinceptTerminal is a modern finance application offering advanced market analytics, investment research, and economic data tools.
vas3k/TaxHacker
Self-hosted AI accounting app. LLM analyzer for receipts, invoices, transactions with custom prompts and categories
Codehagen/Badget
Badget aims to simplify financial management with a user-friendly interface and robust backend
OffcierCia/ultimate-defi-research-base
Here we collect and discuss the best DeFI & Blockchain researches and tools.
OffcierCia/Crypto-OpSec-SelfGuard-RoadMap
Here we collect and discuss the best DeFi, Blockchain and crypto-related OpSec researches and data terminals.
lit26/finvizfinance
Finviz analysis python library.
shner-elmo/TradingView-Screener
A package that lets you create TradingView screeners in Python
impersonator-eth/impersonator
Login into dapps by impersonating any Ethereum address via WalletConnect or iFrame
Web & Frontend
9 repos
Web & Frontend
9 reposrealworld-apps/realworld
The mother of all demo apps — Exemplary fullstack Medium.com clone powered by React, Angular, Node, Django, and many more
badges/shields
Concise, consistent, and legible badges in SVG and raster format
simple-icons/simple-icons
SVG icons for popular brands
rahuldkjain/github-profile-readme-generator
Generate GitHub profile README easily with the latest add-ons like visitors count, GitHub stats, etc using minimal UI.
tandpfun/skill-icons
Showcase your skills on your Github readme or resumé with ease
marwin1991/profile-technology-icons
Add icons to your GitHub profile using this generator
ABSphreak/readme-jokes
Jokes for your GitHub READMEs
GrapheneOS/grapheneos.org
Servers for our website, HTTP/HTTPS connectivity checks, HTTPS network time, NTP, attestation
QubesOS/qubesos.github.io
Qubes OS Project Official Website
Media & Content
9 repos
Media & Content
9 reposiptv-org/iptv
Collection of publicly available IPTV channels from all over the world
harry0703/MoneyPrinterTurbo
Generate short videos with one click using AI LLM.
hacksider/Deep-Live-Cam
real time face swap and one-click video deepfake with only a single image
OpenBMB/VoxCPM
VoxCPM2: Tokenizer-Free TTS for Multilingual Speech Generation, Creative Voice Design, and True-to-Life Cloning
Anil-matcha/Open-Generative-AI
Unrestricted Open-source alternative to AI video platforms — Free AI image & video generation studio with 200+ models (Flux, Midjourney, Kling, Sora, Veo). No content filters. Self-hosted, MIT license.
Free-TV/IPTV
M3U Playlist for free TV channels
roboflow/sports
computer vision and sports
rauchg/doom-captcha
Doom captcha
B03GHB4L1/ClipMaker
Football highlight reel generator from match event data
Security · Cloud
6 repos
Security · Cloud
6 reposduo-labs/cloudmapper
CloudMapper helps you analyze your Amazon Web Services (AWS) environments.
NetSPI/MicroBurst
A collection of scripts for assessing Microsoft Azure security
Azure/review-checklists
Azure Review Checklists helps ensure you are following Microsoft best practices and recommendations across Platform, Applications and Services on Azure
zoph-io/aws-security-survival-kit
Bare minimum AWS Security Alerting and Secure by default Configuration
salesforce/cloud-guardrails
Rapidly apply hundreds of security controls in Azure
fortinet/aws-lambda-guardduty
Lambda function to be called in CloudWatch when GuardDuty sends logs to CloudWatch. This script will write the malicious IP to a dedicated file in an S3 bucket.
Operating Systems & Desktop
5 repos
Operating Systems & Desktop
5 reposmassgravel/Microsoft-Activation-Scripts
Open-source Windows and Office activator featuring HWID, Ohook, TSforge, and Online KMS activation methods, along with advanced troubleshooting.
Raphire/Win11Debloat
A simple, lightweight PowerShell script that allows you to remove pre-installed apps, disable telemetry, as well as perform various other changes to declutter and customize your Windows experience.
eythaann/Seelen-UI
The Fully Customizable Desktop Environment for Windows 10/11.
leaningtech/webvm
Virtual Machine for the Web
microsoft/azurelinux
General purpose Linux OS for Azure
Documents & Data Processing
3 repos
Documents & Data Processing
3 reposmicrosoft/markitdown
Python tool for converting files and office documents to Markdown.
freedomofpress/dangerzone
Take potentially dangerous PDFs, office documents, or images and convert them to safe PDFs
smalot/pdfparser
PdfParser, a standalone PHP library, provides various tools to extract data from a PDF file.
Nada encontrado. Tenta outra pesquisa ou categoria.
Ferramentas externas
Curadas à mão — não fazem parte do catálogo automático.
Segurança
Redes & Utilidades