Exploits + Shellcode + GHDB v2026-08-26
Curated archive of public exploits, shellcode, and papers with SearchSploit CLI for offline searching, CVE lookup, and Nmap integration. Daily-updated database for penetration testers and vulnerability researchers.
Read more...
Curated archive of public exploits, shellcode, and papers with SearchSploit CLI for offline searching, CVE lookup, and Nmap integration. Daily-updated database for penetration testers and vulnerability researchers.
Read more...
git-alerts v1.8.0
Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files
Read more...
Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files
Read more...
gosentry v0.4.1
Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.
Read more...
Security-oriented Go toolchain, focused on state-of-the-art fuzzing capabilities.
Read more...
Malcolm v26.08.0
https://kitploit.com/en/posts/github-cisagov-malcolm-v26080
Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation via OpenSearch Dashboards and Arkime.
https://kitploit.com/en/posts/github-cisagov-malcolm-v26080
Containerized network traffic analysis suite ingesting PCAP, Zeek logs, and Suricata alerts for automated normalization, enrichment, and correlation via OpenSearch Dashboards and Arkime.
joern v4.0.612
https://kitploit.com/en/posts/github-joernio-joern-v40612
Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.gg/vv4MH284Hc
https://kitploit.com/en/posts/github-joernio-joern-v40612
Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.gg/vv4MH284Hc
androidReverse v20
Android reverse engineering entirely on-device. Radare2 binary analysis, 8 Java decompilers, Flutter & Unity il2cpp support.
Read more...
Android reverse engineering entirely on-device. Radare2 binary analysis, 8 Java decompilers, Flutter & Unity il2cpp support.
Read more...
20 Certificate Transparency Tricks for Recon: Master Advanced Asset Discovery for Ethical Hacking
https://medium.com/@verylazytech/20-certificate-transparency-tricks-for-recon-master-advanced-asset-discovery-for-ethical-hacking-0ba8bd8ecf45?source=rss------bug_bounty-5
Ever found a subdomain no one else has, just by reading a certificate log? You’re not alone — Certificate Transparency (CT) is the open…Continue reading on Medium » (https://medium.com/@verylazytech/20-certificate-transparency-tricks-for-recon-master-advanced-asset-discovery-for-ethical-hacking-0ba8bd8ecf45?source=rss------bug_bounty-5)
https://medium.com/@verylazytech/20-certificate-transparency-tricks-for-recon-master-advanced-asset-discovery-for-ethical-hacking-0ba8bd8ecf45?source=rss------bug_bounty-5
Ever found a subdomain no one else has, just by reading a certificate log? You’re not alone — Certificate Transparency (CT) is the open…Continue reading on Medium » (https://medium.com/@verylazytech/20-certificate-transparency-tricks-for-recon-master-advanced-asset-discovery-for-ethical-hacking-0ba8bd8ecf45?source=rss------bug_bounty-5)
Race Condition That Created an Undeletable Group Member
https://medium.com/@y_shivkumar/race-condition-that-created-an-undeletable-group-member-2e9483541fbf?source=rss------bug_bounty-5
https://medium.com/@y_shivkumar/race-condition-that-created-an-undeletable-group-member-2e9483541fbf?source=rss------bug_bounty-5
OverviewContinue reading on Medium » (https://medium.com/@y_shivkumar/race-condition-that-created-an-undeletable-group-member-2e9483541fbf?source=rss------bug_bounty-5)
threat-finder v0.3.0
Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.
Read more...
Runtime vulnerability scanner: finds CVEs in the services actually running on a host and ranks them by network exposure.
Read more...
nuguard v0.9.1
opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis
Read more...
opensource repo for validating agentic AI applications: redteam, behavior, supply-chain, static analysis
Read more...
yaraast v2.0.1rc1
A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representation
Read more...
A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representation
Read more...
OIHK – Sistema operativo OSINT local-first open source + motor de pentesting multiagente
https://www.reddit.com/r/Pentesting/comments/1vz7hj0/oihk_sistema_operativo_osint_localfirst_open/
<!-- SC_OFF -->Compartiendo dos herramientas open source que he estado construyendo bajo el proyecto OIHK: \*\*OIHK Basic\*\* → Espacio de trabajo para investigar OSINT local-first (gestión de evidencias, grafos de inteligencia, modelos de IA locales solamente). App de escritorio hecha con Tauri. \*\*OIHK-pentesting\*\* → Motor de pruebas de penetración autónomas multiagente. Incluye un planificador “root” y agentes especializados para reconocimiento, descubrimiento, validación y reporte. Los hallazgos solo se aceptan cuando hay evidencia real de ejecución de herramientas + un paso de validación separado. Tiene funciones de aplicación exacta del alcance, sandboxing y controles de salida (egress). Todo corre completamente local (LM Studio / Ollama). No hace falta la nube. Diseñado solo para evaluaciones autorizadas. Repos (licencia MIT): \- Basic → https://github.com/Broskigx/OIHK-Basic \- Pentesting → https://github.com/Broskigx/Oihk-pentesting El proyecto todavía está en desarrollo activo (beta). Hay bugs y partes incompletas. Si lo pruebas y encuentras errores o comportamientos inesperados, por favor abre un issue o repórtalos — de verdad ayuda a mejorar las herramientas. Se agradece muchísimo el feedback de la comunidad open source y de seguridad. <!-- SC_ON --> submitted by /u/Broskigx (https://www.reddit.com/user/Broskigx)
[link] (https://www.reddit.com/r/Pentesting/comments/1vz7hj0/oihk_sistema_operativo_osint_localfirst_open/) [comments] (https://www.reddit.com/r/Pentesting/comments/1vz7hj0/oihk_sistema_operativo_osint_localfirst_open/)
https://www.reddit.com/r/Pentesting/comments/1vz7hj0/oihk_sistema_operativo_osint_localfirst_open/
<!-- SC_OFF -->Compartiendo dos herramientas open source que he estado construyendo bajo el proyecto OIHK: \*\*OIHK Basic\*\* → Espacio de trabajo para investigar OSINT local-first (gestión de evidencias, grafos de inteligencia, modelos de IA locales solamente). App de escritorio hecha con Tauri. \*\*OIHK-pentesting\*\* → Motor de pruebas de penetración autónomas multiagente. Incluye un planificador “root” y agentes especializados para reconocimiento, descubrimiento, validación y reporte. Los hallazgos solo se aceptan cuando hay evidencia real de ejecución de herramientas + un paso de validación separado. Tiene funciones de aplicación exacta del alcance, sandboxing y controles de salida (egress). Todo corre completamente local (LM Studio / Ollama). No hace falta la nube. Diseñado solo para evaluaciones autorizadas. Repos (licencia MIT): \- Basic → https://github.com/Broskigx/OIHK-Basic \- Pentesting → https://github.com/Broskigx/Oihk-pentesting El proyecto todavía está en desarrollo activo (beta). Hay bugs y partes incompletas. Si lo pruebas y encuentras errores o comportamientos inesperados, por favor abre un issue o repórtalos — de verdad ayuda a mejorar las herramientas. Se agradece muchísimo el feedback de la comunidad open source y de seguridad. <!-- SC_ON --> submitted by /u/Broskigx (https://www.reddit.com/user/Broskigx)
[link] (https://www.reddit.com/r/Pentesting/comments/1vz7hj0/oihk_sistema_operativo_osint_localfirst_open/) [comments] (https://www.reddit.com/r/Pentesting/comments/1vz7hj0/oihk_sistema_operativo_osint_localfirst_open/)
Why an LLM can't reliably tell an authorized pentester from an attacker using copyable context
https://www.reddit.com/r/Pentesting/comments/1vzcpoe/why_an_llm_cant_reliably_tell_an_authorized/
https://www.reddit.com/r/Pentesting/comments/1vzcpoe/why_an_llm_cant_reliably_tell_an_authorized/
WINFLESHER - Attack Surface Security Framework
https://www.reddit.com/r/Pentesting/comments/1vzdz4c/winflesher_attack_surface_security_framework/
<!-- SC_OFF -->Hey everyone, just dropped a tool called winflesher that might come in super handy for windows machines. It's strictly for enumeration and assessment, so no auto-exploitation—purely helps you map things out. Check it out if you want! Like PingCastle went out for drinks with Bloodhound, and they actually decided to get some work done. 🍷 WinFlesher is an advanced attack surface security assessment framework designed to analyze, evaluate, and report on security postures, attack paths, and remediation strategies in complex environments. Developed for security professionals and cybersecurity auditors, WinFlesher automates vulnerability discovery and critical path correlation within Active Directory and local infrastructures. https://github.com/mindsflee/WinFlesher <!-- SC_ON --> submitted by /u/mindsflee (https://www.reddit.com/user/mindsflee)
[link] (https://www.reddit.com/r/Pentesting/comments/1vzdz4c/winflesher_attack_surface_security_framework/) [comments] (https://www.reddit.com/r/Pentesting/comments/1vzdz4c/winflesher_attack_surface_security_framework/)
https://www.reddit.com/r/Pentesting/comments/1vzdz4c/winflesher_attack_surface_security_framework/
<!-- SC_OFF -->Hey everyone, just dropped a tool called winflesher that might come in super handy for windows machines. It's strictly for enumeration and assessment, so no auto-exploitation—purely helps you map things out. Check it out if you want! Like PingCastle went out for drinks with Bloodhound, and they actually decided to get some work done. 🍷 WinFlesher is an advanced attack surface security assessment framework designed to analyze, evaluate, and report on security postures, attack paths, and remediation strategies in complex environments. Developed for security professionals and cybersecurity auditors, WinFlesher automates vulnerability discovery and critical path correlation within Active Directory and local infrastructures. https://github.com/mindsflee/WinFlesher <!-- SC_ON --> submitted by /u/mindsflee (https://www.reddit.com/user/mindsflee)
[link] (https://www.reddit.com/r/Pentesting/comments/1vzdz4c/winflesher_attack_surface_security_framework/) [comments] (https://www.reddit.com/r/Pentesting/comments/1vzdz4c/winflesher_attack_surface_security_framework/)
<!-- SC_OFF -->A recent preprint formalizes a problem pentesters keep running into with LLM safeguards: the same dual-use request can come from an authorized tester or an attacker, and copyable context cannot reliably prove which one you are. Paper: https://arxiv.org/abs/2607.27951 <!-- SC_ON --> submitted by /u/ClaudiusPapirus (https://www.reddit.com/user/ClaudiusPapirus)
[link] (https://www.youtube.com/watch?v=-2iITRLT7fg) [comments] (https://www.reddit.com/r/Pentesting/comments/1vzcpoe/why_an_llm_cant_reliably_tell_an_authorized/)
[link] (https://www.youtube.com/watch?v=-2iITRLT7fg) [comments] (https://www.reddit.com/r/Pentesting/comments/1vzcpoe/why_an_llm_cant_reliably_tell_an_authorized/)
Hx0-HawkEye v1.0.6
一个轻量级浏览器抓包与安全分析扩展,在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。(A lightweight browser extension for traffic capture and security analysis, enabling capture, interception, modification, replay, rule-based detection, and AI-assisted analysis—all from the browser sidebar.)
Read more...
一个轻量级浏览器抓包与安全分析扩展,在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。(A lightweight browser extension for traffic capture and security analysis, enabling capture, interception, modification, replay, rule-based detection, and AI-assisted analysis—all from the browser sidebar.)
Read more...
androidReverse v20
https://kitploit.com/en/posts/github-ultrasina-androidreverse-v20
Android reverse engineering entirely on-device. Radare2 binary analysis, 8 Java decompilers, Flutter & Unity il2cpp support.
https://kitploit.com/en/posts/github-ultrasina-androidreverse-v20
Android reverse engineering entirely on-device. Radare2 binary analysis, 8 Java decompilers, Flutter & Unity il2cpp support.
magic-extractor v1.3.1
Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.
Read more...
Universal Windows extraction tool that detects unknown files and routes them to the right bundled extractor.
Read more...
The Best-Paying Bug in Bounty Isn’t the One Everyone Hunts
4,590 disclosed reports. Eleven bug types. The crowd is hunting where the money isn’t.Continue reading on Medium »
Read more...
4,590 disclosed reports. Eleven bug types. The crowd is hunting where the money isn’t.Continue reading on Medium »
Read more...
Medium
The Best-Paying Bug in Bounty Isn’t the One Everyone Hunts
4,590 disclosed reports. Eleven bug types. The crowd is hunting where the money isn’t.