How to Track Fresh Exploits Directly in GitHub Repositories
Learn how to track fresh PoC exploits in GitHub repositories using nomi-sec/PoC-in-GitHub, understand real-world attack vectors, and stay ahead of critical vulnerabilities.
Language
HomeLanguages
Sections
Penetration testing, cryptography, network security, and tooling for defenders and researchers.
Learn how to track fresh PoC exploits in GitHub repositories using nomi-sec/PoC-in-GitHub, understand real-world attack vectors, and stay ahead of critical vulnerabilities.
AI-Infra-Guard is an open-source platform for securing AI services and agents. It scans AI infrastructure for CVEs, audits MCP servers and agent skills, and tests LLM resistance to jailbreaks.
Delegating Google Dorking to neural network agents: a look at DorkAgent, a tool that automates search queries using Serper API and LLMs.
Turn a $5 RP2350 microcontroller board into a full-featured USB security token with FIDO2, OpenPGP, and post-quantum cryptography support.
StegoForge combines steganography and steganalysis tools into one CLI with support for images, audio, video, documents, and network packets.
Tool combines ARP scanning, Nmap, and passive traffic monitoring with an interactive topology map for network audits.
Krawl is a deception server that pretends to be a vulnerable web app, feeding scanners infinite trap pages and wasting their resources.
Open-source mcp-scanner audits MCP servers for hidden threats using YARA, LLM-as-judge, and Docker sandboxing.
Build a private surveillance camera on Raspberry Pi with end-to-end encryption and zero-trust architecture — no cloud subscriptions required.
DockerScan combines vulnerability scanning, secret detection, and configuration auditing in one fast Go-based tool for comprehensive container security checks.
Tired of managing dozens of blocklists? 1Hosts offers a lean alternative with just two versions covering ads, trackers, and phishing—available in dozens of formats.
AuthPass brings a fresh look to KeePass with a unified Flutter client that works across Android, iOS, macOS, Windows, Linux, and the browser — all open source.
Google built Zanzibar for authorization at scale. Learn how SpiceDB, an open-source database inspired by it, handles permissions for billions of users.
Coldcard firmware is fully open-source. Here's what's inside the repository, how reproducible builds work, and why running the emulator on your PC is worth it.
A look at Nono — a Rust-based sandboxing tool that isolates AI agents without containers, protecting SSH keys and cloud credentials while keeping terminal performance snappy.
An open-source CCleaner alternative under MIT license that handles system maintenance and cleanup without ads, telemetry, or premium subscriptions.
Destroylist is an open threat intelligence project with 888k+ tracked domains and 180k verified phishing sites. Learn how to block them with a single line of code.
Decepticon is an autonomous Red Team agent that runs attack chains like a real pentester. It scored 98% on the XBOW benchmark and uses 16 specialized agents for different attack stages.
Discover how to automate Ubuntu server hardening with konstruktoid's Shell scripts that leverage systemd isolation and CIS benchmarks to minimize attack surface.
NFCGate is an open-source Android tool for capturing, analyzing, and relaying NFC traffic. Created by TU Darmstadt researchers, it's essential for security researchers.
Andriller CE is a Python-based forensic toolkit for Android devices that extracts data, bypasses locks, and analyzes app backups including encrypted WhatsApp databases.
Capstone Engine is a powerful multi-architecture disassembly framework essential for reverse engineering, malware analysis, and binary security research.
Discover Ciphey, an automated decryption tool that identifies encryption types and decodes data in under 3 seconds using AI and NLP.
openSquat is a Python OSINT tool that detects phishing domains, typosquatting, IDN attacks, and lookalikes before attackers use them.