One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
-
Updated
Jul 9, 2026 - Python
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
A lightweight Command and Control (C2) framework built for offensive security research and red teaming (Post Exploitation).
AI-powered pentesting framework with automated recon and exploitation. Multi-source subdomain discovery, active vuln testing (XSS/SQLi/SSRF/IDOR), AI-driven payload generation, local inference, structured reporting. For pentesters and bug bounty hunters.
An authorization-first, policy-governed red-team operations platform that turns scoped security testing into safe, auditable, and evidence-ready workflows
Turn Tails OS into a ghost that bites. 50+ pentest tools installed into RAM via interactive menu — Tor-routed, zero persistence, vanishes on reboot.
NetLoader-X is a defensive load simulation framework designed to safely study server behavior under stress without generating real network traffic.
Open-source cyber range for offensive security training — isolated labs, live attack detection, and production-grade auth built from scratch
AI autonomous penetration testing + network forensics platform. Groq-powered, 100% free. One command full pentest
This is a simple Python-based keylogger built for educational and ethical hacking purposes. It captures keystrokes system-wide on macOS, logs them to a local file, and optionally sends them to a Discord webhook in real time.
A lightweight, modular post-exploitation framework for Linux and Windows that provides reverse shell session management, cross-platform plugins, SOCKS5 pivoting, in-memory payload execution, resumable file transfers with SHA-256 verification, and structured per-session logging for authorized security research and penetration testing.
🔐 **Password Complexity Checker & Generator** This tool helps you analyze password strength 🔍 and generate secure, random passwords 🎲. It ensures your passwords are tough to crack 💪 by checking for uppercase, lowercase, digits, special characters, and spaces.
Cloud-Security (Red Team)
Nemesis is an autonomous AI-driven pentesting agent that turns LLMs into skilled security testers, executing commands in an isolated Docker container and documenting findings with full context.
Lightweight Active Directory attack surface analyzer that extracts actionable findings from BloodHound data.
Offensive security write-ups, CTF walkthroughs and tooling breakdowns — by 0xK4iros.
A exploit designed to reboot a linux server / system. Sandworm only works on 32-bit linux systems. it looks for riscv32le, calling for a system reboot.
🔐 Inject API credentials securely into unmodified code via a transparent Envoy proxy, protecting sensitive data during AI agent interactions.
🔍 Extract and structure security vulnerability data from unstructured text with ease using the lightweight Python package, vuln-structure.
This repository serves as a portfolio of my work in computer science and offensive security.
Add a description, image, and links to the offensive-security-projects topic page so that developers can more easily learn about it.
To associate your repository with the offensive-security-projects topic, visit your repo's landing page and select "manage topics."