Tag
PentesterFlow is an open-source terminal assistant for authorized offensive-security work that plans against scoped targets, uses pentesting tools, requests approval for sensitive actions, retains lessons across sessions, and writes evidence-backed findings. It includes built-in skills for recon and web vulnerabilities, session continuity features, local continuous learning, and Burp integration.
reverse-skill is a cybersecurity skill routing package for AI Agents. It automatically selects reverse engineering toolchains (such as jadx, apktool, IDA, Ghidra) based on the target, covering APK reverse engineering, binary analysis, frontend encryption cracking, malware, penetration testing, CTF, and more. It has earned 16,000+ stars.
Nightcrawler is an autonomous penetration testing agent that runs entirely on a smartphone, using a local 1.2B AI model on the phone's GPU to discover hosts, map services, and generate pentest reports without cloud connectivity.
An open-source repository containing hundreds of AI security tools has been released, featuring techniques for jailbreaking LLMs, prompt injection testing, red team agents, model extraction, and automated pentesting.
Thomas Ptacek argues that an open weights model from 2025 with a pentest harness could perform sandbox escapes and hack most networks, suggesting current AI security sandboxes are insufficient.
A comprehensive, open-source penetration-testing knowledge base aggregating hundreds of tools, checklists, and guides across 23 security domains, hosted on GitHub.
Kode Dot is a pocket-sized programmable device with dual ESP32 MCUs, AMOLED touchscreen, wireless connectivity, and I/O pins, designed for makers, pentesters, and geeks.
A fully uncensored cybersecurity-specialized AI model fine-tuned on exploits and pentesting data, designed to run locally on consumer hardware with multiple quantization options, offering expert offensive and defensive insights.
Strix is an open-source AI penetration testing tool that dynamically runs applications in Docker sandboxes, uses the Caido proxy to intercept traffic, and leverages a Python sandbox to write practical Proof-of-Concept exploits to discover and verify vulnerabilities. It supports multi-agent collaboration, automatic patch generation, and CI/CD integration, making it more practical than traditional scanners with high false positive rates.
A tool that integrates AI (any LLM or local Ollama) with Apktool to enable real-time decompiling, Smali analysis, manifest review, vulnerability hunting, and live patching of Android APKs via natural language.
An open-source project named Codex5.5 bypasses GPT-5.5's security restrictions by modifying the model_instructions_file. It supports sensitive operations like SQL injection testing, but carries a risk of account suspension. It is recommended to use a throwaway account.
A GitHub repository providing 144 offensive security skills for reconnaissance and penetration testing, field-validated across 600+ targets in 45+ sectors, covering web enumeration, email security, Google dorks, cloud IAM, and more.
BestDefense.io is a security tool that uses AI to perform penetration testing and automated patching for every deployment.
Open-source HTTP toolkit Hetty, built by David Stotijn as a free alternative to Burp Suite Professional, offers MITM proxy, request interception, and editing capabilities with a single Go binary install, no cost or telemetry.
The tech specs for the Flipper One have been released, highlighting its hardware capabilities designed for cybersecurity testing and pentesting.
A curated GitHub repository collecting inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, and CLI/web tools for system administrators, DevOps, pentesters, and security researchers.
hackingtool v2.0.0 is a Python 3.10+ CLI that bundles 185+ security tools across 20 categories with search, tagging, batch install and Docker support for pentesters and researchers.