A curated, battle‑tested collection of offensive, defensive and AI‑powered security tools.
Everything is split into 🔴 Offensive (Red Team), 🔵 Defensive (Blue Team) and 🤖 AI / LLM Security, with sane sub‑categories so you can find the right tool in seconds.
Warning
For authorized security testing and education only. Every tool listed here must be used only against systems you own or have explicit written permission to test. Unauthorized access is illegal. See the Disclaimer.
📑 Table of Contents
- 🔴 Offensive Security (Red Team)
- Reconnaissance — Subdomain / DNS / ASN
- Port Scanning & Network
- HTTP Probing / Crawling / Content Discovery
- JavaScript Analysis & Parameter Discovery
- Fuzzing
- Vulnerability Scanners (Web / App)
- Injection — SQL / NoSQL / Command / SSTI / LFI
- XSS
- Prototype Pollution / Open Redirect / CRLF
- SSRF / Request Smuggling / Web Cache
- GraphQL / API
- CMS / WordPress
- Auth / JWT / Password Cracking
- Deserialization / RMI / XXE
- 403 / 401 Bypass
- C2 / Exploitation / Post-Exploitation
- Out-of-Band (OOB) Interaction
- 🔵 Defensive Security (Blue Team / DevSecOps)
- 🤖 AI / LLM Security
- 🕵️ OSINT
- 🧰 Utilities / Proxies / HTTP Clients
- 📚 Wordlists & Payloads
- 📖 Frameworks, References & Learning
- 🤝 Contributing
- ⚠️ Disclaimer
- 📄 License
No comments yet.