Open Source Security Arsenal
Curated intelligence repository of battle-tested open-source security tools, exploits, and pentesting frameworks.
Security Tools
Malcolm - Security Repository
UnknownMalcolm Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
API-s-for-OSINT List of API's for gathering information about phone numbers, addresses, domains etc
AiSOC - Security Repository
UnknownAiSOC Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
brutespray - Security Repository
Unknownbrutespray Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+ protocols.
CTF - Security Repository
UnknownCTF CTF challenge (mostly pwn) files, scripts etc
nexfil - Security Repository
Unknownnexfil OSINT tool for finding profiles by username
FBI-tools - Security Repository
UnknownFBI-tools 🕵️ OSINT Tools for gathering information and actions forensics 🕵️
ScubaGear - Security Repository
UnknownScubaGear Automation to assess the state of your M365 tenant against CISA's baselines
Dorks-collections-list List of Github repositories and articles with list of dorks for different search engines
reconspider 🔎 Most Advanced Open Source Intelligence (OSINT) Framework for scanning IP Address, Emails, Websites, Organizations.
WhatsMyName Community-maintained dataset of 700+ websites for finding accounts by username — powers OSINT and digital footprint tools.
content - Security Repository
Unknowncontent Security automation content in SCAP, Bash, Ansible, and other formats