Red teaming
Offensive AI security, tools, and methodologies
Guides and methodologies 50
- OWASP GenAI Red Teaming Guidegenai.owasp.org
- Pillar Security - AI Red Teaming Introductionpillar.security
- AI/LLM Red Team Handbookgithub.com
- AI Pentest Scopingdevansh.bearblog.dev
- How Google Does It: Building an Effective AI Red Teamcloud.google.com
- 3 takeaways from red teaming 100 generative AI productsmicrosoft.com
- A First Look at Python in Excel for Red Team Operationsnetspi.com
- Active Directory - Domain Persistence0xstarlight.github.io
- AI Red Teaming Guide - comprehensive guide to adversarial testing of AI systemsgithub.com
- API Security Testing Using AI in Postman - Dana Eppdanaepp.com
- Auditing JDBC Drivers at Scale with Hacktron CLIhacktron.ai
- Automating Bug Bounty with n8nlampysecurity.com
- Automating the Operator - Integrating LLMs into Offensive Security Workflowsarmadin.com
- Bug Bounty Automation with Python: The Secrets of Bug Huntingsentinel-sec.pro
- Building a hypothesis-driven bug bounty automation system with Claude Code Agent Teamszenn.dev
- Building a Red Team Infrastructure in 2023securesystems.de
- Bypassing Detections with Command-Line Obfuscation - introducing ArgFuscatorwietzebeukema.nl
- Chrome Debugging Protocol - Modern Tradecraftmr-r3bot.github.io
- Code4rena on how to get started as a smart contract auditorx.com
- Critical Thinking Podcast on running Claude for hours of autonomous bug bounty hackingx.com
- Critical Thinking podcast: tips for running AI agents for hacking - log failures, never delete filesx.com
- Cyber Red Teaming - organisational, technical and legal implications in a military contextccdcoe.org
- DEF CON 34: Taming the Swarm - lessons from building a deterministic agentic web pentesting systemdefcon.org
- Digging for Secrets on Corporate Sharesblog.bitsadmin.com
- Dissecting redis CVE-2023-28425 with chatGPT as assistanttin-z.github.io
- Finding Zero-Days with Any Model - Niels Provosprovos.org
- From Patch to Exploit - using Claude Code to reverse engineer a zero-day in PaperCut NGtechanarchy.net
- Hacking Google with A.I. for $500,000brutecat.com
- How I Used AI to Create a Working Exploit for CVE-2025-32433 Before Public PoCs Existedplatformsecurity.com
- How to build an offensive AI security agentanshumanbhartiya.com
- How to Google Dork a Specific Website for Hackingstationx.net
- Josh Terrill on a Windows patch-diffing and exploit research workflow using LLM analysisx.com
- Living off the landposts.slayerlabs.com
- Methodology - offensive security testing methodologies for pentesters and red teamersgithub.com
- Microsoft 365 Enumerationguillaumeben.xyz
- Nagli's thread on subdomain recon methodology for bug bounty targeting deepseek.comx.com
- Navigating AI, Fighting Skynet - Using AI for adversarial engineeringblog.zsec.uk
- Phishing Like a Pro: Adding SPF, DMARC, DKIM and MX records to Evilginxfortbridge.co.uk
- Pivoting from Microsoft Cloud to On-Premise Machineswhiteknightlabs.com
- Red Team Maturity Model - a model for building and improving your internal Red Teamredteams.fyi
- Red Teaming with ServiceNowmdsec.co.uk
- Running an Adversary Emulation Exercise - Culbert Reportgit.culbertreport.com
- ScriptBlock Smugglingbc-security.org
- SunSec's generic CDC-style vulnerability research prompt, inspired by a $500K RCE found for $25x.com
- The Bug Bounty Playbook - TTPs, methodology and tradecraft for bug bounty huntingbugbounty.info
- The Bug Bounty Singularity: Our Hackbot - Joseph Thackerjosephthacker.com
- The Bug Hunter's Methodology v4 - Recondrive.google.com
- The Mythos We Have At Home - A Patch-Diffing Pipeline for N-Day Generationoriginhq.com
- Tunnel via Cloudflare to any TCP Serviceiq.thc.org
- Tur.js on bypassing Cloudflare mTLS protection in a banking app with Fridax.com
Tools 340
- P4RS3LT0NGV3elder-plinius.github.io
- Opcode.shopcode.sh
- claude-bug-bounty: AI-powered bug bounty hunting toolkitgithub.com
- Introducing Neo, an AI security engineer for complex security tasksprojectdiscovery.io
- Partnering with Caido to Bring Precision & Control to Agentic Pentestingstrix.ai
- pwn.ai - Autonomous AI Penetration Testingpwn.ai
- Giving an Agent a Rooted Android Phoneworkers.io
- abliteration.ai - uncensored LLMs and Policy Gateway for AI red teaming and pentest workflowsabliteration.ai
- ActiveMQ-RCE - Apache ActiveMQ RCE exploit toolgithub.com
- adauth - Active Directory authentication library for pentest toolinggithub.com
- AddUser-SAMR - create local admins via the SAMR APIgithub.com
- ADOKit - Azure DevOps Services Attack Toolkitgithub.com
- ADPathFinder - OpenGraph Attack Path Mapping in BloodHound CEnetspi.com
- adscan - Active Directory pentesting tool for Linuxgithub.com
- afrog - security tool for bug bounty, pentest and red teaminggithub.com
- agentic_security - Agentic LLM vulnerability scanner and AI red teaming kitgithub.com
- AI HTTP Analyzer - Burp Suite extension using AI to find vulnerabilities in HTTP trafficportswigger.net
- ai-classifier - AI safety evaluation framework testing LLM apps against adversarial prompt datasetsgithub.com
- ai_tabletop_world_builder - AI-powered cybersecurity war-gaming and tabletop exercise platformgithub.com
- aimap - Bishop Fox internet-scale discovery and security testing of exposed AI servicesgithub.com
- AirSnitcher - Wi-Fi client isolation testing toolkit for Kaligithub.com
- amber - read and write Burp Suite Proxy HTTP history byte for bytegithub.com
- ANIMO - Azure and Entra ID red team C2 platformgithub.com
- Announcing AI-driven Caidocaido.io
- APIDetector - scan for exposed Swagger API endpointsgithub.com
- apkX - advanced APK and iOS security analysis toolgithub.com
- ArgusRed - AI security scan and pen test CLIargusred.com
- Arsenal - pentest command inventory and launchergithub.com
- arsenal-ng - Go-based pentest command launcher with cheat-sheetsgithub.com
- AtlasReaper - recon and write ops on Confluence and Jiragithub.com
- AutoAR - automated bug bounty recon and attack-surface platformgithub.com
- AutoPentestX - automated penetration testing and vulnerability reporting toolkitgithub.com
- AutoRMM - EDR-on-EDR Violence red team toolkitgithub.com
- AWS Security Agent on-demand penetration testing is now generally availableaws.amazon.com
- AWS Security Agent on-demand penetration testing now generally availableaws.amazon.com
- AZexec - Azure and Entra ID offensive execution toolgithub.com
- azure-storage-reverse-shell - reverse shell via Azure Storage blobsgithub.com
- BadTakeover-BOF - Beacon Object File for BadSuccessor dMSA account takeovergithub.com
- BadZure - deploy intentionally misconfigured Entra ID tenants with attack pathsgithub.com
- baobab - Tree-based conversation UI for LLM APIsgithub.com
- bebiks releases SSRF Utility tool for bug hunters to discover and exploit SSRF vulnsx.com
- BitUnlocker - BitLocker downgrade attack for CVE-2025-48804github.com
- Bluetooth LE Spam - Android app for phantom BLE device advertisementsgithub.com
- BOFHound AD CS Integration - SpecterOpsposts.specterops.io
- brainstorm - LLM-powered web fuzzing tool combining local models with ffufgithub.com
- Brainstorm Tool Release: Optimizing Web Fuzzing With Local LLMsinvicti.com
- BruteForceAI - AI-powered login brute-force toolgithub.com
- BucketHoarder - search and download files from open cloud buckets via GrayHat Warfaregithub.com
- bugSkills - convert HackerOne bug reports into reusable AI skill filesgithub.com
- Burp Pentest Coverage Tracker - Burp Suite extension for tracking tested endpointsgithub.com
- Burp Variables - store and reuse variables in requests, Burp Suite extensionportswigger.net
- burp-deepseek - Burp extension using DeepSeek for AI security analysisgithub.com
- Burp2API - convert Burp Suite projects into JSON APIsgithub.com
- burpference - LLM-powered Burp Suite extension for analyzing proxy trafficgithub.com
- burpgpt - Burp Suite extension using GPT for vulnerability discoverygithub.com
- BurpQL - AI-optimized query engine for Burp Suite HTTP trafficgithub.com
- BurpSuite 403Bypasser - Burp extension to bypass 403 restricted directoriesgithub.com
- Cable - .NET post-exploitation toolkit for Active Directory reconnaissance and exploitationgithub.com
- Caido - web hacking toolkitcaido.io
- cariddi - crawl and scan URLs for endpoints, secrets, and tokensgithub.com
- cerberus-re - Apple reverse-engineering workbench for coding agentsgithub.com
- CFR - Java decompilergithub.com
- Chrome-App-Bound-Encryption-Decryption - bypass Chromium App-Bound Encryptiongithub.com
- chrome-suite - Chrome DevTools HTTP workbench with built-in AIgithub.com
- chromedb - read Chromium cookies and local storage from diskgithub.com
- ChromeKatz - dump cookies and credentials from Chrome/Edge process memorygithub.com
- Chrown - Google Chrome extension exploitation framework for pentestersgithub.com
- cirro - cloud and identity attack-path research platformgithub.com
- Citrix Virtual Apps and Desktops XEN Unauthenticated RCE Exploitgithub.com
- Clearwing - autonomous AI vulnerability scanner and pentest agent, open-source Glasswing alternativegithub.com
- CloakQuest3r - uncover origin IP behind Cloudflaregithub.com
- cloudproxy - provision cloud proxy servers to hide scraper IPsgithub.com
- CloudRecon - Finding assets from certificatesgithub.com
- CodeNeedle - covert VS Code extension for post-exploitation runtime code executiongithub.com
- Coercer - coerce Windows servers to authenticate to an arbitrary machinegithub.com
- Collector - Burp Suite extension for dynamic token collection and injectiongithub.com
- Containers - Red Team tools containerizedgithub.com
- convoC2 - C2 infrastructure over Microsoft Teamsgithub.com
- CORScanner - CORS misconfiguration vulnerability scannergithub.com
- cr0nym on EDRmetry Playbook - 280 Linux offensive techniques for validating EDR detection coveragex.com
- Crassus - Windows privilege escalation discovery toolgithub.com
- CredMaster - password spraying tool with IP rotation via FireProxgithub.com
- CredSpy - Entra ID user enumeration and auth method discovery via GetCredentialType APIgithub.com
- crt.name - Certificate Transparency subdomain searchcrt.name
- crt.sh - Certificate Transparency log search for subdomain reconcrt.sh?q=%25.domain.com
- crtmon - real-time Certificate Transparency subdomain monitorgithub.com
- CSP Bypass - search tool for bypassing restrictive Content Security Policiescspbypass.com
- ctail - tail Certificate Transparency logs and extract hostnamesgithub.com
- curing - io_uring based rootkit PoC that evades syscall-monitoring security toolsgithub.com
- curl-impersonate - curl patched to mimic Chrome, Firefox and Safari TLS fingerprintsgithub.com
- CursedChrome - malicious Chrome extension implant for red teamsgithub.com
- Custom AI Agent - Burp Suite extension with MCP tooling, AI-assisted analysis and scanninggithub.com
- CVE-2024-6387_Check - regreSSHion OpenSSH vulnerability scannergithub.com
- Cybermes - autonomous offensive security and bug bounty agent frameworkgithub.com
- cygor - modular asset discovery and service enumeration frameworkgithub.com
- Deep Eye - AI-driven penetration testing toolgithub.com
- Deep Hat, formerly WhiteRabbitNeo - Kindo's uncensored offensive security AI modelwhiterabbitneo.com
- DeepTeam - LLM and AI agent red teaming frameworkgithub.com
- depthfirst launches Bug Bounty Verification - agentic pentesting to validate vulnerability reportsx.com
- digitalocean-app-redirector - reverse-HTTP redirector via DigitalOcean Apps for red team infragithub.com
- dirtyfrag - Universal Linux LPE exploitgithub.com
- DISintegrity - analyse Android APK root and tamper detection checksgithub.com
- DonPAPI - remote DPAPI credential dumpinggithub.com
- Doppelganger ATLAS - physical security operations platformatlas.mwgroup.io
- Douglas Day shares his Claude Code init-target.sh script for bug bounty target setupx.com
- DSViper - Windows Defender bypass and payload evasiongithub.com
- DumpChromeSecrets - extract credentials, cookies and tokens from Chromegithub.com
- DutchOven - application-scoped Windows network brownouts for red-team validationgithub.com
- eaphammer - evil twin attacks against WPA2-Enterprise networksgithub.com
- Easy EASM - The Zero-Dollar Attack Surface Management Tool - Recon Village DEF CON 31youtube.com
- eCaptureBurp - Burp Suite extension for TLS traffic captured by eCapture eBPFgithub.com
- EDRChoker - Choking the Telemetry Stream to Bypass Defenseszerosalarium.com
- EDRChoker - throttle EDR agents via QoS policy to bypass defensesgithub.com
- emploleaks - OSINT tool to detect company members with leaked credentialsmeterpreter.org
- EmploLeaks - OSINT tool to find company employees with leaked credentialsgithub.com
- EmploLeaks - OSINT tool to find company employees with leaked credentialsgithub.com
- EntraPassTheCert - Entra ID P2P certificate post-exploitation toolgithub.com
- Enumprotections_BOF - enumerate process protection levelsgithub.com
- EvilMist - cloud pentest and red team toolkitgithub.com
- ExpiredDomains.net - aged expired domain search for phishing infrastructureexpireddomains.net
- eyeballer - Convolutional neural network for analyzing pentest screenshotsgithub.com
- F31 - Kali Linux network noise reduction toolgithub.com
- Faction - OWASP pen test report generation and assessment collaboration frameworkgithub.com
- FFUF-Workflow-Tool - automated ffuf web fuzzing and post-processinggithub.com
- File-Tunnel - tunnel TCP connections through a filegithub.com
- FindMyFlipper - AirTag and SmartTag emulator for FlipperZerogithub.com
- FormThief - spoofing Windows desktop login appsgithub.com
- frogy2.0 - Automated external attack surface intelligence toolkitgithub.com
- frogy2.0 - automated external attack surface toolkit scriptgithub.com
- gau - fetch known URLs from AlienVault OTX, Wayback Machine and Common Crawl for recongithub.com
- ghidra-rpc - agentic Ghidra reverse engineering skill for LLM coding assistantsgithub.com
- Ghost ESP - ESP32 pen-testing firmwaregithub.com
- Gideon - open-source autonomous security operations and red teaming agentgithub.com
- GitHound - BloodHound OpenGraph collector for GitHub attack pathsgithub.com
- GitPhish - GitHub device code flow phishing assessment toolgithub.com
- gluegate - proxy memory APIs via signed mozglue.dllgithub.com
- gofuzz - recursively extract URLs and secrets from JavaScript files with JSluice and Nucleigithub.com
- GoLinHound - BloodHound collector for Linux and SSH attack pathsgithub.com
- GPOHound - Offensive GPO dumping and analysis tool built on BloodHound datagithub.com
- Grapefruit - open-source mobile security testing suite for iOS and Androidcodecolor.ist
- Graphpython - Microsoft Graph API enumeration and exploitation toolkitgithub.com
- graphqlMaker - LLM-assisted tool to find GraphQL queries in JavaScript filesgithub.com
- GraphRobber - Microsoft Graph API post-exploitation frameworkgithub.com
- GraphRunner - Post-exploitation toolset for the Microsoft Graph APIgithub.com
- GraphSpy - Initial access and post-exploitation tool for Entra ID and M365github.com
- guardian-cli - AI-powered penetration testing automationgithub.com
- gungnir - certificate transparency log scannergithub.com
- Hackmap - graphing and note-taking tool built for pentestingx.com
- HackMap - local pentest mapping tool with visual attack paths and live command executiongithub.com
- HAHWUL on ShadowShell - a Caido plugin for in-app terminalsx.com
- HaxRob on Wedgeberry - script for isolated IoT testing with mitmproxy, VPN, Tor or Burpx.com
- HUNT - Burp Suite and OWASP ZAP extensions for finding vulnerable parametersgithub.com
- HuntProxy - web security workbench for AI agentsgithub.com
- IceKube - finding complex attack paths in Kubernetes clusterslabs.withsecure.com
- IDOR Tester - AI-assisted IDOR and BOLA hunting for Burp Suitegithub.com
- Intelligent Cyber Adversary Emulation with the Bounty Hunterlolcads.github.io
- Introducing open-kritt - open-source AI vulnerability research platformkritt.ai
- ipfuscator - generate alternative IPv4 address representations for filter bypassgithub.com
- iwa-tools - offensive Active Directory tradecraft in a browser tabiwa-tools.pkilla.pw
- Jailbreaker-CE - SpecterOps local evaluation harness for jailbreak and prompt-injection testinggithub.com
- JD Java Decompilerjava-decompiler.github.io
- JNDI-Exploit-Kitgithub.com
- Joseph Thacker on Caido's GraphQL SDKs making it better than Burp for Claude Codex.com
- JS-Tap: Weaponizing JavaScript for Red Teamstrustedsec.com
- JSAnalyzer - Burp extension for JavaScript static analysisgithub.com
- jshunter-burp - Burp extension that scans JavaScript files for secrets with TruffleHoggithub.com
- JSMon - JavaScript change monitor for bug bountygithub.com
- jsmon - JavaScript change monitoring tool for bug bountiesgithub.com
- jsmon-go - JavaScript change monitor for bug bounty huntinggithub.com
- jsmon.sh - JavaScript change monitoring for bug bounty reconbeta.jsmon.sh
- jsrip - crawl and analyze JavaScript for secrets and endpointsgithub.com
- k8scout - Kubernetes attack path engine for compromised podsgithub.com
- kanti - web application testing proxy for capturing and modifying HTTP requestsgithub.com
- khaos-c2 - modern C2 post-exploitation framework with covert channelsgithub.com
- KingCastle - LDAP-based Active Directory overview for internal pentestsgithub.com
- Kiosk Tooling - browser tools for kiosk breakout and lateral movementkiosk.vsim.xyz
- KrakenHashes - distributed password cracking systemgithub.com
- Krueger - remotely kill EDR with WDACgithub.com
- KubeHound - Kubernetes attack graph and attack path toolgithub.com
- L0phtCrack password auditing tool is now open sourcel0phtcrack.gitlab.io
- LabForge - Visual cyber range designer for red team lab environmentsgithub.com
- LDAPmonitor - live monitoring of LDAP object changes during pentestsgithub.com
- ldapnomnom - bruteforce Active Directory usernames via LDAP Pinggithub.com
- LDAPWordlistHarvester - extract client wordlist from Active Directory LDAPgithub.com
- Leonidas - automated attack simulation in the cloudgithub.com
- liffy - Local File Inclusion exploitation toolgithub.com
- linWinPwn - Active Directory pentesting toolkitgithub.com
- LLMFuzzer - fuzzing framework for large language modelsgithub.com
- Logisek on SharePointEnum - EvilMist PowerShell tool for red team SharePoint Online search and downloadx.com
- loophole - adversarial agents that stress-test moral principles, system prompts and legal codesgithub.com
- lorito - HTTP security suite for exploiting web vulnerabilities and logging callbacksgithub.com
- Ludus - cyber range platform documentationludus.cloud
- Maestro - Abusing Intune for Lateral Movement Over C2posts.specterops.io
- Magic-Atomics - prevention-focused LOL testing framework mapped to MITRE ATT&CKgithub.com
- malicious-pdf - generate malicious PDF test filesgithub.com
- MANSPIDER - crawl SMB shares for sensitive files and contentgithub.com
- Mantra - recon tool for finding API keys in JavaScript files and HTML pagesx.com
- MapperPlus - source map extractor that recovers source code from exposed .js.map filesgithub.com
- maSSO - malicious IdP for OIDC and SAML SSO security testinggithub.com
- Max - suite of tools for maximizing BloodHound, including the Domain Password Audit Toolgithub.com
- MDE_Enum - Enumerate Windows Defender exclusions and ASR rules without admingithub.com
- MHDDoS - DDoS attack toolkit with 56 methodsgithub.com
- Michael Bargury drops powerpwn v4 to hack public Microsoft Copilot Studio agentsx.com
- mitmproxy2swagger - reverse-engineer REST APIs from captured trafficgithub.com
- MOAK - Mother of All KEVs, agentic AI to exploit vulnerabilitiesmoak.ai
- Moxy - agentic AI DAST tool for pentestinggithub.com
- MSSQLHound - MSSQL attack path collector for BloodHoundgithub.com
- MSSqlPwner - MSSQL pentesting and lateral movement toolgithub.com
- NachoVPN - rogue SSL-VPN server to exploit VPN clientsgithub.com
- Nemesis - SpecterOps offensive data enrichment pipelinegithub.com
- neobotnet - web intelligence platform mapping bug bounty attack surfaceneobotnet.com
- NetExec Timeroast module - unauthenticated brute force of AD computer accounts via NTPx.com
- newtowner - abuse trust-boundaries to bypass firewalls and network controlsgithub.com
- nezha_cyber - DeepSeek-driven TUI red team assistantgithub.com
- nmapsilent - convert Nmap output for Project Discovery tool pipelinesgithub.com
- NoFilter - Windows Filtering Platform privilege escalationgithub.com
- Nord Stream - extract CI/CD secrets by deploying malicious pipelinesgithub.com
- nuclei-burp-plugin - Nuclei template generator plugin for Burp Suitegithub.com
- NucleiFuzzer - web application vulnerability scannergithub.com
- numasec - AI agent for cyber securitygithub.com
- offsec-tools - compiled offensive security toolsgithub.com
- onvifscan - IoT pentesting scanner for ONVIF devicesgithub.com
- Osmedeus - orchestration engine for offensive securitygithub.com
- Osmedeus - orchestration engine for security reconnaissance and vulnerability scanning workflowsosmedeus.org
- ParamAngler - per-parameter payload testing tool for web app bugsgithub.com
- Parameter discovery tools comparison - x8 vs Arjun vs Param Miner4rt.one
- Parrot Security OS - Linux distribution for penetration testing and privacyparrotsec.org
- Passkey Raider - Burp Suite extension for testing Passkey systemsgithub.com
- Payload Wizard - AI assistant for generating cybersecurity payloadspayload-wizard.vercel.app
- Pensar Apex - AI-powered autonomous pentesting agents in your terminalgithub.com
- PentAGI - autonomous AI agents for penetration testinggithub.com
- pentest-copilot - AI-powered ethical hacking assistantgithub.com
- Pentest-Mapper - Burp Suite extension for pentest checklists and flow mappinggithub.com
- periscope - automated web recon and discovery tool with Burp Suite extensiongithub.com
- PETEP - penetration testing proxy for TCP/UDP traffic analysis and modificationgithub.com
- Phishing Club - phishing simulation and red team frameworkgithub.com
- pius - attack surface discovery and OSINT reconnaissance toolgithub.com
- Porch Pirate - Postman recon and OSINT framework for exposed API endpointsgithub.com
- PositiveIntent - Evasive loader for .NET Framework assembliesgithub.com
- PowerHuntShares 2.0 - hunting SMB shares with charts, graphs, passwords and LLM magicnetspi.com
- Praxis - semantic command and control framework for computer-use agentspraxis.originhq.com
- pre-bounty - agent skill to map bug-bounty scope and rank targets - Forefy AI Security Registryforefy.com
- Promptfoo - AI security platform for testing and red-teaming LLM applicationspromptfoo.dev
- proxyblob - SOCKS5 proxy over Azure Storagegithub.com
- ProxyBlobing into your network - SOCKS5 tunneling through Azure Blob Storageblog.quarkslab.com
- PugRecon - Subdomain and public bucket intelligence for attack surface reviewdash.pugrecon.celes.in
- PwNixOS - a hacking-oriented NixOS flakegithub.com
- pwnproxy - local-first security testing platform for pentesters, AI agents and CI/CDgithub.com
- pyLDAPGui - Python GUI for browsing LDAP with BloodHound exportgithub.com
- QRL Web - air-gap file transfer via QR code sequencesminimike86.github.io
- rbndr.us - DNS rebinding testing servicelock.cmpxchg8b.com
- Reaper - MITM proxy for application security testing by humans and AI agentsgithub.com
- ReconAIzer - Burp Suite extension using OpenAI GPT for bug bounty recongithub.com
- reconftw_ai - local LLM analysis of reconftw recon resultsgithub.com
- red-clippy - open-source pentest management built to be operated by an AI agentgithub.com
- RedAI - AI-driven vulnerability discovery and live validationgithub.com
- redteam-collab - red team collaboration infrastructuregithub.com
- redteam-infra - reference deployment recipes for red team infrastructuregithub.com
- redteamtl - red team assessment timeline visualization toolgithub.com
- RegIntel - AI-powered pentest regulatory intelligence with LangGraph agentsgithub.com
- remotechrome - dump Chrome cookies remotely via atexec and CDPgithub.com
- repshot - Burp Suite extension to generate security finding cardsgithub.com
- ResetNightmare - POC for CVE-2026-27912 Kerberos password resetgithub.com
- Reverse Shell Generator - revshells.comrevshells.com
- reverse-skill - AI reverse engineering and pentest skill router for coding agentsgithub.com
- Rogue - LLM agent for automated web vulnerability scanninggithub.com
- RogueSliver - tools to disrupt Sliver C2 campaignsgithub.com
- RSC_Detector - React Server Components fingerprinting and CVE-2025-55182 exploitationgithub.com
- RunasCs - open Csharp version of Windows runas.exegithub.com
- Rusty-Telephone - audio covert channel data exfiltrationgithub.com
- s3tk - S3 bucket security scanner for bug bounty and pentestinggithub.com
- samoscout - LLM-powered passive and active subdomain enumeration toolgithub.com
- SCOPE - AI agent for cloud security purple teaminggithub.com
- ScrappyDoo - OpenGraph-compatible JSON generator for BloodHoundgithub.com
- scrying - NCC Group tool for collecting RDP, web and VNC screenshotsgithub.com
- SecLists - the security tester's companion wordlistsgithub.com
- SecorizonAI - terminal-native AI shell for pentestersgithub.com
- SetupHijack - exploit race conditions in Windows installersgithub.com
- ShadowClone - distribute recon and bug bounty tasks across serverless functionsgithub.com
- ShadowHound - a SharpHound alternative using native PowerShellblog.fndsec.net
- ShareFiltrator - SharePoint sensitive file enumeration and bulk downloadgithub.com
- SharpShares - enumerate accessible network shares in a domaingithub.com
- shortscan - IIS short filename enumeration toolgithub.com
- Shwmae - Windows Hello abuse toolgithub.com
- Singularity of Origin - DNS rebinding attack frameworkgithub.com
- sj - Swagger Jacker, auditing tool for exposed Swagger/OpenAPI definition filesgithub.com
- Slack Jack - Hijack a Slack bot token for phishing and enumerationgithub.com
- smokedmeat - CI/CD red team frameworkgithub.com
- SmokedMeat: A Red Team Tool to Hack Your Pipelines Firstlabs.boostsecurity.io
- Sn1per - automated penetration testing and attack surface management platformgithub.com
- Snaffler - find credentials in Windows/AD file sharesgithub.com
- spy-extension - Chrome extension that steals everything it cangithub.com
- SSH-Snake - self-propagating SSH key and host discovery toolgithub.com
- SSHamble - runZero research tool for attacks against SSH implementationsgithub.com
- Sshimpanzee - reverse SSH server with ICMP, DNS and HTTP tunnelling for red team post-exploitationblog.lexfo.fr
- SSRFUtility - SSRF exploitation toolssrf.cvssadvisor.com
- STE.GG - steganography encode, decode and analyze toolste.gg
- steampipe-plugin-projectdiscovery - query ProjectDiscovery recon tools with SQLgithub.com
- Stepping Stones - A Red Team Activity Hubnccgroup.com
- subby - fast subdomain enumeration toolgithub.com
- SuperSharpShares - automated domain SMB share enumerationgithub.com
- sw33tLie on uff, his ffuf fork for bug bounty fuzzingx.com
- SysReptor - pentest reporting platformgithub.com
- T3MP3ST - autonomous multi-agent offensive-security red teaming platformgithub.com
- T3MP3ST - autonomous multi-agent offensive-security red teaming platformgithub.com
- TaskHound - hunting privileged scheduled tasks on remote systemsr0bit.io
- TeamsPhisher - send phishing messages and attachments to Microsoft Teams usersgithub.com
- teamstracker - monitoring Microsoft Teams user presence via Graph proxygithub.com
- Tenzai - AI hacker for enterprise, autonomous penetration testing agentstenzai.com
- Terra Security - Agentic Offensive Security Platformterra.security
- The Shelf - retired TrustedSec offensive security capabilitiesgithub.com
- thermoptic - HTTP stealth proxy that cloaks requests as Chrome to defeat fingerprintinggithub.com
- Tib3rius announces Collector, a Burp Suite extension for collecting and tracking tokensx.com
- TokenCert - network token creation via certificates using PKINITgithub.com
- TokenFlare: Serverless AiTM Phishing in Under 60 Secondslabs.jumpsec.com
- Trickest - security execution platform for ASM, scanning, and agentic pentesting workflowstrickest.com
- Trickest - security execution platform for offensive security workflows and agentic pentestingtrickest.com
- TTPRunner - autonomous TTP execution agent for purple teaminggithub.com
- uff - unleashed ffuf fork for web fuzzinggithub.com
- uncover - discover exposed hosts on the internet using multiple search enginesgithub.com
- USB Army Knife - close-access tool for pentesters and red teamersgithub.com
- VERDICT - autonomous AI web and API pentest agentgithub.com
- Verizon AI Burp Extensions - VAIBE, AI-assisted Burp Suite extension suitegithub.com
- Vespasian - API discovery and spec generation from live trafficgithub.com
- Visa Vulnerability Agentic Harness - PR #10 document update adding two phasesgithub.com
- VMkatz - extract Windows credentials from VM snapshotsgithub.com
- waymore - find URLs from Wayback Machine and other archivesgithub.com
- web-check - all-in-one OSINT tool for analysing any websitegithub.com
- WinSSHound - Windows SSH misconfiguration discovery for AD lateral movement pathsgithub.com
- Wonka - extract Kerberos tickets from the LSA cachegithub.com
- wpprobe - fast WordPress plugin enumeration toolgithub.com
- wsuks - automating the WSUS MITM attackgithub.com
- XBOW - autonomous AI offensive security and pentesting platformxbow.com
- XBOW Embeds Continuous, AI-Driven Penetration Testing in the Microsoft Security Ecosystemxbow.com
- XBOW pricing - autonomous AI penetration testing platformxbow.com
- xnLinkFinder - discover endpoints, parameters, wordlists and secrets for a targetgithub.com
- XSinator - XS-Leak browser test suitexsinator.com
- Yak Project - open-source security infrastructure with Yakit, IRify static analysis and Memfit AIyaklang.io
- yaklang - a programming language designed for cybersecuritygithub.com
- ZANCUDO - open-source MQTT interception proxy for IoT pentestingversprite.com
Resources 134
- List of AI Hackigithub.com
- If you're using AI for bug bounty, you already know the twox.com
- It is hard to communicate how much bug bounty has changed duex.com
- A secure way to code via Signal. Ingithub.com
- Gandalf - Lakera – Test your AI hacking skillsgandalf.lakera.ai
- finbot-ctf - Vulnerable Agentic AI Platform for AI Security CTFgithub.com
- AI hacking agents keep rejecting your requests? Drop a legit-looking pentest authorization,x.com
- 🛡⚔️AI-Powered Penetratigithub.com
- Fully autonomous AI hacker to find actgithub.com
- Announcing BlackIce: A Containerized Red Teaming Toolkit for AI Secdatabricks.com
- Automatic Exploit Generationgithub.com
- On the Coming Industrialisation of Exploit Generation with LLMssean.heelan.io
- It's the wildest thing these LLM pentesting frameworks blindly trust output fromx.com
- EVA is an AI-assisted penetration testing agithub.com
- Frontier Model Performance on Offensive-Security Tasks: Emerging Evirregular.com
- LLM-Powered AMSI Provider vs. Red Team Agentdreadnode.io
- Practical LLM Security Advice from the NVIDIA AI Red Team - NVIDIAdeveloper.nvidia.com
- BlackIce: A Containerized Red Teaming Toolkit for AI Security Testingarxiv.org
- A project to automate the pentegithub.com
- Hacking with AI SASTs: An overview of 'AI Security Engineers' /joshua.hu
- How We Exploited CodeRabbit: From a Simple PR to RCE and Writeresearch.kudelskisecurity.com
- PentestJudge: Judging Agent Behavior Against Operational Requirements -https://t.co/UgM49zhppJ by @dreadnode Introducing PentestJudge,x.com
- The Deepfake Offensive Toolkitgithub.com
- GPT-5 Under Fire: Red Teaming OpenAI's Latest Model Reveals Surprsplx.ai
- Learn Prompting: Your Guide to Communicating with AIlearnprompting.org
- Critical Langflow RCE flaw exploited to hack AI app serversbleepingcomputer.com
- OWASP LLM Exploit Generation v1.0 - OWASP Top 10 for LLM &genaisecurityproject.com
- Prompt Airlines - AI CTF by Wizpromptairlines.com
- Project Naptime: Evaluating Offensive Security Capabilities of Larggoogleprojectzero.blogspot.com
- Talos launching new machine learning-based exploit detection engineblog.snort.org
- An Empirical Evaluation of LLMs for Solving Offensive Security Chalarxiv.org
- Announcing Microsoft's open automation framework to red team generamicrosoft.com
- A collection of real world AI/ML exgithub.com
- OpenAI Needs To Fix ChatGPT Exploit Before its Store Openstech.co
- Google's AI Red Team: the ethical hackers making AI saferblog.google
- FakeToxicityPrompts: Automatic Red Teaminginterhumanagreement.substack.com
- Announcing OpenAI's Bug Bounty Programopenai.com
- acedef/SynthAPTgithub.com
- Whomp whompx.com
- CrowdStrike Secures AI Attack Surface with Falcon AIDRcrowdstrike.com
- CVE-2025-6515 Prompt Hijacking Attack - How Session Hijacking Affecjfrog.com
- Attacking AI (Live, August 18th & 20th)arcanum-sec.com
- SHIFT - AI-Powered Hackingshiftwaitlist.com
- AttackGen is a cybersecurity incidentgithub.com
- The AI Attack Surface Map v1.0danielmiessler.com
- MUZZLE: Adaptive Agentic Red-Teaming of Web Agents Against Indirect Prompt Injection Attacksarxiv.org
- One Proxy. One AI. One System: Integrating Caido into mastermind-ailabs.trace37.com
- Introducing Assessment Guidance: Map Your Brain Onto XBOW'sxbow.com
- Teaching Claude Everything You've Hackedclawd.it
- How My AI Hunting System Found Two Critical Vulns in a Private Bug Bounty — While I Was Outlabs.trace37.com
- How We Hacked McKinsey's AI Platformcodewall.ai
- Pwning AI Code Interpreters in AWS Bedrock AgentCorebeyondtrust.com
- Killer Agent Framework Featuresexecutiveoffense.beehiiv.com
- How do frontier AI agents perform in multi-step cyber-attack scenarios?aisi.gov.uk
- The new HTB Certified Offensive AI Expert (HTB CO-AE) is officially hereacademy.hackthebox.com
- I Took HTB's AI Red Teamer Path. Here's What I Think.itsbroken.ai
- METATRON: AI-Powered Penetration Testing Assistantgithub.com
- Assessing Claude Mythos Preview's cybersecurity capabilitiesred.anthropic.com
- Building an Automated Pipeline with LangChain DeepAgents to Find Zero-Days in Kernel Drivers. It Found One in ASUS.blog.ahmadz.ai
- llm-rtk: Objective-driven adversarial testing framework for GenAI systems aligned with OWASP GenAI Top 10 risksgithub.com
- Abliteration.ai releases abliterated GLM-5.3 for offensive cyber and red teamingx.com
- Adam Chester on using Claude Code channels in CI to auto-evade YARA detectionsx.com
- Aether AI: the agentic attack AI that learns from every pentest so defences improve at machine speedtryaether.ai
- ai-red-team-course - 8-week course from web/API/cloud hacker to AI red teamergithub.com
- alldomains - bug bounty domain and subdomain listsgithub.com
- Arcanum AI Security Resource Hub - labs, CTFs, bounties and tooling for AI red teamingarcanum-sec.github.io
- Arcanum Security - Jason Haddix's offensive security and AI security training and consultingarcanum-sec.com
- Authorized - AI-drafted letters of authorization for security testingauthorized.xultra.fun
- Awesome OSINT For Everythinggithub.com
- awesome-lolbins-and-beyond - curated list of LOLBins, GTFO and Living Off the Land resourcesgithub.com
- BloodHound Ecosystem - curated list of BloodHound tools and collectorsgist.github.com
- Buffer Overflow cheatsheet - guif.reguif.re
- byor - Build-Your-Own-Ransomware hands-on exercisesgithub.com
- Can AI do novel security research? Meet the HTTP Terminatorportswigger.net
- can-i-take-over-xyz - subdomain takeover referencegithub.com
- Comparing AI Application Security Testing Platformsblog.doyensec.com
- copy.golf - golf your exploitscopy.golf
- Corben Leo - bug bounty find from a 404 route disclosurex.com
- CrowdStrike Launches AI Red Team Services to Secure AI Innovationcrowdstrike.com
- Dead.Letter - How XBOW found an unauthenticated RCE on Eximxbow.com
- DefaultCreds-cheat-sheet - default credentials list for red and blue teamersgithub.com
- DevOps Attack Surface - Pentester's Guide to CI/CD pipeline attacksarcanum-sec.github.io
- Disclosure Index - searchable archive of 11,000+ public bug bounty disclosuresbug-bounty-disclosures.vercel.app
- drift-corpus - Windows kernel patch diffs produced by an AI reverse engineering agentgithub.com
- DVKA - Damn Vulnerable Kubernetes Applicationgithub.com
- Evaluating and mitigating the growing risk of LLM-discovered 0-daysred.anthropic.com
- Everything I Own, Owned - reverse engineering five consumer peripherals with a Claude agentschlarp.com
- Forefy AI Security Registry - audit-goal for AI-driven security assessmentsforefy.com
- From a Copilot to Cluster Admin: inside AtlasOps, Pillar Security's free agent-security CTFpillar.security
- GPT-5.5: Mythos-Like Hacking, Open to All - XBOW's early-access offensive security evaluationxbow.com
- grimoire - Offline full-text search across offensive security knowledge basesgithub.com
- GTFOArgs - argument injection exploitation vector list for Unix binariesgtfoargs.github.io
- GTFOBinsgtfobins.org
- Hack-A-Sat - Space Cybersecurity CTFhackasat.com
- How I used o3 to find CVE-2025-37899, a remote zeroday vulnerability in the Linux kernel's SMB implementationsean.heelan.io
- How pentesting mirrors the evolution of quality assurancetldrsec.com
- HSC24RedTeamInfra - Red Team Infrastructure Automation workshop slides and codegithub.com
- It's More Than Saying No - when leadership asks your offensive security team to do work it wasn't designed forandywgrant.substack.com
- Lessons from Red Teaming 100 Generative AI Products - Microsoft AI Red Team whitepaperairedteamwhitepapers.blob.core.windows.net
- Live Bug Bounty Recon & Enumeration - HackerOne Starbucks programyoutube.com
- Local AI for Penetration Testing and Researchprojectblack.io
- LVE Repository - documenting vulnerabilities and exposures of large language modelslve-project.org
- Mehdi on compact tools for hardware and physical pentestingx.com
- Mid-Year 2026 AI Model Security Research Report - XBOWxbow.com
- Nagli on a DNS fuzzing recon challenge to find hidden subdomainsx.com
- Nathan McNulty on capturing network traffic with edge://net-exportx.com
- OnlyLANs - deliberately vulnerable AI assistant challenge by Just Hacking Trainingonlylans.justhacking.com
- OWASP Juice Shopdemo.owasp-juice.shop
- Pentester vs AI CTF - race the AI on weekly security challengespentester-vs-ai-game.com
- PentestingEverything - pentesting and AppSec knowledge base covering 23 security domainsgithub.com
- PII Disclosure at A.S. Watson Group - HackerOne reporthackerone.com
- Proby - SplxAI hiring-bot CTF challenge to extract a hidden code from its system promptproby.splx.ai
- pwn.ai autonomous pentester drops ImageMagick zero-day chains achieving RCE in every security policyx.com
- Red Team Notes 2.0 - red team techniques, infrastructure and Active Directory attacksdmcxblue.gitbook.io
- Red Team Ops coursecourses.zeropointsecurity.co.uk
- Researchers Hack Source Code from Google Geminivulnu.com
- Resources for Beginner Bug Bounty Hunters - nahamsecgithub.com
- rycron - Security Assessments and Researchrycron.com
- Sam0x90/CTI - adversary emulation plans for the 2022 top 35 MITRE ATT&CK techniquesgithub.com
- Segfault - Disposable Root Servers by The Hacker's Choicethc.org
- SkelSec on an AI agent autonomously exploiting ADCS ESC1 and DCSyncing an ADx.com
- Source to Sink: Improving LLM Vuln Discovery - unprompted 2026youtube.com
- Spooler Alert: Remote Unauth'd RCE-to-root Chain in CUPS found by an autonomous LLM pipelineheyitsas.im
- Superhuman formerly Grammarly bug bounty program on HackerOnehackerone.com
- The future of security testing: harness AI-Powered Extensibility in Burpportswigger.net
- The Haag on using vulhub for CVE POC testing environmentsx.com
- TJ-JPT - pentesting report template for Joplin, Markdown versionsgithub.com
- Tur.js on using DeepSeek in Claude Code to extract 19 databases via blind SQL injectionx.com
- UK Ministry of Defence Red Teaming Handbookassets.publishing.service.gov.uk
- Using Multi-Modal Large Language Models For Breaking Captchaslinkedin.com
- Vulhub - pre-built vulnerable environments based on Docker Composegithub.com
- Vulnerability Research in the Age of AI - Alisa Esage VXCON 2024 keynote slideszerodayengineering.com
- XBOW on HackerOne: What's Next for AI Pen Testingxbow.com
- ZeroDay.cloud - cloud security vulnerability research community and CTF competitionzeroday.cloud