index of github.com/d3vn0mi
d3vn0mi/registry
The package registry of a working penetration tester — red-team tooling, OT/ICS research, CVE proof-of-concepts and lab infrastructure. Years of shipping, from the 2017 experiments to the 2026 offensive-security workshop.
filter tokens — — they stack with plain text
Featured packages
12 curated picks · the flagship builds- featured CVE-2025-2304-POC Proof-of-concept for CVE-2025-2304 — critical (CVSS 9.4) mass-assignment privilege escalation in Camaleon CMS.
- featured ArtiForge Cross-platform event-artifact generator for cyber-training labs — 71 Windows/Linux generators with correlated IDs, binary EVTX export, and Sigma-rule evaluation.
- featured KenbuAuditingSolution Web-based security-audit & compliance platform — 460+ CIS benchmark checks across 8 platforms with live audit sessions, Excel reporting, and GitHub OAuth SSO.
- featured Kagami Offline forensic-analysis & config-auditing tool that runs local LLMs (Ollama) over evidence against CIS/STIG/NIST/OWASP with CVSSv3 scoring — no data leaves the host.
- featured RyoTenkai RyoTenkai is an RPC client for MSF RPC server.
- featured Morgans Tool to generate a set of malicious/benign odt files. The malicious files have an embedded macro that can be altered as needed to execute any commands when the user opens the file.
- featured opcua-sniffer Python OPC UA packet sniffer — captures and dissects OPC UA traffic, extracting credentials, read/write operations, and protocol details for OT/ICS analysis.
- featured openvpn-mem-extractor openvpn-mem-extractor
- featured RNN-LSTM-Network-Intrusion RNN-LSTM Model for network intrusion , using benchmark dataset NSL-NDD
- featured Feature-Selection-SCADA-network Feature extraction and feature selection from pcap files of a SCADA network
- featured EzCME A Python wrapper for CrackMapExec that organizes enumeration output into clean, structured files for easier analysis during penetration testing engagements.
- featured systress A comprehensive command-line tool for stress testing CPU, RAM, and Network resources on Linux systems. Perfect for system administrators, DevOps engineers, and anyone who needs to validate system performance under load.
All packages
Package index
The complete registry — all 136 packages, featured picks first, then everything else in recently-updated order. Every entry links to its source on GitHub.
Featured 12 packages
-
Proof-of-concept for CVE-2025-2304 — critical (CVSS 9.4) mass-assignment privilege escalation in Camaleon CMS.
-
Cross-platform event-artifact generator for cyber-training labs — 71 Windows/Linux generators with correlated IDs, binary EVTX export, and Sigma-rule evaluation.
-
Web-based security-audit & compliance platform — 460+ CIS benchmark checks across 8 platforms with live audit sessions, Excel reporting, and GitHub OAuth SSO.
-
Offline forensic-analysis & config-auditing tool that runs local LLMs (Ollama) over evidence against CIS/STIG/NIST/OWASP with CVSSv3 scoring — no data leaves the host.
-
RyoTenkai is an RPC client for MSF RPC server.
-
Tool to generate a set of malicious/benign odt files. The malicious files have an embedded macro that can be altered as needed to execute any commands when the user opens the file.
-
Python OPC UA packet sniffer — captures and dissects OPC UA traffic, extracting credentials, read/write operations, and protocol details for OT/ICS analysis.
-
openvpn-mem-extractor
-
RNN-LSTM Model for network intrusion , using benchmark dataset NSL-NDD
-
Feature-Selection-SCADA-network
Feature extraction and feature selection from pcap files of a SCADA network
-
A Python wrapper for CrackMapExec that organizes enumeration output into clean, structured files for easier analysis during penetration testing engagements.
-
A comprehensive command-line tool for stress testing CPU, RAM, and Network resources on Linux systems. Perfect for system administrators, DevOps engineers, and anyone who needs to validate system performance under load.
All packages 124 packages
-
Minimal XSS proof-of-concept payload that exfiltrates document.cookie to a webhook.site endpoint
-
Full-stack web app template: FastAPI, React/TypeScript, PostgreSQL, Redis, Docker Compose, OAuth2/JWT and Stripe billing
-
Duplicate copy of the vue-details-popup Vue.js project (Vue CLI scaffold)
-
Python script to add or update IP and hostname entries in the Linux /etc/hosts file
-
Python tool that runs any script or executable as a detached background process with logging, retries and timeouts
-
Placeholder repository for a Twitter-like demo social app (currently only a README)
-
Early-stage concept for a finite-state-machine-based workflow execution engine (currently README only)
-
Python CLI that recursively searches text and binary files for string patterns, aimed at CTF flag hunting and forensics
-
Dockerized Python Modbus TCP server (pymodbus) for OT/ICS lab and testing environments
-
Python website crawler that recursively saves pages and images locally, mirroring the site's path structure
-
Markdown compliance checklists for security frameworks such as the NIST Cybersecurity Framework and GDPR
-
PowerShell 7 DFIR module that analyzes collected Linux/Windows artifacts with 25 analyzers and MITRE ATT&CK mapping
-
Curated collection of penetration testing reference links and cheat sheets organized by attack category
-
Privacy tool that poisons tracking data using LLM-generated personas that auto-browse to bury your real footprint (FastAPI/Next.js)
-
Python CLI that iteratively zips and unzips files through a password list to create nested password-protected archives
-
Python/Scapy tool that extracts and recovers files from PCAP captures (HTTP, FTP, SMTP, DNS, ICMP) for forensics and CTFs
-
Dockerized Python OPC UA server (asyncua) with user authentication for OT/ICS testing
-
Personal travel assistant built on OpenClaw and the Claude API that searches flights/hotels and monitors prices via chat apps
-
Python OPC UA client (asyncua) for reading and writing node values on OT/ICS servers
-
Docker-based learning lab (Mutillidae, MySQL, OpenLDAP, Kali) for practicing Nmap scanning and enumeration
-
Personal collection of Python security automation and recon scripts (nmap, swaks) plus Vagrant/Docker IaC
-
Python OSINT toolkit (PhoneNumberInvestigator) for investigating phone numbers, emails, and names across public sources
-
Personal OpenCTI cyber threat intelligence platform deployment (Nginx/Docker) on a DigitalOcean droplet
-
Catalogue of Docker-based vulnerable application scenarios (SQLi, XSS, RCE, and more) for practicing security exploitation
-
Docker Compose setup to run the Elastic Stack (Elasticsearch, Logstash, Kibana); based on deviantony/docker-elk
-
Collection of personal Dockerfiles, including a Kali Linux image
-
Personal Ansible playbooks for Proxmox, user provisioning, ZFS dataset moves and security hardening
-
Docker-based penetration-testing lab running the deliberately vulnerable Mutillidae app with MySQL, LDAP and a Kali container
-
Multilingual website built with Astro (i18n support)
-
Shell script to migrate all ZFS datasets between pools via snapshot send/receive on Proxmox or Linux
-
Python security assessment and exploitation tool for MinIO: discovery, auth checks, S3 enumeration and CVE checks
-
Docker image extending a Kasm Ubuntu desktop with an OpenConnect VPN client that connects at container startup
-
PowerShell script that recursively finds, collects and archives .hush files for ransomware cleanup and recovery
-
Python CLI to split large files into smaller parts and reassemble them, with configurable chunk size
-
Flask REST API wrapper for the Evilginx phishing toolkit to manage phishlets, lures, and captured sessions programmatically
-
RAVEN External Attack Surface Management platform (Django, Celery, Redis) running 20+ recon tools with AI-powered finding correlation
-
Python/Scapy tool that analyzes DNS traffic in PCAPs to detect and reassemble data exfiltrated via encoded DNS queries
-
Django admin-dashboard web app built on the AppSeed Bootstrap 5 Volt template
-
OSINT people-search tool aggregating 10+ public data sources into unified profiles; Python CLI plus FastAPI web dashboard
-
Template CI/CD pipeline deploying a FastAPI + React app to DigitalOcean App Platform via GitHub Actions
-
Template CI/CD pipeline deploying an Astro static site to Cloudflare Pages via GitHub Actions
-
Public docs for d3vn0mi's paid Agent Skills — portable SKILL.md capabilities for Claude, Codex, Cursor and other agents
-
d3vn0mi_kasm_workspace_registry
Custom Kasm Workspaces registry generated from the official template, publishing a workspace catalog via GitHub Pages
-
GitHub profile README for d3vn0mi, focused on penetration testing, security automation, and phishing simulations
-
Python PoC for CVE-2026-27470, authenticated second-order SQL injection in ZoneMinder's getNearEvents() (status.php), CVSS 8.8
-
Python PoC for CVE-2026-23744, unauthenticated RCE in MCP servers via the /api/mcp/connect serverConfig command field (default port 6274)
-
Python PoC for CVE-2025-47812, unauthenticated RCE in Wing FTP Server <= 7.4.3 via NULL-byte Lua injection into session files
-
Python PoC for CVE-2025-60787, authenticated OS command injection RCE in motionEye <= 0.43.1b4 via unsanitized image_file_name config
-
Django dashboard that fetches HackerOne bug bounty programs and researcher rankings, using Celery, Redis, and Docker
-
Python PoC for CVE-2025-4138, a path traversal in Python's tarfile module abusing symlink chains to bypass PATH_MAX for arbitrary file write
-
TypeScript dashboard aggregating bug bounty programs from HackerOne, Bugcrowd, Intigriti, Immunefi, and YesWeHack into one searchable feed
-
Dockerized Python chatbot web app using OpenAI's GPT-3 API with a simple web frontend
-
Python tool that decodes base64 data and extracts ZIP/TAR archives with magic-number detection and password support, for CTF and forensics
-
Python CLI for managing Appwrite databases, documents, relationships, teams, and storage, with YAML bulk import
-
Dockerfile and Compose for an Ubuntu container with SSH and a sudo 'ansible' user, ready to be managed by Ansible
-
Docker image with Python scripts to generate an inventory and run Ansible playbooks inside a container
-
Java Android Studio app from a 2017 university course lab exercise
-
Autonomous pentest agent (Python) driving recon and exploitation over SSH, streaming every command and evidence to a live web dashboard
-
An open source design system that's fully customizable and agent ready
-
🌉 Local-first Proton Mail MCP and CLI through Proton Bridge. Search, read, draft, send, sync, and act on mail from Claude Desktop or Terminal.
-
基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。
-
AI-powered offensive security agent with 7,300+ actionable security skills. Autonomous pentesting powered by MITRE ATT&CK (2,000+ Atomic tests), CIS Benchmarks (1,500+ controls), OWASP, NIST. Lazy-loading, zero context pollution. Your AI red team.
-
Tooling for discovery & information gathering from OPC-UA servers
-
Hacking notes for penetration testers, red teamers, security engineers and ctf enthusiasts
-
BayesDataPoisoningToolkit
-
no manifest filed
-
practice made claude perfect
-
A Simple and Universal Swarm Intelligence Engine, Predicting Anything. 简洁通用的群体智能引擎,预测万物
-
Script to make a unix machine rdp ready
-
A simple username osint tool built in rust
-
cve-2016-16113
-
Fully autonomous AI Agents system capable of performing complex penetration testing tasks
-
my-soc
-
A real fake social engineering app
-
Document Crafter
-
AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.
-
AI-powered ffuf wrapper
-
Hack-a-Sat 4 2023 - Finals Public Release
-
no manifest filed
-
Open source release of challenges and other code used in the Hack-A-Sat 2 Qualifier in 2021.
-
hackasat-qualifier-2023-techpapers
hackasat-qualifier-2023-techpapers
-
hackasat-qualifier-2023
-
Open source release of challenges and other code used in the Hack-A-Sat Qualifier in 2020.
-
Open source release of challenges and other code used in the 2020 Hack-a-Sat Final.
-
HackTheBox Certified Penetration Tester Specialist Cheatsheet
-
Lightweight REST API built on top of Django's class-based generic views
-
Creating delicious APIs for Django apps since 2010.
-
Python script that can execute any msf module as standalone action and get the output.
-
Fully automated homelab from empty disk to running services with a single command.
-
Script that periodically runs an other script
-
opcua-modbus-gw
-
qrcode image to link utility, so that you dont have to use your camera to scan it
-
Enchanced strings command
-
Xeno-RAT is an open-source remote access tool (RAT) developed in C#, providing a comprehensive set of features for remote system management. Has features such as HVNC, live microphone, reverse proxy, and much much more!
-
A pentest reporting tool written in Python. Free yourself from Microsoft Word.
-
no manifest filed
-
Multithread reverse shell listener
-
Configures SSSD to authenticate against AD's LDAP endpoints
-
Ansible Scripts to Build Out My Parrot
-
Tips on how to write exploit scripts (faster!)
-
no manifest filed
-
A small Socks5 Proxy Server in Python
-
Hugo template site for IKE. To be used as template when creating new simple sites.
-
This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports
-
dev backup for main site
-
Dockerfiles for various disposable environments.
-
Inventory Management and worth of investment simulations for crypto mining operation centers
-
for Linux
-
Project 2 for Bio-informatics
-
Feature selection comparison
-
Transportation scheduler
-
This repository aims to hold suggestions (and hopefully/eventually code) for CTF challenges. The "project" is nicknamed Katana.
-
GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems
-
OSCP-Exam-Report-Template-Markdown
:orange_book: Markdown Templates for Offensive Security OSCP, OSWE, OSCE, OSEE, OSWP exam report
-
Compares prices on Skroutz.gr , analyzes the data from X shops in a URL list and gets you the cheapest price
-
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
-
Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities.
-
no manifest filed
-
This Kali Linux Docker container offers a full desktop experience by using the tightvncserver to provide a VNC connection to the container and novnc for simple VNC access with your browser.
-
OSCP-MarkdownReportingTemplates
Markdown reporting templates and Pandoc styling references to generate sleek reports for OSCP/PWK with little effort.
-
A workflow that scans the IP address specified by the IP_ADDRESS Github secret and reports it in the form of a Github issue.
-
A communal outpouring of online resources for learning different things in cybersecurity
-
CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 180 other CMSs
-
OpenVAS connector for versions 6, 7, 8 and 9