π‘ The reference playbook for pentesting AI chatbots & LLM-powered apps in one place. Ready-to-use payloads covering the full OWASP LLM Top 10 plus frontier vectors (MCP Β· RAG Β· A2A Β· computer-use Β· voice)
β34Jun 18, 2026Updated 2 months ago
Alternatives and similar repositories for AI-Pentest-Playbook
Users that are interested in AI-Pentest-Playbook are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- JSHawk is a powerful, context-aware JavaScript security scanner that hunts for exposed credentials, API keys, and sensitive information iβ¦β17Apr 13, 2026Updated 5 months ago
- An agent that can help triage vulnerabilities across multiple codebasesβ19Mar 14, 2026Updated 5 months ago
- Office 365 and Exchange Enumeration Version 2β18Jan 30, 2024Updated 2 years ago
- A Shodan-based tool to discover publicly exposed Ollama instances and list available LLM models.β23May 27, 2025Updated last year
- β49Jul 7, 2026Updated 2 months ago
- AI Agents on DigitalOcean Gradient AI Platform β’ AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- A collection of Awesome Frida Scripts for MAPTβ20Jan 7, 2023Updated 3 years ago
- WARNING: This is a vulnerable application to test the exploit for the Spring Break vulnerability (CVE-2017-8046). Run it at your own riskβ¦β14Oct 8, 2018Updated 7 years ago
- A standalone tool for logging shell commands to GhostWriter automaticallyβ19Aug 24, 2024Updated 2 years ago
- AWS services enumerator for penetration testingβ21Nov 11, 2025Updated 10 months ago
- Track C2 servers, tools, and botnets over time by framework and locationβ16Aug 17, 2025Updated last year
- Live runtime audit for installed Android apps. Runs on the rooted phone, serves a browser dashboard.β32May 23, 2026Updated 3 months ago
- Turning Gandalf against itself. Use LLMs to automate playing Lakera Gandalf challenge without needing to set up an account with a platforβ¦β32Oct 16, 2023Updated 2 years ago
- A fast secret scanner for source codeβ25Jun 30, 2026Updated 2 months ago
- Verizon Burp Extensions: AI Suiteβ144Apr 22, 2025Updated last year
- Managed Database hosting by DigitalOcean β’ AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- API Penetration Testing Notesβ19Sep 25, 2025Updated 11 months ago
- Research into Undocumented Behavior of Azure AD Refresh Tokensβ13Oct 27, 2023Updated 2 years ago
- A Collection of Proof of Concepts for non-published Web Exploits and Common CVEsβ10Nov 29, 2020Updated 5 years ago
- Demos for Black Hat Europe 2025's The Forensic Trail On GitHub: Hunting For Supply Chain Activityβ27Dec 5, 2025Updated 9 months ago
- A cheat sheet for common pentesting techniques.β18Feb 10, 2020Updated 6 years ago
- IDA 9.0 plugin for decrypting strings encrypted by garble.β25Jul 20, 2026Updated last month
- Malicious package & supply-chain intelligenceβ196Sep 2, 2026Updated last week
- Inject code into .net applicationsβ14Nov 7, 2018Updated 7 years ago
- shellcode obfuscater and runner in golangβ11Aug 13, 2023Updated 3 years ago
- Managed hosting for WordPress and PHP on Cloudways β’ AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- β22Apr 10, 2025Updated last year
- CloudScraper: Tool to enumerate targets in search of cloud resources. S3 Buckets, Azure Blobs, Digital Ocean Storage Space.β11Oct 29, 2018Updated 7 years ago
- β17Mar 19, 2021Updated 5 years ago
- Autonomous AI agents for bug bounty hunting, 18 parallel hunters, built-in validator, zero setup.β22Apr 16, 2026Updated 4 months ago
- Azure AppHunter is an open-source tool created for security researchers, red teamers and defenders to help them identify excessive privilβ¦β105May 31, 2026Updated 3 months ago
- a simple powershell wrapper to automate checking a user's access around the networkβ14Dec 5, 2023Updated 2 years ago
- An autonomous agent that acts as a DEF CON-level Certified Ethical Hacker, using tools such as Nuclei, sqlmap, ffuf, Burp, ZAP, and the Sβ¦β55Apr 3, 2026Updated 5 months ago
- Purple Team Workshop by @jorgeorchillesβ12Jul 31, 2026Updated last month
- RAG pipeline security testing toolkit - 27 techniques across 6 kill chain phases, mapped to MITRE ATLASβ40Apr 19, 2026Updated 4 months ago
- Deploy on Railway without the complexity - Free Credits Offer β’ AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Basic w3af scan in Docker. Can be integrated into CI\CDβ10Feb 21, 2020Updated 6 years ago
- Small tool to decode ASP.NET __VIEWSTATE variable when doing webpentestsβ16Feb 27, 2021Updated 5 years ago
- An N-API module to extract version pragma and imports from Solidity sourcesβ17Jun 7, 2024Updated 2 years ago
- Given a list of domains and known IP and buckets that are owned, which might be susceptible to domain hijacking?β16Sep 20, 2024Updated last year
- Jenkins Security Research or Hacking Jenkins ;)β12Dec 10, 2024Updated last year
- β14Nov 29, 2019Updated 6 years ago
- β14Jul 13, 2020Updated 6 years ago