π‘ The reference playbook for pentesting AI chatbots & LLM-powered apps in one place. Ready-to-use payloads covering the full OWASP LLM Top 10 plus frontier vectors (MCP Β· RAG Β· A2A Β· computer-use Β· voice)
β33Jun 18, 2026Updated 2 months ago
Alternatives and similar repositories for AI-Pentest-Playbook
Users that are interested in AI-Pentest-Playbook are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- JSHawk is a powerful, context-aware JavaScript security scanner that hunts for exposed credentials, API keys, and sensitive information iβ¦β17Apr 13, 2026Updated 4 months ago
- An agent that can help triage vulnerabilities across multiple codebasesβ19Mar 14, 2026Updated 5 months ago
- A Shodan-based tool to discover publicly exposed Ollama instances and list available LLM models.β22May 27, 2025Updated last year
- β47Jul 7, 2026Updated last month
- A class validation and transformation library, to ensure secure data structures in Python.β10May 16, 2024Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient β’ AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A collection of Awesome Frida Scripts for MAPTβ20Jan 7, 2023Updated 3 years ago
- A standalone tool for logging shell commands to GhostWriter automaticallyβ19Aug 24, 2024Updated last year
- AWS services enumerator for penetration testingβ21Nov 11, 2025Updated 9 months ago
- Track C2 servers, tools, and botnets over time by framework and locationβ16Aug 17, 2025Updated last year
- Live runtime audit for installed Android apps. Runs on the rooted phone, serves a browser dashboard.β31May 23, 2026Updated 3 months ago
- Turning Gandalf against itself. Use LLMs to automate playing Lakera Gandalf challenge without needing to set up an account with a platforβ¦β32Oct 16, 2023Updated 2 years ago
- A fast secret scanner for source codeβ24Jun 30, 2026Updated last month
- Verizon Burp Extensions: AI Suiteβ144Apr 22, 2025Updated last year
- Research into Undocumented Behavior of Azure AD Refresh Tokensβ13Oct 27, 2023Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient β’ AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A Collection of Proof of Concepts for non-published Web Exploits and Common CVEsβ10Nov 29, 2020Updated 5 years ago
- Demos for Black Hat Europe 2025's The Forensic Trail On GitHub: Hunting For Supply Chain Activityβ27Dec 5, 2025Updated 8 months ago
- AzDevRecon is a powerful web-based enumeration tool for offensive security professionals, red teamers, and pentesters targeting Azure Devβ¦β31Oct 13, 2025Updated 10 months ago
- Malicious package & supply-chain intelligenceβ190Updated this week
- shellcode obfuscater and runner in golangβ11Aug 13, 2023Updated 3 years ago
- CloudScraper: Tool to enumerate targets in search of cloud resources. S3 Buckets, Azure Blobs, Digital Ocean Storage Space.β11Oct 29, 2018Updated 7 years ago
- Autonomous AI agents for bug bounty hunting, 18 parallel hunters, built-in validator, zero setup.β21Apr 16, 2026Updated 4 months ago
- Azure AppHunter is an open-source tool created for security researchers, red teamers and defenders to help them identify excessive privilβ¦β105May 31, 2026Updated 2 months ago
- An autonomous agent that acts as a DEF CON-level Certified Ethical Hacker, using tools such as Nuclei, sqlmap, ffuf, Burp, ZAP, and the Sβ¦β54Apr 3, 2026Updated 4 months ago
- Managed Database hosting by DigitalOcean β’ AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Purple Team Workshop by @jorgeorchillesβ12Jul 31, 2026Updated 3 weeks ago
- RAG pipeline security testing toolkit - 27 techniques across 6 kill chain phases, mapped to MITRE ATLASβ40Apr 19, 2026Updated 4 months ago
- Basic w3af scan in Docker. Can be integrated into CI\CDβ10Feb 21, 2020Updated 6 years ago
- Given a list of domains and known IP and buckets that are owned, which might be susceptible to domain hijacking?β16Sep 20, 2024Updated last year
- Jenkins Security Research or Hacking Jenkins ;)β12Dec 10, 2024Updated last year
- β14Nov 29, 2019Updated 6 years ago
- A simple web app to get the latest EPSS data for a CVE IDβ14Dec 14, 2025Updated 8 months ago
- Utility to pull disclosed vulnerabilities from HackerOne private programs - for personal use onlyβ13Aug 22, 2021Updated 5 years ago
- β27Nov 12, 2025Updated 9 months ago
- Managed Database hosting by DigitalOcean β’ AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Phone Number Gathering & OSINT Tool. Collects Phone Numbers and Performs OSINT on the Numbers. Only works on Nigerian Numbers at the momeβ¦β15Aug 25, 2020Updated 5 years ago
- A free, open-source, multi-lingual, template-based VDP policy, safe harbor clause, securitytxt, and DNS Security TXT generator.β16Aug 16, 2026Updated last week
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parametersβ14Feb 10, 2022Updated 4 years ago
- 12-week Geekwise course on web application security and hardening.β17Mar 19, 2020Updated 6 years ago
- Microsoft Graph API post-exploitation framework with a browser-based GUI.β51Apr 15, 2026Updated 4 months ago
- Secrets Find0r is a multithreaded SMB share crawler that hunts for exposed credentials and secrets across Windows networks. It enumeratesβ¦β71May 6, 2026Updated 3 months ago
- Find open databases - Powered by Binaryedge.ioβ14Jan 4, 2020Updated 6 years ago