π‘ The reference playbook for pentesting AI chatbots & LLM-powered apps in one place. Ready-to-use payloads covering the full OWASP LLM Top 10 plus frontier vectors (MCP Β· RAG Β· A2A Β· computer-use Β· voice)
β31Jun 18, 2026Updated last month
Alternatives and similar repositories for AI-Pentest-Playbook
Users that are interested in AI-Pentest-Playbook are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- JSHawk is a powerful, context-aware JavaScript security scanner that hunts for exposed credentials, API keys, and sensitive information iβ¦β17Apr 13, 2026Updated 3 months ago
- β12Feb 20, 2022Updated 4 years ago
- An agent that can help triage vulnerabilities across multiple codebasesβ18Mar 14, 2026Updated 4 months ago
- Office 365 and Exchange Enumeration Version 2β18Jan 30, 2024Updated 2 years ago
- A Shodan-based tool to discover publicly exposed Ollama instances and list available LLM models.β22May 27, 2025Updated last year
- 1-Click AI Models by DigitalOcean Gradient β’ AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- β45Jul 7, 2026Updated 3 weeks ago
- A class validation and transformation library, to ensure secure data structures in Python.β10May 16, 2024Updated 2 years ago
- A standalone tool for logging shell commands to GhostWriter automaticallyβ19Aug 24, 2024Updated last year
- Track C2 servers, tools, and botnets over time by framework and locationβ16Aug 17, 2025Updated 11 months ago
- Live runtime audit for installed Android apps. Runs on the rooted phone, serves a browser dashboard.β28May 23, 2026Updated 2 months ago
- Turning Gandalf against itself. Use LLMs to automate playing Lakera Gandalf challenge without needing to set up an account with a platforβ¦β32Oct 16, 2023Updated 2 years ago
- A fast secret scanner for source codeβ25Jun 30, 2026Updated last month
- Verizon Burp Extensions: AI Suiteβ144Apr 22, 2025Updated last year
- Research into Undocumented Behavior of Azure AD Refresh Tokensβ13Oct 27, 2023Updated 2 years ago
- AI Agents on DigitalOcean Gradient AI Platform β’ AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Demos for Black Hat Europe 2025's The Forensic Trail On GitHub: Hunting For Supply Chain Activityβ26Dec 5, 2025Updated 7 months ago
- A cheat sheet for common pentesting techniques.β18Feb 10, 2020Updated 6 years ago
- Malicious package & supply-chain intelligenceβ181Jul 25, 2026Updated last week
- IDA 9.0 plugin for decrypting strings encrypted by garble.β24Jul 20, 2026Updated 2 weeks ago
- Inject code into .net applicationsβ14Nov 7, 2018Updated 7 years ago
- β22Apr 10, 2025Updated last year
- CloudScraper: Tool to enumerate targets in search of cloud resources. S3 Buckets, Azure Blobs, Digital Ocean Storage Space.β11Oct 29, 2018Updated 7 years ago
- Autonomous AI agents for bug bounty hunting, 18 parallel hunters, built-in validator, zero setup.β19Apr 16, 2026Updated 3 months ago
- Azure AppHunter is an open-source tool created for security researchers, red teamers and defenders to help them identify excessive privilβ¦β104May 31, 2026Updated 2 months ago
- Virtual machines for every use case on DigitalOcean β’ AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Purple Team Workshop by @jorgeorchillesβ12Updated this week
- RAG pipeline security testing toolkit - 27 techniques across 6 kill chain phases, mapped to MITRE ATLASβ37Apr 19, 2026Updated 3 months ago
- source for llmsec.netβ16Jul 24, 2024Updated 2 years ago
- Basic w3af scan in Docker. Can be integrated into CI\CDβ10Feb 21, 2020Updated 6 years ago
- Small tool to decode ASP.NET __VIEWSTATE variable when doing webpentestsβ15Feb 27, 2021Updated 5 years ago
- An N-API module to extract version pragma and imports from Solidity sourcesβ17Jun 7, 2024Updated 2 years ago
- Given a list of domains and known IP and buckets that are owned, which might be susceptible to domain hijacking?β16Sep 20, 2024Updated last year
- Jenkins Security Research or Hacking Jenkins ;)β12Dec 10, 2024Updated last year
- β14Nov 29, 2019Updated 6 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI β’ AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- A simple web app to get the latest EPSS data for a CVE IDβ14Dec 14, 2025Updated 7 months ago
- Utility to pull disclosed vulnerabilities from HackerOne private programs - for personal use onlyβ13Aug 22, 2021Updated 4 years ago
- Phone Number Gathering & OSINT Tool. Collects Phone Numbers and Performs OSINT on the Numbers. Only works on Nigerian Numbers at the momeβ¦β15Aug 25, 2020Updated 5 years ago
- A free, open-source, multi-lingual, template-based VDP policy, safe harbor clause, securitytxt, and DNS Security TXT generator.β16Updated this week
- The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parametersβ14Feb 10, 2022Updated 4 years ago
- 12-week Geekwise course on web application security and hardening.β17Mar 19, 2020Updated 6 years ago
- Simple extension that allows to run nuclei scanner directly from burp and transforms json results into the issues.β32Jun 22, 2023Updated 3 years ago