🛡 The reference playbook for pentesting AI chatbots & LLM-powered apps in one place. Ready-to-use payloads covering the full OWASP LLM Top 10 plus frontier vectors (MCP · RAG · A2A · computer-use · voice)
☆36Jun 18, 2026Updated 3 months ago
Alternatives and similar repositories for AI-Pentest-Playbook
Users that are interested in AI-Pentest-Playbook are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- JSHawk is a powerful, context-aware JavaScript security scanner that hunts for exposed credentials, API keys, and sensitive information i…☆17Apr 13, 2026Updated 5 months ago
- An agent that can help triage vulnerabilities across multiple codebases☆19Mar 14, 2026Updated 6 months ago
- Office 365 and Exchange Enumeration Version 2☆18Jan 30, 2024Updated 2 years ago
- A Shodan-based tool to discover publicly exposed Ollama instances and list available LLM models.☆24May 27, 2025Updated last year
- ☆50Jul 7, 2026Updated 2 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- WARNING: This is a vulnerable application to test the exploit for the Spring Break vulnerability (CVE-2017-8046). Run it at your own risk…☆14Oct 8, 2018Updated 7 years ago
- AWS services enumerator for penetration testing☆21Nov 11, 2025Updated 10 months ago
- A standalone tool for logging shell commands to GhostWriter automatically☆19Aug 24, 2024Updated 2 years ago
- Live runtime audit for installed Android apps. Runs on the rooted phone, serves a browser dashboard.☆33May 23, 2026Updated 4 months ago
- Track C2 servers, tools, and botnets over time by framework and location☆16Aug 17, 2025Updated last year
- Turning Gandalf against itself. Use LLMs to automate playing Lakera Gandalf challenge without needing to set up an account with a platfor…☆32Oct 16, 2023Updated 2 years ago
- A fast secret scanner for source code☆26Jun 30, 2026Updated 3 months ago
- API Penetration Testing Notes☆19Sep 25, 2025Updated last year
- Verizon Burp Extensions: AI Suite☆146Apr 22, 2025Updated last year
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Research into Undocumented Behavior of Azure AD Refresh Tokens☆13Oct 27, 2023Updated 2 years ago
- A Collection of Proof of Concepts for non-published Web Exploits and Common CVEs☆10Nov 29, 2020Updated 5 years ago
- Demos for Black Hat Europe 2025's The Forensic Trail On GitHub: Hunting For Supply Chain Activity☆28Dec 5, 2025Updated 9 months ago
- AzDevRecon is a powerful web-based enumeration tool for offensive security professionals, red teamers, and pentesters targeting Azure Dev…☆32Oct 13, 2025Updated 11 months ago
- A cheat sheet for common pentesting techniques.☆18Feb 10, 2020Updated 6 years ago
- shellcode obfuscater and runner in golang☆11Aug 13, 2023Updated 3 years ago
- ☆22Apr 10, 2025Updated last year
- operative framework is a OSINT investigation framework, you can interact with multiple targets, execute multiple modules, create links wi…☆13Oct 23, 2019Updated 6 years ago
- CloudScraper: Tool to enumerate targets in search of cloud resources. S3 Buckets, Azure Blobs, Digital Ocean Storage Space.☆11Oct 29, 2018Updated 7 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- ☆17Mar 19, 2021Updated 5 years ago
- Autonomous AI agents for bug bounty hunting, 18 parallel hunters, built-in validator, zero setup.☆22Apr 16, 2026Updated 5 months ago
- a simple powershell wrapper to automate checking a user's access around the network☆14Dec 5, 2023Updated 2 years ago
- An autonomous agent that acts as a DEF CON-level Certified Ethical Hacker, using tools such as Nuclei, sqlmap, ffuf, Burp, ZAP, and the S…☆56Apr 3, 2026Updated 6 months ago
- Purple Team Workshop by @jorgeorchilles☆12Jul 31, 2026Updated 2 months ago
- RAG pipeline security testing toolkit - 27 techniques across 6 kill chain phases, mapped to MITRE ATLAS☆42Apr 19, 2026Updated 5 months ago
- source for llmsec.net☆16Jul 24, 2024Updated 2 years ago
- An N-API module to extract version pragma and imports from Solidity sources☆17Jun 7, 2024Updated 2 years ago
- Small tool to decode ASP.NET __VIEWSTATE variable when doing webpentests☆15Feb 27, 2021Updated 5 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Given a list of domains and known IP and buckets that are owned, which might be susceptible to domain hijacking?☆16Sep 20, 2024Updated 2 years ago
- ☆26Nov 12, 2025Updated 10 months ago
- ☆14Nov 29, 2019Updated 6 years ago
- ☆14Jul 13, 2020Updated 6 years ago
- Utility to pull disclosed vulnerabilities from HackerOne private programs - for personal use only☆13Aug 22, 2021Updated 5 years ago
- A simple web app to get the latest EPSS data for a CVE ID☆14Dec 14, 2025Updated 9 months ago
- Phone Number Gathering & OSINT Tool. Collects Phone Numbers and Performs OSINT on the Numbers. Only works on Nigerian Numbers at the mome…☆15Aug 25, 2020Updated 6 years ago