MCP security testing framework for evaluating Model Context Protocol server vulnerabilities
☆35Feb 17, 2026Updated 6 months ago
Alternatives and similar repositories for MCPHammer
Users that are interested in MCPHammer are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Open benchmark for AI agent security tools — prompt injection, data exfiltration, tool abuse, provenance☆25Updated this week
- Apple artifacts database - Mirror of https://github.com/cocool97/appledb_rs☆27Oct 14, 2025Updated 10 months ago
- Simple LLM service identification - translate IP:Port to Ollama, vLLM, LiteLLM, or 60+ other AI services in seconds☆231Updated this week
- ☆15May 30, 2026Updated 2 months ago
- ☆16Mar 24, 2026Updated 5 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Organizational asset discovery tool with 20+ plugins covering certificate transparency, passive DNS, and all 5 Regional Internet Registri…☆88Updated this week
- Tools for attacking Computer Use Agents☆33Jan 16, 2026Updated 7 months ago
- This plugin is inspired by tools.slcyber.io. It contains two tools: Surf (an SSRF target discovery tool) and Wordlists (custom wordlists …☆24Jan 19, 2026Updated 7 months ago
- AATMF | An Open Source - Adversarial AI Threat Modeling Framework☆30Jun 1, 2026Updated 2 months ago
- ProxyWatch☆86Apr 25, 2026Updated 4 months ago
- Unify your OAST provider management and consolidate all interactions into a single, streamlined workflow.☆26May 23, 2026Updated 3 months ago
- A list of useful payloads and bypass for Web Application Security☆14Nov 26, 2023Updated 2 years ago
- MCP server for analyzing PE, ELF, and Mach-O binaries using LIEF☆25Mar 6, 2026Updated 5 months ago
- Command Execution PoC for OpenSSL Stack buffer overflow CVE-2025-15467☆15Feb 25, 2026Updated 6 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Exploit Development CheatSheet.☆18Aug 9, 2021Updated 5 years ago
- MODBUS Penetration Testing Framework☆12Jul 2, 2017Updated 9 years ago
- ☆13Mar 14, 2022Updated 4 years ago
- ☆19Dec 18, 2024Updated last year
- A practical, community-driven checklist for pentesting MCP servers. Covers traffic analysis, tool-call behavior, namespace abuse, auth fl…☆40Apr 7, 2026Updated 4 months ago
- Upload Forge is a powerful, production-grade security tool designed to detect and exploit file upload vulnerabilities in web applications…☆24Jan 2, 2026Updated 7 months ago
- Modular OSINT and attack surface analysis platform for authorized security research, with risk scoring, attack paths, and report generati…☆85Jun 4, 2026Updated 2 months ago
- Tyche is a Mythic HTTPX Profile Generator used to create Malleable C2 Profiles.☆52Mar 28, 2026Updated 5 months ago
- Shroudware is a compile-time obfuscation library implemented entirely in the C preprocessor.☆28Apr 12, 2026Updated 4 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Analyzes software dependencies across GitHub repositories to identify security vulnerabilities and health risks in your supply chain.☆125May 26, 2026Updated 3 months ago
- A personal RAG system for offensive security knowledge☆176Aug 11, 2026Updated 2 weeks ago
- A multi-platform CI/CD vulnerability detection and attack automation tool for identifying security weaknesses in pipeline configurations.☆179Aug 16, 2026Updated last week
- A powerful Go tool for finding origin IPs of domains by querying multiple security APIs and validating results with built-in HTTP client.☆50Dec 4, 2025Updated 8 months ago
- MCPwned is a companion extension that enables pentesters to effectively test MCP servers. It recognizes MCP-like endpoints, provies a sca…☆20Jul 3, 2026Updated last month
- Windows named pipe hooking toolkit☆45Mar 20, 2026Updated 5 months ago
- Secrets scanner with a twist... this is for getting threat actor credentials from MALWARE. Acquire TA creds from FLOSS exports, memdumps…☆39Aug 9, 2026Updated 3 weeks ago
- Just another AD training, but free.☆17Aug 9, 2025Updated last year
- Suite of programs meant to aid in bug hunting and security assessments☆77Dec 29, 2019Updated 6 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Maturity Model Collaborative project☆15Feb 27, 2023Updated 3 years ago
- AWS SSO Device-Code Phishing Toolkit for Red / Purple Teams☆23Mar 10, 2026Updated 5 months ago
- Experimental PoC for unhooking API functions using in-memory patching, without VirtualProtect, for one specific EDR.☆14Jul 9, 2023Updated 3 years ago
- Sage is a virtual Mythic agent that that uses an AI agentic system to operate Mythic and Mythic agents running on compromised hosts.☆21Updated this week
- New exploitation tricks for hardened .NET Remoting servers☆33Aug 5, 2025Updated last year
- API discovery tool that maps attack surfaces from captured traffic and generates specs for REST, GraphQL, SOAP, and WebSocket APIs☆126Updated this week
- A simple OAuth App designed to capture OAuth tokens when users authenticate through GitHub OAuth flow.☆27Apr 20, 2026Updated 4 months ago