Security AI helper for Caido: pipes your local Claude Code / Gemini / Codex / Copilot CLI through 18 MCP tools for manual web security testing. Local-first, no API keys.
☆38Jun 26, 2026Updated last month
Alternatives and similar repositories for drift
Users that are interested in drift are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Caido plugin to send HTTP requests to external CLI security tools with preview, batch execution, and live output☆23Jun 29, 2026Updated last month
- Stealth hybrid URL mapper☆26May 1, 2026Updated 3 months ago
- Windows C/C++ development environment on Linux☆18Mar 29, 2026Updated 4 months ago
- Modular OSINT and attack surface analysis platform for authorized security research, with risk scoring, attack paths, and report generati…☆48Jun 4, 2026Updated last month
- Mutation-driven HTTP fuzzing for Burp Suite☆15Mar 2, 2026Updated 5 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆22Mar 16, 2026Updated 4 months ago
- Fast Go-based XSS assessment toolkit☆20Mar 18, 2026Updated 4 months ago
- PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.☆23Mar 1, 2026Updated 5 months ago
- MCPwned is a companion extension that enables pentesters to effectively test MCP servers. It recognizes MCP-like endpoints, provies a sca…☆20Jul 3, 2026Updated last month
- Echos is a stealthy C2 traffic emulator built in Rust for Red Teamers. It simulates adversarial beaconing patterns and custom jitter to t…☆34Jul 28, 2026Updated last week
- Claude Skill to create Caido plugins☆23Dec 1, 2025Updated 8 months ago
- Browser extension blocking scam and phishing pages https://chromewebstore.google.com/detail/nehboro/ljgklnaofelbcnegjniagpmjknkmaiom☆15Apr 22, 2026Updated 3 months ago
- Professional AWS pentest tool: IAM privilege escalation, S3 exploits, compute enumeration, detailed audit reports☆33May 2, 2026Updated 3 months ago
- A curated collection of tools, techniques, frameworks, and learning resources focused on Attack Surface Management (ASM).☆37Jan 13, 2026Updated 6 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- this is everything☆41Apr 7, 2026Updated 3 months ago
- An extension to find callback endpoints in the background while searching the Web☆47Mar 26, 2026Updated 4 months ago
- Agent-native code security review with MCP, structured findings, and practical pre-merge scanning workflows.☆22Apr 2, 2026Updated 4 months ago
- mattew crawls target websites, extracts hidden attack surface, runs security analysis, fingerprints technology, and generates professiona…☆16Jul 2, 2026Updated last month
- Nuclei scripts created by @rxerium for zero days / actively exploited vulnerabilities.☆194Jul 20, 2026Updated 2 weeks ago
- ThreatCheck - Select any indicator of compromise on any web page - or highlight an entire paragraph from a threat report - and instantly …☆34May 6, 2026Updated 2 months ago
- Burp extension to generate multi-step CSRF POC.☆31Sep 23, 2019Updated 6 years ago
- MCP server for .NET reverse engineering workflows (dnSpy/ILSpy ecosystem), built in C#.☆40Mar 25, 2026Updated 4 months ago
- SharpDir is a simple code set to search both local and remote file systems for files and is compatible with Cobalt Strike.☆29Jul 4, 2019Updated 7 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Salesforce identity and permission graph collector for BloodHound CE. Maps users, profiles, permission sets, roles, groups, sharing rules…☆47Updated this week
- ☆79May 8, 2026Updated 2 months ago
- Ransoblin (Ransomware Bokoblin)☆18Oct 4, 2020Updated 5 years ago
- C# code to run PIC using CreateThread☆17Apr 19, 2019Updated 7 years ago
- Tailscale/Headscale C2 profile and agent for Mythic☆25Mar 14, 2026Updated 4 months ago
- AWS SSO Device-Code Phishing Toolkit for Red / Purple Teams☆23Mar 10, 2026Updated 4 months ago
- Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.☆17Jul 11, 2025Updated last year
- SharpSvc is a simple code set to interact with the SC Manager API and is compatible with Cobalt Strike.☆26Aug 8, 2023Updated 2 years ago
- ☆20Dec 23, 2023Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern Java…☆15May 11, 2026Updated 2 months ago
- Passive JavaScript reconnaissance for penetration testers — bridging Burp Suite traffic into structured, AST-based analysis in VSCode.☆36Feb 5, 2026Updated 5 months ago
- Tool to assist bug bounty hunters☆77Mar 23, 2026Updated 4 months ago
- Kibana app for RedELK☆18Mar 19, 2023Updated 3 years ago
- 哪吒网络安全是一款高性能终端 UI (TUI) 应用,专为从事红队演练、渗透测试和漏洞研究的网络安全专业人员打造。本应用作为智能指挥控制界面,利用 DeepSeek 大语言模型提供实时流式对话、基于函数调用 (Function Calling) 的自动化工具编排,以及多智能…☆21May 28, 2026Updated 2 months ago
- Miscellaneous C-Sharp projects for red team activities☆22Aug 12, 2022Updated 3 years ago
- ☆50Feb 27, 2026Updated 5 months ago