Skip to content

A curated list of awesome security tools, experimental case or other interesting things with LLM or GPT.

License

Notifications You must be signed in to change notification settings

Escape-Technologies/awesome-gpt-security

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

24 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Awesome GPT + Security Awesome

A curated list of awesome security tools, experimental case or other interesting things with LLM or GPT.

Contents

Tools

🧰

Audit

  • SourceGPT - prompt manager and source code analyzer built on top of ChatGPT as the oracle
  • ChatGPTScanner - A white box code scan powered by ChatGPT
  • chatgpt-code-analyzer - ChatGPT Code Analyzer for Visual Studio Code
  • hacker-ai - An online tool using AI to detect vulnerabilities in source code
  • audit_gpt - Fine-tuning GPT for Smart Contract Auditing

Reconnaissance

  • GPT_Vuln-analyzer - Uses ChatGPT API, Python-Nmap, DNS Recon modules and uses the GPT3 model to create vulnerability reports based on Nmap scan data, and DNS scan information. It can also perform subdomain enumeration to a great extent
  • SubGPT - SubGPT looks at subdomains you have already discovered for a domain and uses BingGPT to find more.
  • Navi - A QA based Reconnaissance Tool with GPT

Offensive

  • PentestGPT - A GPT-empowered penetration testing tool
  • burpgpt - A Burp Suite extension that integrates OpenAI's GPT to perform an additional passive scan for discovering highly bespoke vulnerabilities, and enables running traffic-based analysis of any type.
  • ReconAIzer - A Burp Suite extension to add OpenAI (GPT) on Burp and help you with your Bug Bounty recon to discover endpoints, params, URLs, subdomains and more!
  • PassGAN - A Deep Learning Approach for Password Guessing. HomeSecurityHeroes land a Product, and you can test how much time an AI would need to crack your password here.
  • nuclei_gpt - Only need to submit the relevant Request and Response and the description of the vulnerability to generate a Nuclei PoC.

Detecting

  • k8sgpt - a tool for scanning your Kubernetes clusters, diagnosing, and triaging issues in simple English.
  • cloudgpt - Vulnerability scanner for AWS customer managed policies using ChatGPT
  • IATelligence - About IATelligence is a Python script that will extract the IAT of a PE file and request GPT to get more information about the API and the ATT&CK matrix related

Preventing

Social Engineering

Reverse Engineering

  • gpt-wpre - Whole-Program Reverse Engineering with GPT-3
  • G-3PO - A Script that Solicits GPT-3 for Comments on Decompiled Code

Fix

  • wolverine - Auto fix the bugs in your Python Script/Code

Assessment

  • falco-gpt - AI-generated remediations for Falco audit events
  • selefra - an open-source policy-as-code software that provides analytics for multi-cloud and SaaS.

Cases

🌰

Experimental

Academic

Blogs

Fun


GPT Security

🚨

Bypass Security Policy

Bug Bounty

Crack

  • gpt4free -- Just API's from some language model sites.
  • EdgeGPT -- Reverse engineered API of Microsoft's Bing Chat AI

Contributing

Your contributions are always welcome! Please take a look at the contribution guidelines first.


If you have any question about this opinionated list, do not hesitate to open an issue on GitHub.

About

A curated list of awesome security tools, experimental case or other interesting things with LLM or GPT.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published