Skip to content
View CommonHuman-Lab's full-sized avatar

Block or report CommonHuman-Lab

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
CommonHuman-Lab/README.md

πŸ™ CommonHuman-Lab

Open-source offensive security & AI tooling ⚑

Building weird, powerful, self-hostable tools for security, defenders, researchers & curious humans.


Scanners

Tool Description
BreachSQL Fast SQL injection scanner with built-in exploitation β€” detect and extract in one command, across all major backends, with WAF evasion baked in. Drops into a Python pipeline.
StingXSS Context-aware XSS scanner β€” reflected, DOM, stored, and confirmed browser XSS with WAF detection and evasion
PhaseAccess Open-source IDOR / BOLA scanner. Goes beyond simple ID enumeration β€” it understands ownership, sessions, and evidence.

Infrastructure

Tool Description
NyxStrike AI-powered offensive security orchestration β€” connects LLM agents to real tools and runs full attack chains from recon to exploitation
GloomProxy Open-source DAST platform built around a full MITM proxy β€” attack surface graph, distributed scanner plugins, auth orchestration, replay, workflows, and correlation in a single self-hosted UI.
OctoRig Spin up realistic vulnerable environments for pentesting, security research, and offensive security training β€” with a single command.
GloamFire Docker-native adversary simulation and detection validation framework for SOC teams, purple teams, homelabs, and detection engineers.

Harvesters

Tool Description
VaultRip Post-exploitation credential harvesting and active attack engine.

🌿 Why?

Because security tooling should be:

  • Transparent βœ…
  • Self-hostable βœ…
  • Fast βœ…
  • Experimental βœ…
  • Actually fun to use βœ…

Pinned Loading

  1. nyxstrike nyxstrike Public

    AI Powered penetration testing Platform for offensive security research

    Python 143 32

  2. stingxss stingxss Public

    Context-aware reflected & DOM XSS scanner with WAF detection and evasion

    Python 4 1

  3. breachsql breachsql Public

    Fast SQL injection scanner with built-in exploitation β€” detect and extract in one command, across all major backends, with WAF evasion baked in. Drops into a Python pipeline.

    Python 6

  4. OctoRig OctoRig Public

    Realistic vulnerable labs and a self-hosted CTF platform β€” events, badges, scoreboards β€” spun up with one command.

    Python 6 3

  5. phaseaccess phaseaccess Public

    Native IDOR and broken object-level authorization detection engine

    Python 5

  6. gloomproxy gloomproxy Public

    Browse a target normally and watch the attack surface graph build itselfc β€” all correlated in real time. Then hit it with distributed scanner plugins, replay and fuzz interesting requests, and mana…

    Python 4 1