8 个仓库
Automatic recording of specific tool calls and resource requests to provide visibility into AI agent data exchanges.
Distinct from Request Payloads: Distinct from Request Payloads: focuses on the observability and recording of AI-specific tool and prompt payloads for debugging.
Explore 8 awesome GitHub repositories matching networking & communication · Execution Payload Tracing. Refine with filters or upvote what's useful.
mcp-use is a development framework designed for building, deploying, and managing servers, clients, and autonomous agents using the Model Context Protocol. It provides a comprehensive toolkit for creating servers that expose custom tools, data resources, and prompts to compatible AI agents. The project distinguishes itself by offering a complete lifecycle for protocol-based applications, including a dedicated hosting platform for production servers and a compliance validator to ensure servers meet marketplace publishing requirements. It also features an observability suite for tracing protoco
Automatically records tool calls, resource reads, and prompt requests to provide full payload visibility.
mcp-agent is a framework for building AI agents that integrate with Model Context Protocol servers to execute tools and access data. It functions as a multi-agent orchestrator and protocol-compliant server, enabling the creation of agents that can discover and invoke tools from connected external servers. The project distinguishes itself through a durable workflow engine that supports long-running tasks capable of pausing, resuming, and surviving restarts. It implements complex orchestration patterns, including iterative evaluator-optimizer loops, hierarchical workflow nesting, and specialist
Annotates execution spans with tool names and token counts to provide visibility into request payloads.
Monkey is an adversary emulation platform and breach and attack simulation tool designed to test network defenses through automated lateral movement and exploit delivery. It functions as a network security testing system that evaluates security posture by attempting to propagate through vulnerabilities and extract sensitive system credentials. The platform distinguishes itself by simulating specific real-world attacker behaviors, such as ransomware encryption, cryptojacking, and the theft of browser-stored credentials and secure shell keys. It utilizes binary hash randomization to evade antiv
Runs malicious payloads on infected machines to test the depth and impact of a successful compromise.
P4wnP1 is a hardware-based USB HID attack platform and peripheral emulator. It functions as a tool for emulating USB keyboards and mice to execute automated keystroke payloads, as well as a WiFi-enabled remote access tool that provides a wireless bridge for network relay and SSH access. The project is distinguished by its ability to establish covert bidirectional communication channels and remote shells using raw HID reports, specifically to bridge air-gapped systems. It further enables wireless network interception and the routing of network traffic over WiFi to facilitate man-in-the-middle
Executes bash payloads when events occur like network link up, target IP assignment, or SSH login.
This project is a set of specialized utilities for generating malformed documents, obfuscating payloads, and crafting specific attack vectors to evaluate the resilience of security scanners. It functions as a PDF fuzzing framework and security testing tool designed to create PDF files with embedded payloads for verifying how document viewers and web applications handle vulnerabilities. The toolkit provides capabilities for encoding and hiding malicious content to test the detection effectiveness of security scanners. It includes a security payload generator for crafting specific attack vector
Constructs PDF files by combining vulnerability strings with valid file format specifications.
这是一个用于 Linux 安全审计和系统枚举的综合工具包。它作为一个框架,用于识别配置弱点、收集系统信息并检测漏洞,以协助在 Linux 系统上获得更高的管理访问级别。 该工具包包括用于基于版本的漏洞扫描的专门功能,该功能将已安装的软件与已知的受影响版本进行匹配,以及用于跟踪循环系统模式和定期任务的时间窗口进程监控。它还提供了用于在本地网络上托管和交付枚举脚本以在目标机器上进行远程执行的基础设施。 该系统涵盖了广泛的安全分析领域,包括本地权限提升扫描、基于规则的枚举以及基于用户定义的详细程度和类别的过滤输出报告。
Transfers and triggers analysis logic on separate hosts to perform security audits from a remote position.
Octelium is a zero-trust network access platform and identity-aware proxy designed to secure private HTTP, SSH, and SQL resources. It functions as a secure gateway that validates human and workload identities using OIDC, SAML, and FIDO2 passkeys before granting access to internal applications and SaaS APIs. The system is distinguished by its secretless access broker, which injects credentials—such as API keys, passwords, and AWS Sigv4 signatures—at the gateway level so users can access databases and cloud resources without managing secrets. It further specializes in AI gateway administration,
Uses Lua scripts to sanitize AI payloads and implement data loss prevention guardrails.
BloodHound is an identity risk management platform and graph-based attack path analyzer used to map identity relationships and permissions in Active Directory. It functions as a security tool for auditing directory services, uncovering unintended privilege relationships, and visualizing sequences of permissions that can lead to domain compromise. The project differentiates itself as a comprehensive adversary emulation framework that coordinates remote agents and executes post-exploitation commands. It includes a reverse proxy for bypassing multi-factor authentication via real-time session hij
Executes binary files and assemblies on remote agents to extend their operational capabilities.