Skip to content
View CommonHuman-Lab's full-sized avatar

Block or report CommonHuman-Lab

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
CommonHuman-Lab/README.md

🐙 CommonHuman-Lab

Open-source offensive security & AI tooling ⚡

Building weird, powerful, self-hostable tools for security, defenders, researchers & curious humans.


Scanners

ToolDescription
BreachSQLFast SQL injection scanner with built-in exploitation — detect and extract in one command, across all major backends, with WAF evasion baked in. Drops into a Python pipeline.
StingXSSContext-aware XSS scanner — reflected, DOM, stored, and confirmed browser XSS with WAF detection and evasion
PhaseAccessOpen-source IDOR / BOLA scanner. Goes beyond simple ID enumeration — it understands ownership, sessions, and evidence.

Infrastructure

ToolDescription
GloomProxyOpen-source DAST platform built around a full MITM proxy — attack surface graph, distributed scanner plugins, auth orchestration, replay, workflows, and correlation in a single self-hosted UI.
OctoRigSpin up realistic vulnerable environments for pentesting, security research, and offensive security training — with a single command.
GloamFireDocker-native adversary simulation and detection validation framework for SOC teams, purple teams, homelabs, and detection engineers.
NyxStrikeAI-powered offensive security orchestration — connects LLM agents to real tools and runs full attack chains from recon to exploitation

Harvesters

ToolDescription
VaultRipPost-exploitation credential harvesting and active attack engine.

Libraries

PackageDescription
commonhuman-coreShared HTTP engine and web crawler — session management, injection helpers, BFS crawling, and passive recon primitives
commonhuman-payloadsShared payload collections, encoders, and WAF signatures
commonhuman-cliShared CLI argument handling and output formatting

🌿 Why?

Because security tooling should be:

  • Transparent ✅
  • Self-hostable ✅
  • Fast ✅
  • Experimental ✅
  • Actually fun to use ✅

Pinned Loading

  1. nyxstrikenyxstrikePublic

    AI Powered penetration testing Platform for offensive security research

    Python 142 35

  2. stingxssstingxssPublic

    Context-aware reflected & DOM XSS scanner with WAF detection and evasion

    Python 4 1

  3. breachsqlbreachsqlPublic

    Fast SQL injection scanner with built-in exploitation — detect and extract in one command, across all major backends, with WAF evasion baked in. Drops into a Python pipeline.

    Python 6

  4. OctoRigOctoRigPublic

    Realistic vulnerable labs and a self-hosted CTF platform — events, badges, scoreboards — spun up with one command.

    Python 6 3

  5. phaseaccessphaseaccessPublic

    Native IDOR and broken object-level authorization detection engine

    Python 5

  6. gloomproxygloomproxyPublic

    Browse a target normally and watch the attack surface graph build itselfc — all correlated in real time. Then hit it with distributed scanner plugins, replay and fuzz interesting requests, and mana…

    Python 4 1