domain: penetration-testing
1317 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| Z4nzu/hackingtool An all-in-one, menu-driven Python toolkit that aggregates 215 curated security testing tools across 21 categories such as recon, OSINT, web… | 77 | 79125 | active |
| usestrix/strix Strix is an open-source AI penetration testing tool that deploys autonomous agents to find, validate, and fix application vulnerabilities. … | 84 | 58564 | active |
| KeygraphHQ/shannon Shannon is an open-source, autonomous AI pentester for web applications and APIs that runs locally from the command line. It analyzes sourc… | 84 | 47226 | active |
| Metasploit Framework Metasploit Framework is the world's most widely used open-source penetration testing framework, providing a large collection of exploit, pa… | 77 | 38886 | active |
| sqlmapproject/sqlmap sqlmap is an open-source penetration testing tool that automates the detection and exploitation of SQL injection flaws and the takeover of … | 75 | 38275 | stable |
| mukul975/Anthropic-Cybersecurity-Skills A large open-source library of structured cybersecurity skills (Markdown files with YAML frontmatter) for AI coding agents, mapped to frame… | 78 | 31259 | active |
| projectdiscovery/nuclei Nuclei is a fast, open-source vulnerability scanner built on a simple YAML-based template DSL, maintained by ProjectDiscovery. It uses a la… | 98 | 30855 | active |
| zhaoxuya520/reverse-skill A cybersecurity skill router pack that directs AI coding agents (Claude Code, Cursor, Cline, Kiro) to the right reverse-engineering, penetr… | 69 | 29591 | active |
| hashcat Hashcat is the world's fastest and most advanced password recovery utility, supporting over 300 highly-optimized hashing algorithms across … | 80 | 26631 | active |
| robertdavidgraham/masscan Masscan is an Internet-scale TCP port scanner written in C that transmits 10 million SYN packets per second, capable of scanning the entire… | 58 | 25955 | active |
| vxcontrol/pentagi PentAGI is a self-hosted, fully autonomous multi-agent AI system for performing complex penetration testing tasks, built in Go with a React… | 78 | 22033 | active |
| gentilkiwi/mimikatz mimikatz is a well-known Windows security tool written in C that extracts plaintext passwords, hashes, PINs, and Kerberos tickets from memo… | 57 | 21799 | active |
| Frida Frida is a dynamic instrumentation toolkit that lets developers, reverse-engineers, and security researchers inject JavaScript or native li… | 94 | 21752 | active |
| MobSF/Mobile-Security-Framework-MobSF MobSF is an automated all-in-one mobile application security testing framework for Android, iOS, and Windows Mobile apps. It performs stati… | 94 | 21650 | active |
| smicallef/spiderfoot SpiderFoot is an open-source OSINT automation tool that integrates with over 200 data sources to gather and analyze intelligence about targ… | 57 | 21441 | active |
| peass-ng/PEASS-ng PEASS-ng is a suite of privilege escalation enumeration scripts (LinPEAS for Linux/Unix/macOS and WinPEAS for Windows) that scan local syst… | 95 | 20381 | active |
| bee-san/RustScan RustScan is a fast, modern port scanner written in Rust that can scan all 65k ports in seconds. It includes a scripting engine (Python, Lua… | 67 | 20331 | active |
| bettercap/bettercap bettercap is a Go-based, all-in-one framework for network reconnaissance and man-in-the-middle attacks across WiFi, Bluetooth Low Energy, w… | 88 | 19865 | active |
| laramies/theHarvester theHarvester is a Python CLI tool that gathers open-source intelligence (emails, subdomains, hostnames, IPs, names, URLs, ASNs) about a dom… | 91 | 17202 | active |
| ZPhisher Zphisher is a beginner-friendly, automated phishing toolkit written in Bash with 30+ ready-made login page templates. It supports multiple … | 23 | 16700 | active |
| MatrixTM/MHDDoS MHDDoS is a Python 3 command-line DDoS attack script offering 57 flood methods across Layer 7 (HTTP) and Layer 4 (TCP/UDP), including bypas… | 74 | 16595 | active |
| ffuf/ffuf ffuf is a fast web fuzzer written in Go used for discovering directories, virtual hosts, and parameters by brute-forcing HTTP requests. It … | 97 | 16593 | stable |
| fortra/impacket Impacket is a collection of Python classes for low-level programmatic access to network protocols, including full implementations of SMB1-3… | 83 | 16038 | active |
| zaproxy/zaproxy Zed Attack Proxy (ZAP) by Checkmarx is a free, open-source web application security scanner used for finding vulnerabilities in web apps du… | 78 | 15686 | stable |
| Evilginx Evilginx is a standalone man-in-the-middle attack framework written in Go that proxies traffic between a victim's browser and a legitimate … | 62 | 15535 | active |
| trustedsec/social-engineer-toolkit The Social-Engineer Toolkit (SET) is an open-source Python-based penetration testing framework for authorized social-engineering assessment… | 70 | 15239 | active |
| GreyDGL/PentestGPT PentestGPT is an AI-powered penetration testing agent framework that drives LLMs (Claude Code, Codex, or many providers in legacy mode) to … | 70 | 15091 | active |
| owasp-amass/amass OWASP Amass is a Go-based framework for in-depth attack surface mapping and external asset discovery using OSINT gathering and active recon… | 81 | 15047 | active |
| HunxByts/GhostTrack GhostTrack is a Python-based OSINT CLI tool for gathering information about IP addresses, phone numbers, and usernames across social media.… | 30 | 14943 | active |
| maurosoria/dirsearch dirsearch is an advanced web path scanner that brute-forces directories and files on web servers using wordlists. It is a Python CLI tool w… | 87 | 14662 | active |
| moonD4rk/HackBrowserData HackBrowserData is a self-contained Go CLI that extracts and decrypts browser data (passwords, cookies, history, bookmarks, credit cards, d… | 91 | 14458 | active |
| shadow1ng/fscan Fscan is a comprehensive intranet scanning tool written in Go that automates host discovery, port scanning, service identification, weak-pa… | 95 | 14450 | active |
| projectdiscovery/subfinder Subfinder is a fast, passive subdomain discovery tool written in Go that enumerates valid subdomains for target domains using online passiv… | 95 | 14315 | active |
| gophish/gophish Gophish is an open-source phishing framework for running phishing simulations and security awareness training. It provides a web UI and RES… | 23 | 14152 | stable |
| OJ/gobuster Gobuster is a fast, multi-threaded brute-forcing tool written in Go for enumerating web directories/files, DNS subdomains, virtual hosts, c… | 80 | 14038 | active |
| juice-shop/juice-shop OWASP Juice Shop is an intentionally insecure web application written in Node.js, Express, and Angular that covers vulnerabilities from the… | 94 | 13726 | active |
| digininja/DVWA Damn Vulnerable Web Application (DVWA) is a PHP/MariaDB web application intentionally riddled with common web vulnerabilities at multiple d… | 70 | 13551 | active |
| openwall/john John the Ripper jumbo is an open-source offline password cracker supporting hundreds of hash and cipher types, from Unix and Windows passwo… | 75 | 13543 | active |
| nmap/nmap Nmap is the industry-standard open-source network scanner for host discovery, port scanning, service/version detection, and OS fingerprinti… | 77 | 13465 | stable |
| threat9/routersploit RouterSploit is an open-source exploitation framework dedicated to embedded devices like routers, modeled after Metasploit. It provides mod… | 59 | 13223 | active |
| vanhauser-thc/thc-hydra THC-Hydra is a parallelized network login cracker supporting dozens of protocols (SSH, FTP, HTTP forms, SMB, RDP, databases, and more). It … | 80 | 12200 | active |
| justcallmekoko/ESP32Marauder ESP32 Marauder is a suite of WiFi and Bluetooth offensive and defensive security tools distributed as firmware for ESP32-based hardware. It… | 99 | 12134 | active |
| dstotijn/hetty Hetty is an open source HTTP toolkit for security research, serving as an alternative to Burp Suite Pro. It provides a MITM HTTP proxy with… | 65 | 12007 | active |
| BishopFox/sliver Sliver is an open-source cross-platform adversary emulation and red team framework written in Go. It generates dynamically compiled implant… | 90 | 11729 | active |
| chaitin/xray xray is a security assessment tool from Chaitin that scans web applications for common vulnerabilities like XSS and SQL injection, supporti… | 23 | 11720 | active |
| 0x4m4/hexstrike-ai HexStrike AI is an MCP server that bridges LLM agents (Claude, GPT, Copilot) with 150+ cybersecurity tools for autonomous penetration testi… | 61 | 11381 | active |
| 1N3/Sn1per Sn1per is an open-source automated penetration testing and attack surface management platform that chains reconnaissance, scanning, exploit… | 63 | 11043 | active |
| beefproject/beef BeEF (Browser Exploitation Framework) is a penetration testing tool focused on the web browser, hooking one or more browsers and using them… | 72 | 10983 | active |
| AlessandroZ/LaZagne LaZagne is an open-source Python application that recovers passwords stored locally by common software such as browsers, mail clients, WiFi… | 42 | 10963 | active |
| sullo/nikto Nikto is a Perl-based command-line web server scanner that tests servers for dangerous files, outdated software, misconfigurations, and kno… | 89 | 10684 | active |
| blacklanternsecurity/bbot BBOT is a recursive, multipurpose internet scanner built in Python for automating OSINT reconnaissance, bug bounty hunting, and attack surf… | 99 | 10508 | active |
| projectdiscovery/httpx httpx is a fast, multi-purpose HTTP toolkit written in Go that runs multiple probes (status codes, titles, TLS certificates, tech detection… | 93 | 10322 | active |
| samratashok/nishang Nishang is a framework and collection of PowerShell scripts and payloads for offensive security, penetration testing, and red teaming. It c… | 23 | 10069 | active |
| shmilylty/OneForAll OneForAll is a powerful Python-based subdomain collection and enumeration tool for reconnaissance. It gathers subdomains via brute forcing,… | 59 | 10029 | active |
| thewhiteh4t/seeker Seeker is a security testing tool that hosts a fake website asking users for browser location permission, capturing GPS coordinates (longit… | 72 | 9937 | active |
| wpscanteam/wpscan WPScan is a black-box WordPress security scanner written in Ruby, used by security professionals and site maintainers to audit WordPress in… | 93 | 9740 | active |
| malwaredllc/byob BYOB is an open-source post-exploitation framework written in Python, featuring a command-and-control server with a web GUI, a cross-platfo… | 76 | 9498 | active |
| sensepost/objection objection is a runtime mobile exploration toolkit powered by Frida for assessing the security posture of iOS and Android applications witho… | 88 | 9347 | active |
| evilsocket/pwnagotchi Pwnagotchi is an A2C deep reinforcement learning agent built on bettercap that learns from its surrounding WiFi environment to maximize cap… | 67 | 9189 | active |
| frohoff/ysoserial ysoserial is a proof-of-concept command-line tool that generates serialized Java payloads exploiting unsafe object deserialization using ga… | 48 | 9033 | active |
| yogeshojha/rengine reNgine is a self-hosted automated web reconnaissance and vulnerability scanning framework with configurable recon engines, data correlatio… | 64 | 8795 | active |
| Tsunami Security Scanner Tsunami is a general-purpose network security scanner from Google that detects high-severity vulnerabilities with high confidence. It relie… | 74 | 8606 | active |
| HavocFramework/Havoc Havoc is a modern, malleable post-exploitation command and control (C2) framework with a Go teamserver, a Qt-based cross-platform client, a… | 10 | 8507 | active |
| epi052/feroxbuster feroxbuster is a fast, recursive content discovery tool written in Rust that performs forced browsing against web servers. It brute-forces … | 72 | 8035 | active |
| six2dez/reconftw reconFTW is an open-source (MIT) automated reconnaissance framework written in Shell that orchestrates 80+ security tools to perform full r… | 86 | 8025 | active |
| v1s1t0r1sh3r3/airgeddon A multi-use bash script for auditing wireless networks on Linux, wrapping tools like aircrack-ng to automate attacks such as evil twin, WPS… | 93 | 7952 | active |
| PCILeech PCILeech is DMA attack software that uses PCIe hardware devices (or software memory acquisition methods) to read and write target system me… | 65 | 7899 | active |
| p1ngul1n0/blackbird Blackbird is a Python CLI OSINT tool that searches for user accounts by username or email across 600+ social networks and platforms, levera… | 46 | 7861 | active |
| Scout Suite Scout Suite is an open source multi-cloud security auditing tool that assesses the security posture of cloud environments. It gathers confi… | 42 | 7801 | stable |
| mandiant/commando-vm Commando VM is a fully customizable Windows-based security distribution for penetration testing and red teaming, packaged as a PowerShell i… | 53 | 7791 | active |
| hfiref0x/UACME UACMe is a C-based command-line tool that demonstrates dozens of Windows User Account Control (UAC) bypass techniques abusing built-in Auto… | 87 | 7764 | active |
| r0ysue/r0capture A Frida-based universal Android application-layer packet capture script that hooks SSL/TLS regardless of certificate pinning, obfuscation, … | 64 | 7750 | active |
| yaklang/yakit Yakit is an all-in-one interactive application security testing platform built as a GUI client for the Yaklang security DSL engine over gRP… | 95 | 7700 | active |
| aircrack-ng/aircrack-ng Aircrack-ng is a complete suite of command-line tools for assessing WiFi network security, covering packet capture, injection, monitor mode… | 62 | 7541 | active |
| apache/caldera Apache Caldera is a cybersecurity platform for automated adversary emulation built on the MITRE ATT&CK framework. It provides an asynchrono… | 79 | 7213 | active |
| ayoubfaouzi/al-khaser Al-Khaser is a proof-of-concept Windows application that demonstrates a wide range of malware anti-analysis techniques, including anti-debu… | 73 | 7108 | active |
| guardicore/monkey Infection Monkey is an open-source adversary emulation platform that simulates malware-like self-propagation across a network to test secur… | 31 | 7076 | active |
| LasCC/HackTools HackTools is an all-in-one browser extension for offensive security professionals that bundles penetration testing tools like XSS payloads,… | 23 | 7002 | active |
| urbanadventurer/WhatWeb WhatWeb is a command-line web scanner that identifies the technologies powering websites, including CMSs, web servers, JavaScript libraries… | 76 | 6800 | stable |
| ticarpi/jwt_tool A Python command-line toolkit for validating, forging, scanning, and tampering with JSON Web Tokens (JWTs). It automates checks for known J… | 31 | 6754 | active |
| AFLplusplus/AFLplusplus AFL++ is a superior, actively maintained fork of American Fuzzy Lop, a coverage-guided fuzzer with many mutators, power schedules, and inst… | 92 | 6736 | active |
| infobyte/faraday Faraday is an open-source vulnerability management platform that aggregates, normalizes, and deduplicates findings from over 90 security to… | 98 | 6695 | active |
| The-Z-Labs/linux-exploit-suggester A shell-based auditing tool that assesses a Linux system's exposure to publicly known kernel privilege escalation exploits based on kernel … | 65 | 6593 | active |
| BruceDevices/firmware Bruce is an open-source (AGPL-3.0) ESP32 firmware packed with offensive-security and Red Team tools such as WiFi attacks, Evil Portal, ward… | 90 | 6570 | active |
| j3ssie/osmedeus Osmedeus is a security-focused declarative orchestration engine that lets users define reconnaissance and vulnerability-scanning pipelines … | 93 | 6538 | active |
| EnableSecurity/wafw00f WAFW00F is a Python command-line tool that identifies and fingerprints Web Application Firewall (WAF) products protecting a website. It sen… | 79 | 6528 | stable |
| Mebus/cupp CUPP is a Python CLI tool that generates targeted password wordlists by profiling personal information about a user, such as birthdays, nic… | 74 | 6507 | active |
| s0md3v/Arjun Arjun is a Python command-line tool that discovers hidden HTTP query parameters for URL endpoints using a large dictionary of over 25,000 p… | 26 | 6385 | active |
| infinition/Bjorn Bjorn is an autonomous network scanning and offensive security tool that runs on a Raspberry Pi with a 2.13-inch e-Paper HAT. It discovers … | 63 | 6252 | active |
| projectdiscovery/naabu Naabu is a fast, lightweight port scanner written in Go that performs SYN, CONNECT, and UDP scans to enumerate open ports on hosts. It is d… | 89 | 6205 | active |
| k8gege/K8tools K8tools is a large curated collection of penetration testing and offensive security tools covering internal network penetration, privilege … | 34 | 6203 | active |
| GhostTroops/scan4all scan4all is a Go-based automated vulnerability scanning and reconnaissance tool that integrates vscan, nuclei, ksubdomain, and subfinder. I… | 23 | 6170 | active |
| DominicBreuker/pspy pspy is a command line tool that snoops on Linux processes without root permissions by combining procfs scans with inotify watchers to catc… | 54 | 6155 | stable |
| AzeemIdrisi/PhoneSploit-Pro PhoneSploit Pro is an all-in-one Python CLI tool for remotely exploiting and testing Android devices using ADB and the Metasploit Framework… | 88 | 6128 | active |
| InterceptSuite/ProxyBridge ProxyBridge is a free, open-source universal proxy client (Proxifier alternative) that transparently redirects TCP and UDP traffic from any… | 80 | 6128 | active |
| AutoRecon/AutoRecon AutoRecon is a multi-threaded Python CLI tool that automates network reconnaissance by performing port and service detection scans, then la… | 61 | 6093 | active |
| mishakorzik/AllHackingTools AllHackingTools is an all-in-one installer and menu system for Termux that automates downloading and installing a large collection of penet… | 56 | 6083 | active |
| alpkeskin/mosint Mosint is an automated email OSINT tool written in Go that investigates target email addresses by consolidating multiple services. It check… | 23 | 6008 | active |
| Ed1s0nZ/CyberStrikeAI CyberStrikeAI is a Go-based AI-native cybersecurity platform that combines LLM-powered agents, MCP-native tools, RAG knowledge bases, and v… | 79 | 5991 | active |
| RfidResearchGroup/proxmark3 The Iceman fork of Proxmark3, the client software for the Proxmark3 RFID analysis device, supporting reading, cloning, simulating, and snif… | 88 | 5986 | active |
page 1 / 14 next →