domain: penetration-testing
1317 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| byt3bl33d3r/DeathStar DeathStar is a Python CLI tool that automates gaining Domain and Enterprise Admin privileges in Active Directory environments by chaining c… | 32 | 1618 | maintenance |
| nccgroup/Winpayloads Winpayloads is a Python 2.7 tool for generating undetectable Windows payloads with extras like UAC bypass, persistence, and PowerShell stag… | 32 | 1616 | maintenance |
| stark0de/nginxpwner Nginxpwner is a Python command-line tool that scans Nginx servers for common misconfigurations and known vulnerabilities, such as CRLF inje… | 10 | 1599 | maintenance |
| tokyoneon/Chimera Chimera is a PowerShell obfuscation script that transforms malicious PS1 payloads using string substitution and variable concatenation to b… | 32 | 1597 | maintenance |
| outflanknl/Dumpert Dumpert is a proof-of-concept LSASS memory dumper written in C and assembly that uses direct system calls and API unhooking to evade AV/EDR… | 32 | 1595 | maintenance |
| Lotus6/ThinkphpGUI A Java-based GUI vulnerability exploitation tool targeting the ThinkPHP framework, supporting detection of vulnerabilities across ThinkPHP … | 23 | 1595 | maintenance |
| wyzxxz/shiro_rce_tool A Java-based command-line tool that assists in detecting and exploiting Apache Shiro rememberMe deserialization vulnerabilities. It brute-f… | 32 | 1594 | maintenance |
| sairson/Yasso Yasso is a Go-based intranet penetration testing toolkit that combines service brute-forcing (RDP, SSH, Redis, PostgreSQL, MongoDB, MSSQL, … | 23 | 1594 | maintenance |
| savio-code/fern-wifi-cracker Fern Wifi Cracker is a Python/Qt GUI application for wireless security auditing that can crack and recover WEP, WPA/WPA2, and WPS keys. It … | 70 | 1592 | maintenance |
| 0xHJK/dumpall dumpall is a Python command-line tool for exploiting information disclosure vulnerabilities on web servers. It reconstructs source code fro… | 23 | 1579 | maintenance |
| zidansec/CloudPeler CrimeFlare is a PHP command-line OSINT tool that attempts to reveal the real origin IP address behind websites protected by Cloudflare's WA… | 10 | 1576 | maintenance |
| XiphosResearch/exploits A collection of miscellaneous proof-of-concept exploit scripts written by Xiphos Research for security testing purposes, covering CVEs acro… | 32 | 1575 | maintenance |
| v3n0m-Scanner/V3n0M-Scanner V3n0M is an offensive security framework and vulnerability scanner written in Python 3.6+ using asyncio. It scans for SQLi, XSS, LFI/RFI vu… | 23 | 1573 | maintenance |
| DeEpinGh0st/Erebus Erebus is a post-exploitation plugin for Cobalt Strike written in PowerShell and Sleep (Aggressor Script). It bundles information gathering… | 23 | 1568 | maintenance |
| Viralmaniar/BigBountyRecon BigBountyRecon is a C# Windows GUI tool that automates initial reconnaissance on a target organisation using 58 techniques, including Googl… | 23 | 1564 | maintenance |
| Mr-Un1k0d3r/PowerLessShell PowerLessShell is a Python CLI tool that generates MSBuild project files capable of executing PowerShell scripts or raw shellcode without s… | 66 | 1559 | maintenance |
| Cn33liz/p0wnedShell p0wnedShell is a C# offensive PowerShell host application that runs PowerShell commands and modules within a runspace environment without r… | 32 | 1550 | maintenance |
| SharadKumar97/OSINT-SPY OSINT-SPY is a Python command-line tool that performs open-source intelligence scans on emails, domains, IP addresses, organizations, Bitco… | 23 | 1543 | maintenance |
| mandiant/SharPersist SharPersist is a Windows persistence toolkit written in C# that can add, remove, check, and list various persistence techniques such as reg… | 10 | 1542 | maintenance |
| xiecat/goblin Goblin is a phishing simulation system for red team/blue team security exercises, built in Go. It works as a reverse proxy that transparent… | 23 | 1538 | maintenance |
| s0md3v/Corsy Corsy is a lightweight Python 3 CLI tool that scans websites for known CORS (Cross-Origin Resource Sharing) misconfigurations. It tests for… | 23 | 1534 | maintenance |
| GhostPack/SharpUp SharpUp is a C# port of common Windows privilege escalation checks from the PowerUp PowerShell script. It audits a system for misconfigurat… | 32 | 1531 | maintenance |
| galkan/crowbar Crowbar is a Python-based brute forcing tool for penetration testing that supports protocols often missing from other brute force tools, su… | 23 | 1531 | maintenance |
| harleyQu1nn/AggressorScripts A curated collection of Aggressor scripts (.cna) for Cobalt Strike 3.0+, aggregated from multiple community sources. The scripts automate r… | 32 | 1530 | maintenance |
| Ha3MrX/InstaBrute InstaBrute is a shell script that performs brute-force password attacks against Instagram accounts, exploiting password-guessing vectors co… | 71 | 1527 | maintenance |
| Yaxser/Backstab Backstab is a Windows command-line tool that kills antimalware/EDR-protected processes by abusing the Microsoft-signed Sysinternals Process… | 23 | 1527 | maintenance |
| gentilkiwi/kekeo kekeo is a C-based command-line toolbox for manipulating Microsoft Kerberos, from the author of mimikatz. It supports operations like ticke… | 23 | 1521 | maintenance |
| CTF-MissFeng/bayonet Bayonet is a self-hosted web-based IT asset management and attack-surface platform for penetration testers, integrating subdomain enumerati… | 23 | 1517 | maintenance |
| chaitin/rad Rad (Radium) is a browser-based web crawler built for security scanning, driving a real Chrome browser to discover URLs and requests across… | 23 | 1514 | maintenance |
| WooyunDota/DroidSSLUnpinning A collection of Frida hook scripts (ObjectionUnpinningPlus) that bypass Android certificate pinning so HTTPS traffic can be intercepted wit… | 32 | 1509 | maintenance |
| ViRb3/TrustMeAlready An Xposed module for rooted Android devices that disables SSL certificate verification and pinning system-wide. It hooks Java trust-check m… | 10 | 1508 | maintenance |
| nidem/kerberoast A collection of Python and PowerShell tools for attacking Microsoft Kerberos implementations, including requesting service tickets, crackin… | 32 | 1507 | maintenance |
| hatRiot/zarp Zarp is a Python-based network attack tool focused on exploiting local networks by abusing networking protocols rather than systems. It pro… | 23 | 1504 | maintenance |
| pentestmonkey/windows-privesc-check A standalone Windows executable (built from Python with PyInstaller) that audits systems for privilege escalation vectors such as weak serv… | 32 | 1500 | maintenance |
| Kevin-Robertson/Powermad Powermad is a set of PowerShell functions for exploiting Active Directory's default MachineAccountQuota and Active Directory-Integrated DNS… | 32 | 1500 | maintenance |
| veo/wsMemShell A Java-based WebSocket memory webshell (memshell) tool that injects WebSocket endpoints into running application servers like Tomcat, Sprin… | 32 | 1490 | maintenance |
| mufeedvh/moonwalk moonwalk is a single-binary Rust CLI tool that covers tracks during Linux penetration testing by saving and reverting system log state, she… | 23 | 1488 | maintenance |
| 0x00-0x00/ShellPop ShellPop is a Python CLI tool that generates ready-to-use reverse and bind shell commands for penetration testing, with obfuscation, encode… | 23 | 1485 | maintenance |
| optiv/Freeze Freeze is a Go-based payload creation toolkit that generates Windows shellcode loaders designed to bypass EDR security controls. It uses su… | 10 | 1476 | maintenance |
| jordanpotti/AWSBucketDump AWSBucketDump is a Python CLI security tool that enumerates AWS S3 buckets using wordlists, similar to a subdomain bruteforcer but for S3. … | 32 | 1473 | maintenance |
| matterpreter/OffensiveCSharp A collection of standalone C# tools and proof-of-concept programs for offensive security operations, each compiled individually in Visual S… | 32 | 1473 | maintenance |
| 0x09AL/RdpThief RdpThief is a standalone DLL that, when injected into the mstsc.exe (Remote Desktop client) process, uses API hooking to extract clear-text… | 32 | 1469 | maintenance |
| antonioCoco/RemotePotato0 RemotePotato0 is a Windows privilege escalation exploit that abuses the DCOM activation service to trigger NTLM authentication from privile… | 23 | 1469 | maintenance |
| psypanda/hashID hashID is a Python CLI tool that identifies over 220 hash types using regular expressions, working on single hashes, files, or directories.… | 23 | 1468 | maintenance |
| rootclay/WMIHACKER WMIHACKER is a VBScript-based command-line tool for lateral movement on Windows hosts via WMI (port 135), avoiding the commonly detected 44… | 33 | 1465 | maintenance |
| nccgroup/house House is a runtime mobile application analysis toolkit with a web GUI, powered by Frida and written in Python. It simplifies dynamic functi… | 32 | 1463 | maintenance |
| woodpecker-framework/woodpecker-framework-release Woodpecker-framework is a Java-based vulnerability detection and deep exploitation framework focused on precisely targeting high-risk vulne… | 23 | 1463 | maintenance |
| twelvesec/gasmask GasMasK is an all-in-one open source OSINT and reconnaissance tool written in Python 3. It aggregates information about a target domain fro… | 23 | 1462 | maintenance |
| wyzxxz/heapdump_tool A Java-based CLI tool that parses JVM heapdump files (via jhat) to search for sensitive information such as plaintext passwords, cloud acce… | 32 | 1457 | maintenance |
| SySS-Research/Seth Seth is a Python and Bash proof-of-concept tool that performs a man-in-the-middle attack on RDP connections via ARP spoofing, downgrading t… | 56 | 1454 | maintenance |
| QAX-A-Team/BrowserGhost BrowserGhost is a C# command-line tool for red team operators that extracts saved browser credentials, cookies, history, and bookmarks from… | 23 | 1452 | maintenance |
| oddcod3/Phantom-Evasion Phantom-Evasion is a Python-based antivirus evasion tool that generates obfuscated executables and payloads designed to bypass antivirus de… | 10 | 1449 | maintenance |
| SamJoan/droopescan Droopescan is a plugin-based command-line scanner that helps security researchers identify the CMS, version, plugins, themes, and interesti… | 32 | 1445 | maintenance |
| Raikia/FiercePhish FiercePhish is a self-hosted PHP web application for managing full phishing engagements, including campaign tracking, scheduled email sendi… | 23 | 1437 | maintenance |
| jweny/pocassist Pocassist is an open-source vulnerability PoC testing framework written in Go that lets users edit, run, and batch-test PoCs through a web … | 10 | 1436 | maintenance |
| spacehuhn/wifi_ducky WiFi Ducky is a Wi-Fi controlled BadUSB device built from an ESP8266 and ATmega32U4 that uploads, saves, and remotely executes Ducky Script… | 23 | 1435 | maintenance |
| BugScanTeam/DNSLog DNSLog is a self-hosted tool that monitors DNS resolution records and HTTP access logs, built on Django with an integrated DNS server. It i… | 10 | 1435 | maintenance |
| nccgroup/demiguise Demiguise is a Python CLI tool from NCC Group that generates HTML files containing RC4-encrypted HTA payloads, which are decrypted dynamica… | 32 | 1429 | maintenance |
| FunnyWolf/pystinger Pystinger is a Python tool that establishes a SOCKS4a proxy and port mapping through a webshell (PHP, JSP, or ASPX) on a compromised server… | 23 | 1427 | maintenance |
| 7kbstorm/7kbscan-WebPathBrute 7kbscan-WebPathBrute is a Windows GUI tool for brute-forcing web paths and directories using dictionaries. It supports multithreaded scanni… | 23 | 1423 | maintenance |
| paranoidninja/CarbonCopy A Python CLI tool that downloads a website's TLS certificate, creates a spoofed version of it, and uses it to sign Windows executables for … | 32 | 1421 | maintenance |
| ptoomey3/Keychain-Dumper A command-line tool for jailbroken iOS devices that dumps Keychain items (passwords, certificates, identities) accessible to an attacker. I… | 23 | 1419 | maintenance |
| Mr-Un1k0d3r/DKMC DKMC (Don't Kill My Cat) is a Python CLI tool that embeds obfuscated shellcode inside valid BMP images, producing polyglot files that are b… | 10 | 1418 | maintenance |
| brannondorsey/naive-hashcat A plug-and-play shell script wrapper around hashcat that cracks password hashes using pre-configured, empirically tested attack parameters.… | 23 | 1416 | maintenance |
| Lucifer1993/struts-scan A Python2 command-line tool that detects and exploits Apache Struts2 remote code execution vulnerabilities across all major versions (ST2-0… | 32 | 1412 | maintenance |
| cube0x0/noPac A C# tool that scans for and exploits the CVE-2021-42287/CVE-2021-42278 Active Directory vulnerability chain, allowing a standard domain us… | 32 | 1412 | maintenance |
| m4ll0k/Atlas Atlas is a Python CLI tool that suggests SQLMap tamper scripts to bypass WAF/IDS/IPS protections during SQL injection testing. It works by … | 32 | 1411 | maintenance |
| CiscoCXSecurity/enum4linux enum4Linux is a Perl-based CLI tool that enumerates information from Windows and Samba hosts, serving as a Linux alternative to enum.exe. I… | 71 | 1407 | maintenance |
| c0ny1/FastjsonExploit A Java CLI framework for quickly exploiting Fast deserialization vulnerabilities. It generates exploit payloads with one command and bundle… | 32 | 1406 | maintenance |
| hakluke/weaponised-XSS-payloads A collection of weaponised XSS payloads - JavaScript files that perform sensitive actions (like creating admin users) on popular CMS platfo… | 32 | 1404 | maintenance |
| maK-/parameth parameth is a Python command-line tool that brute-forces GET and POST parameter names on web endpoints by comparing response differences. I… | 10 | 1396 | maintenance |
| sham00n/buster Buster is a Python command-line OSINT tool for email reconnaissance. It finds social accounts linked to an email, data breaches, pastes, re… | 32 | 1395 | maintenance |
| 649/Memcrashed-DDoS-Exploit A Python CLI exploit tool that finds exposed Memcached servers via the Shodan API and sends forged UDP packets to them to amplify DDoS atta… | 32 | 1394 | maintenance |
| ustayready/CredSniper CredSniper is a phishing framework built on Python's Flask micro-framework and Jinja2 templating that launches realistic phishing sites wit… | 32 | 1392 | maintenance |
| NytroRST/NetRipper NetRipper is a Windows post-exploitation tool that uses API hooking to intercept network traffic, capturing both plain-text and encrypted d… | 32 | 1390 | maintenance |
| BastilleResearch/mousejack A collection of device discovery and research tools for the MouseJack vulnerabilities affecting wireless mice and keyboards using nRF24LU1+… | 32 | 1386 | maintenance |
| importCTF/Instagram-Hacker A Python command-line script that performs brute-force password attacks against Instagram accounts, using mechanize and requests with optio… | 32 | 1384 | maintenance |
| 3ndG4me/AutoBlue-MS17-010 A semi-automated, standalone Python exploit for the MS17-010 (EternalBlue) SMB vulnerability that generates kernel shellcode and handles li… | 32 | 1382 | maintenance |
| lijiejie/swagger-exp A Python-based Swagger REST API information disclosure exploitation tool. It enumerates API endpoints, auto-fills parameters, tests for una… | 32 | 1381 | maintenance |
| screetsec/Dracnmap Dracnmap is a shell-based menu tool that wraps nmap to simplify network scanning and information gathering. It exposes nmap's advanced scri… | 23 | 1380 | maintenance |
| fnmsd/MySQL_Fake_Server A pure Python3 fake MySQL server used in penetration testing to exploit MySQL client file reading and trigger Java deserialization attacks … | 32 | 1378 | maintenance |
| bitsadmin/fakelogonscreen FakeLogonScreen is a red-team utility that displays a fake Windows logon screen to capture a user's password, validating it against Active … | 23 | 1378 | maintenance |
| TideSec/Mars Mars is a self-hosted security platform for asset discovery, subdomain enumeration, port and web fingerprinting, and change monitoring of i… | 32 | 1376 | maintenance |
| Katana Katana is a Python CLI tool by John Hammond that automates common low-hanging-fruit checks for CTF challenges, paired with ctf-katana, a cu… | 32 | 1363 | maintenance |
| danigargu/CVE-2020-0796 A proof-of-concept exploit for CVE-2020-0796 (SMBGhost), a local privilege escalation vulnerability in Windows 10's SMBv3 client driver. Wr… | 23 | 1359 | maintenance |
| ReversecLabs/SharpGPOAbuse SharpGPOAbuse is a C# .NET command-line tool that abuses a user's edit rights on a Group Policy Object to compromise objects controlled by … | 32 | 1353 | maintenance |
| jeffzh3ng/fuxi Fuxi is a self-hosted penetration testing platform written in Python that provides a web interface for organizing and running security asse… | 32 | 1346 | maintenance |
| LittleBear4/OA-EXPTOOL A Python-based exploitation framework targeting Chinese OA (Office Automation) systems, bundling nearly 20 batch vulnerability scanners for… | 23 | 1345 | maintenance |
| trustedsec/trevorc2 TrevorC2 is a client/server command-and-control framework that tunnels communications through a browsable, legitimate-looking website to ev… | 32 | 1344 | maintenance |
| OmerYa/Invisi-Shell Invisi-Shell is a proof-of-concept tool that bypasses PowerShell security features (ScriptBlock logging, Module logging, Transcription, AMS… | 32 | 1339 | maintenance |
| pwnesia/ssb SSB (Secure Shell Bruteforcer) is a fast, concurrent SSH password brute-forcing tool written in Go. It attempts to authenticate against an … | 23 | 1335 | maintenance |
| Arvanaghi/SessionGopher SessionGopher is a PowerShell tool that extracts and decrypts saved session information for remote access tools like WinSCP, PuTTY, SuperPu… | 32 | 1334 | maintenance |
| GhostPack/SafetyKatz SafetyKatz is a C# tool that combines a modified Mimikatz with a .NET PE loader to dump LSASS memory and extract credentials. It minidumps … | 32 | 1332 | maintenance |
| tyranid/DotNetToJScript A C# command-line tool that generates JScript (or VBScript/VBA/scriptlet) files which bootstrap and load a .NET assembly entirely from memo… | 23 | 1332 | maintenance |
| g0tmi1k/msfpc MSFPC is a shell-based wrapper around msfvenom that generates Meterpreter payloads with minimal input, such as just a platform name or file… | 23 | 1331 | maintenance |
| infobyte/evilgrade Evilgrade is a modular penetration testing framework that exploits poor software update implementations by injecting fake updates via DNS m… | 23 | 1326 | maintenance |
| 4ra1n/super-xray Super Xray is a Java-based GUI launcher for the xray web vulnerability scanner, wrapping its command-line interface and config.yaml setup i… | 10 | 1325 | maintenance |
| stampery/mongoaudit mongoaudit is a Python CLI tool that audits MongoDB servers for poor security configurations, known vulnerabilities, and misconfigurations.… | 23 | 1324 | maintenance |
| myzxcg/RealBlindingEDR A Windows offensive security tool that uses arbitrary kernel read/write via a signed driver to remove AV/EDR kernel callbacks (ObRegisterCa… | 18 | 1324 | maintenance |
| dirkjanm/CVE-2020-1472 A proof-of-concept exploit for CVE-2020-1472 (Zerologon), a critical Netlogon privilege escalation vulnerability in Windows domain controll… | 32 | 1320 | maintenance |