Ross ROSS = Recommend OSS · open-source software intelligence for agents

domain: penetration-testing

1317 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
byt3bl33d3r/DeathStar
DeathStar is a Python CLI tool that automates gaining Domain and Enterprise Admin privileges in Active Directory environments by chaining c…
321618maintenance
nccgroup/Winpayloads
Winpayloads is a Python 2.7 tool for generating undetectable Windows payloads with extras like UAC bypass, persistence, and PowerShell stag…
321616maintenance
stark0de/nginxpwner
Nginxpwner is a Python command-line tool that scans Nginx servers for common misconfigurations and known vulnerabilities, such as CRLF inje…
101599maintenance
tokyoneon/Chimera
Chimera is a PowerShell obfuscation script that transforms malicious PS1 payloads using string substitution and variable concatenation to b…
321597maintenance
outflanknl/Dumpert
Dumpert is a proof-of-concept LSASS memory dumper written in C and assembly that uses direct system calls and API unhooking to evade AV/EDR…
321595maintenance
Lotus6/ThinkphpGUI
A Java-based GUI vulnerability exploitation tool targeting the ThinkPHP framework, supporting detection of vulnerabilities across ThinkPHP …
231595maintenance
wyzxxz/shiro_rce_tool
A Java-based command-line tool that assists in detecting and exploiting Apache Shiro rememberMe deserialization vulnerabilities. It brute-f…
321594maintenance
sairson/Yasso
Yasso is a Go-based intranet penetration testing toolkit that combines service brute-forcing (RDP, SSH, Redis, PostgreSQL, MongoDB, MSSQL, …
231594maintenance
savio-code/fern-wifi-cracker
Fern Wifi Cracker is a Python/Qt GUI application for wireless security auditing that can crack and recover WEP, WPA/WPA2, and WPS keys. It …
701592maintenance
0xHJK/dumpall
dumpall is a Python command-line tool for exploiting information disclosure vulnerabilities on web servers. It reconstructs source code fro…
231579maintenance
zidansec/CloudPeler
CrimeFlare is a PHP command-line OSINT tool that attempts to reveal the real origin IP address behind websites protected by Cloudflare's WA…
101576maintenance
XiphosResearch/exploits
A collection of miscellaneous proof-of-concept exploit scripts written by Xiphos Research for security testing purposes, covering CVEs acro…
321575maintenance
v3n0m-Scanner/V3n0M-Scanner
V3n0M is an offensive security framework and vulnerability scanner written in Python 3.6+ using asyncio. It scans for SQLi, XSS, LFI/RFI vu…
231573maintenance
DeEpinGh0st/Erebus
Erebus is a post-exploitation plugin for Cobalt Strike written in PowerShell and Sleep (Aggressor Script). It bundles information gathering…
231568maintenance
Viralmaniar/BigBountyRecon
BigBountyRecon is a C# Windows GUI tool that automates initial reconnaissance on a target organisation using 58 techniques, including Googl…
231564maintenance
Mr-Un1k0d3r/PowerLessShell
PowerLessShell is a Python CLI tool that generates MSBuild project files capable of executing PowerShell scripts or raw shellcode without s…
661559maintenance
Cn33liz/p0wnedShell
p0wnedShell is a C# offensive PowerShell host application that runs PowerShell commands and modules within a runspace environment without r…
321550maintenance
SharadKumar97/OSINT-SPY
OSINT-SPY is a Python command-line tool that performs open-source intelligence scans on emails, domains, IP addresses, organizations, Bitco…
231543maintenance
mandiant/SharPersist
SharPersist is a Windows persistence toolkit written in C# that can add, remove, check, and list various persistence techniques such as reg…
101542maintenance
xiecat/goblin
Goblin is a phishing simulation system for red team/blue team security exercises, built in Go. It works as a reverse proxy that transparent…
231538maintenance
s0md3v/Corsy
Corsy is a lightweight Python 3 CLI tool that scans websites for known CORS (Cross-Origin Resource Sharing) misconfigurations. It tests for…
231534maintenance
GhostPack/SharpUp
SharpUp is a C# port of common Windows privilege escalation checks from the PowerUp PowerShell script. It audits a system for misconfigurat…
321531maintenance
galkan/crowbar
Crowbar is a Python-based brute forcing tool for penetration testing that supports protocols often missing from other brute force tools, su…
231531maintenance
harleyQu1nn/AggressorScripts
A curated collection of Aggressor scripts (.cna) for Cobalt Strike 3.0+, aggregated from multiple community sources. The scripts automate r…
321530maintenance
Ha3MrX/InstaBrute
InstaBrute is a shell script that performs brute-force password attacks against Instagram accounts, exploiting password-guessing vectors co…
711527maintenance
Yaxser/Backstab
Backstab is a Windows command-line tool that kills antimalware/EDR-protected processes by abusing the Microsoft-signed Sysinternals Process…
231527maintenance
gentilkiwi/kekeo
kekeo is a C-based command-line toolbox for manipulating Microsoft Kerberos, from the author of mimikatz. It supports operations like ticke…
231521maintenance
CTF-MissFeng/bayonet
Bayonet is a self-hosted web-based IT asset management and attack-surface platform for penetration testers, integrating subdomain enumerati…
231517maintenance
chaitin/rad
Rad (Radium) is a browser-based web crawler built for security scanning, driving a real Chrome browser to discover URLs and requests across…
231514maintenance
WooyunDota/DroidSSLUnpinning
A collection of Frida hook scripts (ObjectionUnpinningPlus) that bypass Android certificate pinning so HTTPS traffic can be intercepted wit…
321509maintenance
ViRb3/TrustMeAlready
An Xposed module for rooted Android devices that disables SSL certificate verification and pinning system-wide. It hooks Java trust-check m…
101508maintenance
nidem/kerberoast
A collection of Python and PowerShell tools for attacking Microsoft Kerberos implementations, including requesting service tickets, crackin…
321507maintenance
hatRiot/zarp
Zarp is a Python-based network attack tool focused on exploiting local networks by abusing networking protocols rather than systems. It pro…
231504maintenance
pentestmonkey/windows-privesc-check
A standalone Windows executable (built from Python with PyInstaller) that audits systems for privilege escalation vectors such as weak serv…
321500maintenance
Kevin-Robertson/Powermad
Powermad is a set of PowerShell functions for exploiting Active Directory's default MachineAccountQuota and Active Directory-Integrated DNS…
321500maintenance
veo/wsMemShell
A Java-based WebSocket memory webshell (memshell) tool that injects WebSocket endpoints into running application servers like Tomcat, Sprin…
321490maintenance
mufeedvh/moonwalk
moonwalk is a single-binary Rust CLI tool that covers tracks during Linux penetration testing by saving and reverting system log state, she…
231488maintenance
0x00-0x00/ShellPop
ShellPop is a Python CLI tool that generates ready-to-use reverse and bind shell commands for penetration testing, with obfuscation, encode…
231485maintenance
optiv/Freeze
Freeze is a Go-based payload creation toolkit that generates Windows shellcode loaders designed to bypass EDR security controls. It uses su…
101476maintenance
jordanpotti/AWSBucketDump
AWSBucketDump is a Python CLI security tool that enumerates AWS S3 buckets using wordlists, similar to a subdomain bruteforcer but for S3. …
321473maintenance
matterpreter/OffensiveCSharp
A collection of standalone C# tools and proof-of-concept programs for offensive security operations, each compiled individually in Visual S…
321473maintenance
0x09AL/RdpThief
RdpThief is a standalone DLL that, when injected into the mstsc.exe (Remote Desktop client) process, uses API hooking to extract clear-text…
321469maintenance
antonioCoco/RemotePotato0
RemotePotato0 is a Windows privilege escalation exploit that abuses the DCOM activation service to trigger NTLM authentication from privile…
231469maintenance
psypanda/hashID
hashID is a Python CLI tool that identifies over 220 hash types using regular expressions, working on single hashes, files, or directories.…
231468maintenance
rootclay/WMIHACKER
WMIHACKER is a VBScript-based command-line tool for lateral movement on Windows hosts via WMI (port 135), avoiding the commonly detected 44…
331465maintenance
nccgroup/house
House is a runtime mobile application analysis toolkit with a web GUI, powered by Frida and written in Python. It simplifies dynamic functi…
321463maintenance
woodpecker-framework/woodpecker-framework-release
Woodpecker-framework is a Java-based vulnerability detection and deep exploitation framework focused on precisely targeting high-risk vulne…
231463maintenance
twelvesec/gasmask
GasMasK is an all-in-one open source OSINT and reconnaissance tool written in Python 3. It aggregates information about a target domain fro…
231462maintenance
wyzxxz/heapdump_tool
A Java-based CLI tool that parses JVM heapdump files (via jhat) to search for sensitive information such as plaintext passwords, cloud acce…
321457maintenance
SySS-Research/Seth
Seth is a Python and Bash proof-of-concept tool that performs a man-in-the-middle attack on RDP connections via ARP spoofing, downgrading t…
561454maintenance
QAX-A-Team/BrowserGhost
BrowserGhost is a C# command-line tool for red team operators that extracts saved browser credentials, cookies, history, and bookmarks from…
231452maintenance
oddcod3/Phantom-Evasion
Phantom-Evasion is a Python-based antivirus evasion tool that generates obfuscated executables and payloads designed to bypass antivirus de…
101449maintenance
SamJoan/droopescan
Droopescan is a plugin-based command-line scanner that helps security researchers identify the CMS, version, plugins, themes, and interesti…
321445maintenance
Raikia/FiercePhish
FiercePhish is a self-hosted PHP web application for managing full phishing engagements, including campaign tracking, scheduled email sendi…
231437maintenance
jweny/pocassist
Pocassist is an open-source vulnerability PoC testing framework written in Go that lets users edit, run, and batch-test PoCs through a web …
101436maintenance
spacehuhn/wifi_ducky
WiFi Ducky is a Wi-Fi controlled BadUSB device built from an ESP8266 and ATmega32U4 that uploads, saves, and remotely executes Ducky Script…
231435maintenance
BugScanTeam/DNSLog
DNSLog is a self-hosted tool that monitors DNS resolution records and HTTP access logs, built on Django with an integrated DNS server. It i…
101435maintenance
nccgroup/demiguise
Demiguise is a Python CLI tool from NCC Group that generates HTML files containing RC4-encrypted HTA payloads, which are decrypted dynamica…
321429maintenance
FunnyWolf/pystinger
Pystinger is a Python tool that establishes a SOCKS4a proxy and port mapping through a webshell (PHP, JSP, or ASPX) on a compromised server…
231427maintenance
7kbstorm/7kbscan-WebPathBrute
7kbscan-WebPathBrute is a Windows GUI tool for brute-forcing web paths and directories using dictionaries. It supports multithreaded scanni…
231423maintenance
paranoidninja/CarbonCopy
A Python CLI tool that downloads a website's TLS certificate, creates a spoofed version of it, and uses it to sign Windows executables for …
321421maintenance
ptoomey3/Keychain-Dumper
A command-line tool for jailbroken iOS devices that dumps Keychain items (passwords, certificates, identities) accessible to an attacker. I…
231419maintenance
Mr-Un1k0d3r/DKMC
DKMC (Don't Kill My Cat) is a Python CLI tool that embeds obfuscated shellcode inside valid BMP images, producing polyglot files that are b…
101418maintenance
brannondorsey/naive-hashcat
A plug-and-play shell script wrapper around hashcat that cracks password hashes using pre-configured, empirically tested attack parameters.…
231416maintenance
Lucifer1993/struts-scan
A Python2 command-line tool that detects and exploits Apache Struts2 remote code execution vulnerabilities across all major versions (ST2-0…
321412maintenance
cube0x0/noPac
A C# tool that scans for and exploits the CVE-2021-42287/CVE-2021-42278 Active Directory vulnerability chain, allowing a standard domain us…
321412maintenance
m4ll0k/Atlas
Atlas is a Python CLI tool that suggests SQLMap tamper scripts to bypass WAF/IDS/IPS protections during SQL injection testing. It works by …
321411maintenance
CiscoCXSecurity/enum4linux
enum4Linux is a Perl-based CLI tool that enumerates information from Windows and Samba hosts, serving as a Linux alternative to enum.exe. I…
711407maintenance
c0ny1/FastjsonExploit
A Java CLI framework for quickly exploiting Fast deserialization vulnerabilities. It generates exploit payloads with one command and bundle…
321406maintenance
hakluke/weaponised-XSS-payloads
A collection of weaponised XSS payloads - JavaScript files that perform sensitive actions (like creating admin users) on popular CMS platfo…
321404maintenance
maK-/parameth
parameth is a Python command-line tool that brute-forces GET and POST parameter names on web endpoints by comparing response differences. I…
101396maintenance
sham00n/buster
Buster is a Python command-line OSINT tool for email reconnaissance. It finds social accounts linked to an email, data breaches, pastes, re…
321395maintenance
649/Memcrashed-DDoS-Exploit
A Python CLI exploit tool that finds exposed Memcached servers via the Shodan API and sends forged UDP packets to them to amplify DDoS atta…
321394maintenance
ustayready/CredSniper
CredSniper is a phishing framework built on Python's Flask micro-framework and Jinja2 templating that launches realistic phishing sites wit…
321392maintenance
NytroRST/NetRipper
NetRipper is a Windows post-exploitation tool that uses API hooking to intercept network traffic, capturing both plain-text and encrypted d…
321390maintenance
BastilleResearch/mousejack
A collection of device discovery and research tools for the MouseJack vulnerabilities affecting wireless mice and keyboards using nRF24LU1+…
321386maintenance
importCTF/Instagram-Hacker
A Python command-line script that performs brute-force password attacks against Instagram accounts, using mechanize and requests with optio…
321384maintenance
3ndG4me/AutoBlue-MS17-010
A semi-automated, standalone Python exploit for the MS17-010 (EternalBlue) SMB vulnerability that generates kernel shellcode and handles li…
321382maintenance
lijiejie/swagger-exp
A Python-based Swagger REST API information disclosure exploitation tool. It enumerates API endpoints, auto-fills parameters, tests for una…
321381maintenance
screetsec/Dracnmap
Dracnmap is a shell-based menu tool that wraps nmap to simplify network scanning and information gathering. It exposes nmap's advanced scri…
231380maintenance
fnmsd/MySQL_Fake_Server
A pure Python3 fake MySQL server used in penetration testing to exploit MySQL client file reading and trigger Java deserialization attacks …
321378maintenance
bitsadmin/fakelogonscreen
FakeLogonScreen is a red-team utility that displays a fake Windows logon screen to capture a user's password, validating it against Active …
231378maintenance
TideSec/Mars
Mars is a self-hosted security platform for asset discovery, subdomain enumeration, port and web fingerprinting, and change monitoring of i…
321376maintenance
Katana
Katana is a Python CLI tool by John Hammond that automates common low-hanging-fruit checks for CTF challenges, paired with ctf-katana, a cu…
321363maintenance
danigargu/CVE-2020-0796
A proof-of-concept exploit for CVE-2020-0796 (SMBGhost), a local privilege escalation vulnerability in Windows 10's SMBv3 client driver. Wr…
231359maintenance
ReversecLabs/SharpGPOAbuse
SharpGPOAbuse is a C# .NET command-line tool that abuses a user's edit rights on a Group Policy Object to compromise objects controlled by …
321353maintenance
jeffzh3ng/fuxi
Fuxi is a self-hosted penetration testing platform written in Python that provides a web interface for organizing and running security asse…
321346maintenance
LittleBear4/OA-EXPTOOL
A Python-based exploitation framework targeting Chinese OA (Office Automation) systems, bundling nearly 20 batch vulnerability scanners for…
231345maintenance
trustedsec/trevorc2
TrevorC2 is a client/server command-and-control framework that tunnels communications through a browsable, legitimate-looking website to ev…
321344maintenance
OmerYa/Invisi-Shell
Invisi-Shell is a proof-of-concept tool that bypasses PowerShell security features (ScriptBlock logging, Module logging, Transcription, AMS…
321339maintenance
pwnesia/ssb
SSB (Secure Shell Bruteforcer) is a fast, concurrent SSH password brute-forcing tool written in Go. It attempts to authenticate against an …
231335maintenance
Arvanaghi/SessionGopher
SessionGopher is a PowerShell tool that extracts and decrypts saved session information for remote access tools like WinSCP, PuTTY, SuperPu…
321334maintenance
GhostPack/SafetyKatz
SafetyKatz is a C# tool that combines a modified Mimikatz with a .NET PE loader to dump LSASS memory and extract credentials. It minidumps …
321332maintenance
tyranid/DotNetToJScript
A C# command-line tool that generates JScript (or VBScript/VBA/scriptlet) files which bootstrap and load a .NET assembly entirely from memo…
231332maintenance
g0tmi1k/msfpc
MSFPC is a shell-based wrapper around msfvenom that generates Meterpreter payloads with minimal input, such as just a platform name or file…
231331maintenance
infobyte/evilgrade
Evilgrade is a modular penetration testing framework that exploits poor software update implementations by injecting fake updates via DNS m…
231326maintenance
4ra1n/super-xray
Super Xray is a Java-based GUI launcher for the xray web vulnerability scanner, wrapping its command-line interface and config.yaml setup i…
101325maintenance
stampery/mongoaudit
mongoaudit is a Python CLI tool that audits MongoDB servers for poor security configurations, known vulnerabilities, and misconfigurations.…
231324maintenance
myzxcg/RealBlindingEDR
A Windows offensive security tool that uses arbitrary kernel read/write via a signed driver to remove AV/EDR kernel callbacks (ObRegisterCa…
181324maintenance
dirkjanm/CVE-2020-1472
A proof-of-concept exploit for CVE-2020-1472 (Zerologon), a critical Netlogon privilege escalation vulnerability in Windows domain controll…
321320maintenance

← prev page 10 / 14 next →