domain: penetration-testing
1317 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| TermuxHackz/wifi-hacker A shell script that automates attacking wireless connections using built-in Kali Linux tools, supporting WEP, WPS, WPA, and WPA2 securities… | 32 | 1319 | maintenance |
| redhuntlabs/RedHunt-OS RedHunt OS is a pre-configured Linux virtual machine (OVA) bundling adversary emulation and threat hunting tools such as Caldera, Atomic Re… | 33 | 1318 | maintenance |
| vanhoefm/fragattacks A security testing tool that tests Wi-Fi clients and access points for the FragAttacks fragmentation and aggregation vulnerabilities affect… | 41 | 1311 | maintenance |
| vincentcox/bypass-firewalls-by-DNS-history A shell script that attempts to bypass web application firewalls (like Cloudflare, Incapsula, SUCURI) by finding the origin server IP throu… | 32 | 1306 | maintenance |
| k8gege/K8CScan K8CScan is a high-concurrency, plugin-based scanner designed for large internal network penetration testing. It bundles information gatheri… | 32 | 1303 | maintenance |
| Viralmaniar/Passhunt Passhunt is a Python-based command-line tool for searching default credentials across 523 vendors and 2084 default passwords for network de… | 23 | 1303 | maintenance |
| nccgroup/SocksOverRDP A SOCKS4/4a/5 proxy implementation that tunnels traffic over RDP or Citrix (XenApp/XenDesktop) connections using Dynamic Virtual Channels. … | 23 | 1299 | maintenance |
| Vu1nT0tal/IoT-vulhub A collection of Docker-based environments for reproducing IoT firmware vulnerabilities, inspired by the Vulhub project. It uses binwalk for… | 23 | 1294 | maintenance |
| kinghacker0/WishFish WishFish is a bash-based security testing tool that generates phishing-style links (wishing or custom pages) which, when opened by a target… | 32 | 1290 | maintenance |
| med0x2e/SigFlip SigFlip is a red-team tool for patching Authenticode-signed PE files (exe, dll, sys) without invalidating their existing signatures, by emb… | 32 | 1290 | maintenance |
| smxiazi/xia_sql A Burp Suite extension (written in Java) that appends single and double quotes to every request parameter to detect possible SQL injection,… | 23 | 1286 | maintenance |
| entropy1337/infernal-twin Infernal-Wireless is an automated wireless hacking framework written in Python that aids penetration testers in assessing Wi-Fi security. I… | 23 | 1285 | maintenance |
| hangetzzu/saycheese SayCheese is a shell-based social engineering tool that generates a malicious HTTPS page to capture webcam photos from a target who clicks … | 32 | 1284 | maintenance |
| c0ny1/upload-fuzz-dic-builder A Python CLI script that generates fuzzing dictionaries for testing file upload vulnerabilities. It tailors wordlists based on target detai… | 32 | 1279 | maintenance |
| yzddmr6/webshell-venom A tool that generates unlimited polymorphic (AV-evading) webshells for penetration testing. It mutates webshell code to bypass antivirus an… | 10 | 1278 | maintenance |
| rbsec/dnscan dnscan is a Python command-line tool that performs DNS subdomain enumeration using wordlists, attempting zone transfers first and falling b… | 32 | 1277 | maintenance |
| khast3x/Redcloud Redcloud is a Python-based toolbox that automates deployment of red team attack infrastructure using Docker, deployable locally or remotely… | 23 | 1276 | maintenance |
| netxfly/x-crack x-crack is a command-line weak password (credential brute-force) scanner written in Go that tests common username/password combinations aga… | 23 | 1276 | maintenance |
| SECFORCE/Tunna Tunna is a Python toolset that tunnels arbitrary TCP connections over HTTP using a remote webshell and a local SOCKS-capable proxy. It is d… | 32 | 1274 | maintenance |
| screetsec/Brutal Brutal is a Linux toolkit for generating HID attack payloads for Teensy boards, similar to a Rubber Ducky but with different syntax. It cre… | 32 | 1270 | maintenance |
| darkr4y/geacon Geacon is a Go implementation of CobaltStrike's Beacon implant, built to study the C2 protocol through reverse engineering. It supports com… | 32 | 1266 | maintenance |
| UzJu/Cloud-Bucket-Leak-Detection-Tools A Python CLI tool that detects misconfigured and leaked cloud storage buckets across six major cloud providers including Aliyun, Tencent Cl… | 29 | 1266 | maintenance |
| lintstar/LSTAR LSTAR is a comprehensive Cobalt Strike post-exploitation Aggressor plugin written in PowerShell and CNA. It consolidates host information g… | 23 | 1266 | maintenance |
| shack2/SuperSQLInjectionV1 SuperSQLInjection (SSQLInjection) is a C#-based GUI SQL injection tool that builds raw HTTP requests over TCP sessions, supporting injectio… | 23 | 1266 | maintenance |
| Cybellum/DoubleAgent DoubleAgent is a research tool and proof-of-concept demonstrating a zero-day code injection and persistence technique on Windows, exploitin… | 32 | 1262 | maintenance |
| andresriancho/enumerate-iam A Python CLI tool that enumerates the IAM permissions associated with an AWS credential set by brute-forcing all non-destructive API calls … | 32 | 1252 | maintenance |
| pmiaowu/BurpFastJsonScan A passive BurpSuite extension written in Java that detects FastJson deserialization vulnerabilities in JSON-bearing HTTP requests. It autom… | 23 | 1251 | maintenance |
| W01fh4cker/Serein Serein is a graphical Python tool for batch-collecting URLs via the FOFA search engine API and running batch detection/exploitation of know… | 10 | 1250 | maintenance |
| m4n3dw0lf/pythem pythem is a multi-purpose penetration testing framework written in Python 2.7, providing an interactive CLI for security researchers. It bu… | 32 | 1248 | maintenance |
| mgeeky/ThreadStackSpoofer A proof-of-concept C++ implementation of thread call stack spoofing, an in-memory evasion technique that hides shellcode references from a … | 23 | 1242 | maintenance |
| AbirHasan2005/ShellPhish A modified (modded) version of the ShellPhish phishing simulation tool that generates fake login pages for popular websites like Facebook, … | 32 | 1241 | maintenance |
| Tylous/SniffAir SniffAir is an open-source wireless security framework for parsing passively collected wireless traffic and launching wireless attacks. It … | 23 | 1240 | maintenance |
| nahamsec/bbht A shell script that installs a curated set of popular bug bounty hunting and reconnaissance tools on an Ubuntu box. It automates setup of t… | 32 | 1239 | maintenance |
| Zerx0r/Kage Kage is an Electron-based graphical user interface for the Metasploit Framework's RPC server, allowing users to manage meterpreter sessions… | 10 | 1235 | maintenance |
| mrknow001/aliyun-accesskey-Tools A Python tool for exploiting leaked Alibaba Cloud (Aliyun) AccessKeys: it enumerates ECS hosts associated with a key and enables remote com… | 23 | 1232 | maintenance |
| dark-player/instabrute.github.io IG-HACK is a bash-based brute-force script that attempts to crack Instagram account passwords using wordlist attacks, designed to run in Te… | 38 | 1227 | maintenance |
| craigz28/firmwalker Firmwalker is a simple bash script that searches extracted or mounted firmware file systems for security-relevant files and content, such a… | 32 | 1225 | maintenance |
| AndroBugs/AndroBugs_Framework AndroBugs Framework is a command-line Android vulnerability scanner that analyzes APK files to find potential security vulnerabilities and … | 10 | 1224 | maintenance |
| dagrz/aws_pwn A collection of Python scripts for penetration testing AWS environments, covering reconnaissance, exploitation, stealth, exploration, and p… | 32 | 1223 | maintenance |
| am0nsec/HellsGate The original C implementation of the Hell's Gate technique, which resolves Windows system call numbers at runtime to invoke NT APIs directl… | 32 | 1220 | maintenance |
| hacktoolspack/hack-tools A curated collection of free hacking and cybersecurity tools covering DoS, information gathering, malware/ransomware generation, and remote… | 23 | 1218 | maintenance |
| nccgroup/redsnarf RedSnarf is a pen-testing/red-teaming tool for retrieving hashes and credentials from Windows workstations, servers, and domain controllers… | 32 | 1216 | maintenance |
| elkokc/reflector Reflector is a Burp Suite extension written in Java that detects reflected XSS vulnerabilities in real time while browsing a target web app… | 23 | 1214 | maintenance |
| iagox86/hash_extender A C command-line tool that automates hash length extension attacks against algorithms like MD4, MD5, SHA-1, SHA-256, SHA-512, RIPEMD-160, a… | 34 | 1211 | maintenance |
| EddieIvan01/iox iox is a Go-based command-line tool for TCP/UDP port forwarding and intranet SOCKS5 proxying, serving as a modern replacement for lcx/ew. I… | 23 | 1209 | maintenance |
| Viralmaniar/Powershell-RAT A Python-based remote access trojan (RAT) for red team engagements that backdoors Windows machines via scheduled tasks and exfiltrates scre… | 23 | 1207 | maintenance |
| LiNuX-Mallu/CAM-DUMPER CAM-DUMPER is a shell-based security testing tool that generates a malicious HTTPS page served via Serveo or Ngrok port forwarding to captu… | 32 | 1203 | maintenance |
| Viralmaniar/I-See-You ISeeYou is a Bash and JavaScript tool that captures a target's exact GPS coordinates (latitude/longitude) during social engineering or phis… | 32 | 1199 | maintenance |
| fofapro/Hosts_scan A small Python tool that brute-force matches IP addresses against domain names by binding Hosts headers, to discover weak or internal syste… | 32 | 1197 | maintenance |
| l3m0n/Bypass_Disable_functions_Shell A PHP webshell that collects various techniques for bypassing PHP's disable_functions restriction to achieve command execution, including L… | 32 | 1193 | maintenance |
| the-xentropy/xencrypt Xencrypt is a single-file PowerShell crypter that encrypts, compresses, and obfuscates PowerShell scripts to bypass AMSI and antivirus dete… | 32 | 1192 | maintenance |
| OWASP/joomscan OWASP JoomScan is an open-source Perl-based vulnerability scanner for Joomla CMS deployments. It enumerates versions, components, and known… | 23 | 1192 | maintenance |
| AlexisAhmed/BugBountyToolkit A multi-platform bug bounty toolkit that bundles popular security and reconnaissance tools (Nmap, Amass, sqlmap, ffuf, etc.) into a pre-con… | 32 | 1189 | maintenance |
| bats3c/DarkLoadLibrary DarkLoadLibrary is a C library implementing an alternative to the Windows LoadLibrary API designed for offensive security operations. It lo… | 32 | 1188 | maintenance |
| DanMcInerney/icebreaker A PowerShell-based penetration testing tool that automates five internal network attacks against Active Directory to obtain plaintext crede… | 32 | 1185 | maintenance |
| Ekultek/BlueKeep A Python proof-of-concept exploit for CVE-2019-0708 (BlueKeep), a pre-authentication remote code execution vulnerability in Microsoft RDP a… | 65 | 1183 | maintenance |
| timwhitez/crawlergo_x_XRAY A Python glue script that combines the crawlergo dynamic crawler with the XRAY passive vulnerability scanner, replaying crawled URLs throug… | 32 | 1182 | maintenance |
| lmammino/jwt-cracker jwt-cracker is a Node.js command-line tool that brute-forces the signing secrets of HS256, HS384, and HS512 JWT tokens. It supports custom … | 23 | 1179 | maintenance |
| BuffaloWill/oxml_xxe A Ruby/Sinatra web tool for embedding XXE/XML exploits into document file formats like DOCX, XLSX, ODT, SVG, and XML. It is used to test XX… | 32 | 1178 | maintenance |
| antonioCoco/RoguePotato RoguePotato is a Windows local privilege escalation tool written in C that elevates from a service account to SYSTEM by abusing the DCOM/NT… | 23 | 1177 | maintenance |
| mttaggart/OffensiveNotion OffensiveNotion is a command-and-control (C2) platform that abuses the Notion notetaking app as its communication channel. It ships a cross… | 10 | 1177 | maintenance |
| dionach/CMSmap CMSmap is a Python open-source CLI scanner that automates detection of security flaws in popular CMSs, integrating common vulnerabilities f… | 32 | 1176 | maintenance |
| Spooks4576/Ghost_ESP Ghost ESP is open-source ESP32 firmware (written in C on ESP-IDF) that turns 45+ ESP32 boards into a wireless security testing platform cov… | 10 | 1175 | maintenance |
| CCob/SharpBlock SharpBlock is a C# command-line tool that blocks EDR (Endpoint Detection and Response) protection DLLs from executing their entry points in… | 32 | 1171 | maintenance |
| Lucifer1993/SatanSword SatanSword is a Python-based red team penetration testing framework that integrates web fingerprinting, PoC-based vulnerability detection, … | 32 | 1171 | maintenance |
| yangyangwithgnu/bypass_disablefunc_via_LD_PRELOAD A small PHP exploit script plus compiled shared object that bypasses PHP's disable_functions restriction to execute OS commands via LD_PREL… | 32 | 1171 | maintenance |
| DarkCoderSc/win-brute-logon A Windows command-line proof-of-concept tool that brute-forces local user account passwords without requiring any privileges, exploiting th… | 32 | 1170 | maintenance |
| n0b0dyCN/redis-rogue-server A Python-driven exploit tool that achieves remote code execution on unpatched Redis servers (<=5.0.5) by loading a malicious Redis module f… | 32 | 1170 | maintenance |
| 4w4k3/BeeLogger BeeLogger is a Python-based penetration testing tool that generates Windows keylogger executables which exfiltrate captured keystrokes via … | 32 | 1169 | maintenance |
| SpiderLabs/HostHunter HostHunter is a Python CLI recon tool that maps IPv4/IPv6 targets to virtual hostnames using OSINT and active reconnaissance techniques suc… | 23 | 1169 | maintenance |
| tongcheng-security-team/NextScan NextScan (飞刃) is an enterprise-grade distributed black-box vulnerability scanning platform built in Go, composed of Server, Agent, and Web … | 21 | 1164 | maintenance |
| chenjj/CORScanner CORScanner is a fast Python tool for detecting CORS misconfiguration vulnerabilities in websites, using gevent for high-concurrency network… | 23 | 1162 | maintenance |
| Ch0pin/AVIator AV|Ator is a GUI backdoor generator that encrypts shellcode with AES and produces Windows executables that decrypt and inject the payload u… | 10 | 1161 | maintenance |
| Lucifer1993/TPscan TPscan is a one-click vulnerability detection tool for ThinkPHP applications, written in Python 3. It scans ThinkPHP-based web services for… | 32 | 1159 | maintenance |
| loseys/BlackMamba BlackMamba is a Python/Qt-based Command and Control (C2) framework for post-exploitation that manages multiple client connections simultane… | 10 | 1158 | maintenance |
| aircrack-ng/rtl8188eus An out-of-tree Linux/Android kernel driver for Realtek RTL8188eus/eu/etv WiFi chipsets, maintained under the Aircrack-ng organization. It a… | 34 | 1157 | maintenance |
| d3ckx1/Fvuln Fvuln (Find-Vulnerability) is an automated security scanning tool for penetration testers and red teams. It combines live IP detection, por… | 23 | 1157 | maintenance |
| deepzec/Bad-Pdf Bad-PDF is a Python tool that generates malicious PDF files exploiting CVE-2018-4993 to steal NTLMv1/NTLMv2 hashes from Windows machines vi… | 44 | 1151 | maintenance |
| Telefonica/Eternalblue-Doublepulsar-Metasploit A Metasploit module that exploits the EternalBlue/DoublePulsar SMB vulnerability in Windows systems. It integrates the leaked NSA exploit i… | 32 | 1151 | maintenance |
| threatexpress/red-team-scripts A collection of red team focused tools, PowerShell scripts, and notes for offensive security engagements, including host and domain enumera… | 32 | 1146 | maintenance |
| uber-common/metta Metta is an information security preparedness tool that runs adversarial simulations to test host-based and network detection instrumentati… | 32 | 1145 | maintenance |
| FuzzySecurity/Sharp-Suite Sharp-Suite is a collection of C# security tooling samples for Windows threat emulation, including techniques like process command-line spo… | 32 | 1144 | maintenance |
| ChrisTheCoolHut/Zeratool Zeratool is an Automatic Exploit Generation (AEG) tool that uses angr to concolically analyze binaries for buffer overflow and format strin… | 23 | 1144 | maintenance |
| leechristensen/SpoolSample SpoolSample is a C# proof-of-concept tool that coerces Windows hosts to authenticate to arbitrary machines via the MS-RPRN Print System Rem… | 32 | 1141 | maintenance |
| christophetd/log4shell-vulnerable-app A deliberately vulnerable Spring Boot web application demonstrating the Log4Shell vulnerability (CVE-2021-44228) using Log4j 2.14.1. It shi… | 32 | 1140 | maintenance |
| chvancooten/follina.py A proof-of-concept Python script that replicates the 'Follina' MS-MSDT Microsoft Office remote code execution vulnerability for local testi… | 32 | 1139 | maintenance |
| Bhaviktutorials/shark Shark is a shell-based phishing toolkit that automates hosting fake login pages with port forwarding via ngrok and Cloudflare tunnels. It i… | 23 | 1137 | maintenance |
| nccgroup/featherduster FeatherDuster is an automated, modular cryptanalysis tool from NCC Group that identifies and exploits weak cryptosystems from supplied ciph… | 23 | 1137 | maintenance |
| JPaulMora/Pyrit Pyrit is a WPA/WPA2-PSK precomputed cracker that builds massive databases of pre-computed Pairwise Master Keys using multi-core CPUs and GP… | 68 | 1134 | maintenance |
| stephenbradshaw/vulnserver Vulnserver is a deliberately vulnerable multithreaded Windows TCP server containing multiple subtly different buffer overflow bugs. It is d… | 32 | 1133 | maintenance |
| med0x2e/GadgetToJScript GadgetToJScript is a C# tool that generates .NET BinaryFormatter serialized gadget payloads embedded in JS/VBS/VBA/HTA scripts, triggering … | 23 | 1133 | maintenance |
| shr3ddersec/Shr3dKit Shr3dKit is a shell script that installs a large curated collection of red team and offensive security tools onto a Kali Linux system (hard… | 32 | 1131 | maintenance |
| r35tart/RW_Password A Python script that filters leaked password dictionaries with regex to extract passwords matching common corporate strength policies (leng… | 32 | 1127 | maintenance |
| mgeeky/ShellcodeFluctuation A C++ proof-of-concept implementing an in-memory evasion technique that encrypts shellcode and fluctuates its memory protection between RW/… | 23 | 1127 | maintenance |
| hausec/ADAPE-Script A PowerShell script that automates Active Directory assessment and privilege escalation checks by bundling multiple well-known pentest modu… | 32 | 1125 | maintenance |
| GreatSCT/GreatSCT GreatSCT is a Python-based framework that generates metasploit payloads designed to bypass antivirus and application whitelisting solutions… | 10 | 1123 | maintenance |
| mdsecactivebreach/o365-attack-toolkit A Go-based red team toolkit for performing OAuth phishing attacks against Office365 accounts. It uses stolen tokens with the Microsoft Grap… | 32 | 1122 | maintenance |
| 1n7erface/Template Template is a heuristic intranet scanning CLI tool built for red team operations, combining host discovery, port scanning, web fingerprinti… | 23 | 1121 | maintenance |
| google/ssl_logger A Python command-line tool that decrypts and logs a running process's SSL/TLS traffic, mimicking Echo Mirage's SSL logging on Linux and mac… | 10 | 1119 | maintenance |
| JoelGMSec/AutoRDPwn AutoRDPwn is a PowerShell post-exploitation framework that automates the RDP Shadow attack on Windows, letting an attacker view or control … | 32 | 1118 | maintenance |