domain: penetration-testing
1317 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| hash3liZer/WiFiBroot WiFiBroot is a Python 2 command-line tool for wireless (WPA/WPA2) penetration testing that captures and cracks 4-way handshakes and PMKID k… | 23 | 1114 | maintenance |
| wireghoul/dotdotpwn DotDotPwn is a flexible directory traversal fuzzer written in Perl that discovers path traversal vulnerabilities in HTTP, FTP, and TFTP ser… | 23 | 1114 | maintenance |
| awake1t/PortBrute A compact cross-platform brute-force tool written in Go that attempts password attacks against FTP, SSH, SMB, MSSQL, MySQL, PostgreSQL, and… | 32 | 1111 | maintenance |
| prateek147/DVIA-v2 Damn Vulnerable iOS App (DVIA-v2) is a deliberately vulnerable iOS application written in Swift for practicing iOS penetration testing. It … | 23 | 1111 | maintenance |
| calebstewart/CVE-2021-1675 A pure PowerShell proof-of-concept exploit for CVE-2021-1675 (PrintNightmare), a Windows Print Spooler local privilege escalation vulnerabi… | 32 | 1109 | maintenance |
| tevora-threat/SharpView SharpView is a C#/.NET port of the PowerView PowerShell script for Active Directory domain enumeration and reconnaissance. It exposes Power… | 32 | 1108 | maintenance |
| curi0usJack/luckystrike LuckyStrike is a PowerShell-based utility for generating malicious Microsoft Office macro documents, intended for penetration testing and e… | 10 | 1108 | maintenance |
| KathanP19/JSFScan.sh JSFScan.sh is a shell script that automates JavaScript reconnaissance for bug bounty hunting. Given a list of subdomains, it gathers JS fil… | 32 | 1107 | maintenance |
| dark-lbp/isf ISF (Industrial Exploitation Framework) is a Python-based exploitation framework modeled after Metasploit, focused on industrial control sy… | 10 | 1105 | maintenance |
| Arrexel/phpbash phpbash is a standalone, semi-interactive web shell written in PHP and packaged as a single file. It is designed to assist penetration test… | 32 | 1102 | maintenance |
| endgameinc/RTA Red Team Automation (RTA) is a Python framework of scripts that emulate malicious tradecraft modeled after the MITRE ATT&CK matrix, letting… | 32 | 1095 | maintenance |
| G4lile0/ESP32-WiFi-Hash-Monster A firmware for M5Stack/ESP32 devices that captures WPA2 EAPOL handshake and PMKID packets over WiFi and stores them on an SD card for later… | 32 | 1095 | maintenance |
| M4sc3r4n0/Evil-Droid Evil-Droid is a shell-based framework that creates, generates, and embeds APK payloads for penetrating Android platforms, built on top of t… | 23 | 1094 | maintenance |
| JackOfMostTrades/gadgetinspector A Java bytecode analyzer that automatically discovers deserialization gadget chains in Java libraries and application classpaths. It produc… | 32 | 1090 | maintenance |
| veracode-research/rogue-jndi Rogue JNDI is a malicious LDAP and HTTP server written in Java for exploiting insecure JNDI API usage in Java applications. It serves vario… | 32 | 1086 | maintenance |
| Accenture/Spartacus Spartacus is a Windows toolkit that automates discovery and exploitation of DLL and COM hijacking vulnerabilities by parsing Process Monito… | 10 | 1085 | maintenance |
| pentestmonkey/unix-privesc-check A single shell script that audits Unix systems for misconfigurations allowing local privilege escalation. It can be uploaded and run direct… | 32 | 1082 | maintenance |
| sysdream/chashell Chashell is a Go-based reverse shell that tunnels communication over DNS, paired with a multi-client control server called chaserv. All tra… | 32 | 1082 | maintenance |
| Leeon123/CC-attack A Python3 command-line tool that performs Layer 7 HTTP/HTTPS flood (CC) attacks through SOCKS4/5 or HTTP proxies, with multithreading, rand… | 23 | 1081 | maintenance |
| dirkjanm/PrivExchange PrivExchange is a set of Python proof-of-concept tools that abuse Exchange Web Services push notifications to relay authentication and esca… | 32 | 1077 | maintenance |
| wireghoul/htshells A collection of self-contained .htaccess files that turn Apache servers into web shells or launch various attacks when uploaded. It include… | 32 | 1076 | maintenance |
| admintony/Prepare-for-AWD A collection of Python and PHP scripts for AWD (Attack with Defense) CTF competitions, including batch attack scripts for planting and trig… | 32 | 1075 | maintenance |
| scrt/avcleaner avcleaner is a C/C++ source-to-source obfuscator built on LLVM, designed to evade antivirus detection by transforming source code (e.g., hi… | 32 | 1073 | maintenance |
| antonioCoco/SharPyShell SharPyShell is a Python tool that generates a tiny, obfuscated ASP.NET webshell for C# web applications on .NET Framework and provides an i… | 23 | 1072 | maintenance |
| c0ny1/jsEncrypter A Burp Suite extension that uses PhantomJS to invoke front-end JavaScript encryption functions on payloads, enabling fuzzing and brute-forc… | 23 | 1069 | maintenance |
| iphelix/dnschef DNSChef is a highly configurable DNS proxy (fake DNS) tool written in Python for penetration testers and malware analysts. It can forge DNS… | 32 | 1068 | maintenance |
| FeeiCN/ESD ESD is a Python-based subdomain enumeration tool that brute-forces and collects subdomains for a given domain. It uses AsyncIO/aioDNS for f… | 10 | 1068 | maintenance |
| ZHacker13/ReverseTCPShell A PowerShell-based ReverseTCP shell framework that provides a command-and-control (C2) server with modules for remote host information gath… | 32 | 1067 | maintenance |
| safebuffer/sam-the-admin A Python CLI exploit tool that chains CVE-2021-42278 and CVE-2021-42287 to impersonate a Domain Admin from a standard Active Directory doma… | 32 | 1067 | maintenance |
| 0xbadjuju/Tokenvator Tokenvator is a C# command-line tool for manipulating Windows tokens to elevate privileges, such as stealing a SYSTEM token from a running … | 23 | 1067 | maintenance |
| raddyfiy/caidao-official-version An archive of the official versions of 'China Chopper' (中国菜刀), a well-known webshell management client, with archived download snapshots an… | 23 | 1063 | maintenance |
| AHXR/ghost Ghost is a lightweight Remote Access Trojan (RAT) written in C++ that gives an attacker silent remote command-line access to Windows machin… | 23 | 1058 | maintenance |
| Abacus-Group-RTO/legion Legion is an open-source, semi-automated network penetration testing framework with a graphical interface, forked from Sparta. It orchestra… | 10 | 1057 | maintenance |
| ptoomey3/evilarc evilarc is a Python CLI tool that creates tar and zip archives containing files with directory traversal characters in their embedded paths… | 32 | 1055 | maintenance |
| a1phaboy/FastjsonScan FastjsonScan is a Go-based command-line scanner that detects Fastjson deserialization vulnerabilities in Java web services. It identifies t… | 23 | 1055 | maintenance |
| noob-hackers/lazybee Lazybee is a Python-based CLI tool for generating random wordlists for brute-force attacks, primarily targeting Termux on Android. It gener… | 32 | 1049 | maintenance |
| samratashok/ADModule A backup of the Microsoft-signed ActiveDirectory PowerShell module (DLL and module files) from Server 2016 with RSAT. It allows enumerating… | 32 | 1047 | maintenance |
| rastating/wordpress-exploit-framework A Ruby framework for penetration testing WordPress installations, providing a console with loadable exploit and payload modules. It is dist… | 10 | 1046 | maintenance |
| OffensivePython/Saddam Saddam is a Python command-line tool that performs DDoS amplification attacks using DNS, NTP, SNMP, and SSDP reflection vectors. It can als… | 32 | 1045 | maintenance |
| thomasxm/BOAZ_beta BOAZ is a multilayered AV/EDR evasion framework written in C++/C with Python linking, designed to generate polymorphic payloads that bypass… | 57 | 1042 | maintenance |
| TryCatchHCF/DumpsterFire DumpsterFire is a modular, menu-driven, cross-platform Python toolset for building repeatable, time-delayed, distributed security events. I… | 23 | 1039 | maintenance |
| rapid7/hackazon Hackazon is a deliberately vulnerable online storefront web application built with PHP, AJAX, and RESTful APIs. It serves as a training and… | 10 | 1038 | maintenance |
| adi0x90/attifyos Attify OS is a Linux distribution based on Ubuntu 18.04 pre-configured with tools for security assessment and penetration testing of IoT de… | 32 | 1037 | maintenance |
| SaadAhla/FilelessPELoader A C++ tool that fetches an AES-encrypted Windows PE executable from a remote location, decrypts it in memory, and executes it without writi… | 31 | 1037 | maintenance |
| rfunix/Pompem Pompem is a Python command-line tool that automates searching for exploits and vulnerabilities across major databases like PacketStorm, CXS… | 23 | 1037 | maintenance |
| marco-lancini/goscan GoScan is an interactive network scanner client written in Go that provides abstraction and automation over nmap, with auto-completion and … | 23 | 1036 | maintenance |
| securing/DumpsterDiver DumpsterDiver is a Python command-line tool that scans large volumes of files for hardcoded secrets such as AWS, Azure, and SSH keys as wel… | 10 | 1036 | maintenance |
| yassineaboukir/sublert Sublert is a Python CLI security and reconnaissance tool that uses certificate transparency logs to monitor new subdomains issued TLS/SSL c… | 32 | 1034 | maintenance |
| averagesecurityguy/scripts A collection of Python scripts written for use during penetration testing engagements, organized into categories like brute forcing, enumer… | 32 | 1033 | maintenance |
| Tylous/ZipExec ZipExec is a Go-based proof-of-concept tool that wraps binaries into a password-protected zip file, base64 encodes it into a JScript loader… | 32 | 1032 | maintenance |
| WithSecureLabs/doublepulsar-detection-script A Python 2 script that sweeps networks to detect Windows systems compromised with the DOUBLEPULSAR implant (SMB and RDP variants) released … | 32 | 1030 | maintenance |
| luantak/ToRat ToRat is a cross-platform remote administration tool written in Go that uses the Tor network as its transport mechanism and RPC for communi… | 10 | 1030 | maintenance |
| admintony/svnExploit SvnExploit is a Python CLI tool that exploits SVN source code disclosure vulnerabilities, supporting both SVN <1.7 and >1.7 repository form… | 32 | 1029 | maintenance |
| Ridter/noPac A Python CLI exploit tool that chains CVE-2021-42278 and CVE-2021-42287 to escalate from a standard Active Directory domain user to Domain … | 32 | 1021 | maintenance |
| b4rtik/SharpKatz SharpKatz is a C# port of mimikatz's credential extraction commands, including sekurlsa::logonpasswords, sekurlsa::ekeys, and lsadump::dcsy… | 32 | 1021 | maintenance |
| ryhanson/phishery Phishery is an SSL-enabled HTTP server written in Go that harvests credentials via Basic Authentication prompts, plus a tool to inject phis… | 23 | 1020 | maintenance |
| fO-000/bluing Bluing is a Python-based Bluetooth intelligence gathering tool (successor to bluescan) for scanning and probing Bluetooth Classic (BR/EDR) … | 23 | 1019 | maintenance |
| ReversecLabs/awspx awspx is a graph-based security tool that visualizes effective access and resource relationships in AWS environments. It resolves IAM polic… | 23 | 1018 | maintenance |
| mdsecactivebreach/CACTUSTORCH CACTUSTORCH is a payload generation tool that produces JavaScript, VBScript, and VBA shellcode launchers for adversary simulations. It spaw… | 32 | 1017 | maintenance |
| maaaaz/impacket-examples-windows A repository of pre-compiled Windows binaries of the Impacket example scripts, a collection of network protocol tools for security testing.… | 23 | 1017 | maintenance |
| bit4woo/teemo Teemo is a Python command-line reconnaissance tool that collects domains, subdomains, and email addresses for a target organization. It agg… | 32 | 1016 | maintenance |
| quentinhardy/msdat MSDAT is an open-source Python penetration testing tool for remotely testing the security of Microsoft SQL Server databases. It supports cr… | 32 | 1016 | maintenance |
| secretsquirrel/BDFProxy BDFProxy is a man-in-the-middle proxy that patches downloaded binaries on the fly by embedding payloads, combining the Backdoor Factory wit… | 32 | 1015 | maintenance |
| b3-v3r/Hunner Hunner is a Python-based hacking framework for penetration testing that combines vulnerability scanning (SQL injection, XSS), denial-of-sit… | 32 | 1012 | maintenance |
| c0ny1/java-memshell-scanner A JSP-based scanner that detects and helps remove Java web memory shells (memshells) such as Filter, Servlet, and Listener types in middlew… | 32 | 1012 | maintenance |
| s7ckTeam/Glass Glass is a Python CLI tool for rapid fingerprint identification of asset lists, querying Fofa, ZoomEye, Shodan, and 360 Quake APIs to gathe… | 32 | 1010 | maintenance |
| feihong-cs/Java-Rce-Echo A collection of Java test code for achieving command output echo after remote code execution (RCE) across common application servers and pl… | 32 | 1008 | maintenance |
| TideSec/FuzzScanner FuzzScanner is a Ruby/Python-based reconnaissance toolset that batch-collects information about target websites, including subdomains, open… | 32 | 1008 | maintenance |
| hackerxphantom/HACK-CAMERA A Bash-based penetration-testing tool that hosts a phishing page which requests camera access and captures webcam shots from targets who op… | 23 | 1008 | maintenance |
| stormshadow07/HackTheWorld A Python CLI script that generates Windows payloads designed to evade antivirus detection, integrating with Metasploit and mingw-w64 for co… | 32 | 1005 | maintenance |
| maaaaz/thc-hydra-windows A Windows-compiled distribution of THC-HYDRA, the popular network login brute-forcing tool, bundled with Cygwin DLLs and optional SSH, MySQ… | 23 | 1004 | maintenance |
| Armur-Ai/Pentest-Swarm-AI An open-source autonomous penetration testing application that orchestrates a swarm of AI agents (recon, classification, exploitation, repo… | 75 | 2381 | experimental |
| s0md3v/Striker Striker is a Python-based offensive reconnaissance and vulnerability scanning suite that discovers subdomains, scans common ports, detects … | 23 | 2341 | experimental |
| m4ll0k/BBTz A collection of bug bounty tools and example scripts written in Python by security researcher m4ll0k. It serves as a set of ideas and refer… | 32 | 1909 | experimental |
| TarlogicSecurity/BlueSpy BlueSpy is a Python proof-of-concept tool that records and replays audio from vulnerable Bluetooth devices by exploiting pairing without us… | 61 | 1612 | experimental |
| faizann24/wifi-bruteforcer-fsecurify An Android application that attempts to brute force WiFi passwords without requiring a rooted device. It is written in Java and distributed… | 32 | 1486 | experimental |
| achuna33/MYExploit MYExploit is a Java-based one-click scanning and exploitation tool targeting OA (office automation) enterprise products, built as an extens… | 23 | 1485 | experimental |
| chompie1337/SMBGhost_RCE_PoC A Python proof-of-concept exploit for CVE-2020-0796 (SMBGhost), achieving pre-authentication remote code execution against vulnerable Windo… | 32 | 1395 | experimental |
| lem0nSec/ShellGhost ShellGhost is a proof-of-concept memory-based evasion technique written in C that keeps shellcode invisible in memory from process start to… | 29 | 1200 | experimental |
| blackhillsinfosec/WifiForge WifiForge is a Python-based training framework from Black Hills InfoSec that simulates Wi-Fi networks using mininet-wifi so pentesters can … | 70 | 1184 | experimental |
| NytroRST/ShellcodeCompiler A C++ command-line compiler that converts a simplified C/C++-style source language into small, position-independent, NULL-free shellcode fo… | 32 | 1160 | experimental |
| berylliumsec/nebula Nebula is an AI-powered penetration testing desktop application that combines a terminal, browser, notes, findings, and reporting into one … | 92 | 1097 | experimental |
| koutto/jok3r Jok3r is a Python3 CLI framework that automates network and web black-box penetration testing by chaining 50+ open-source security tools. I… | 32 | 1087 | experimental |
| ZeroMemoryEx/Terminator Terminator is a C++ proof-of-concept tool that terminates EDR/XDR/antivirus processes on Windows by abusing the vulnerable, signed zam64.sy… | 20 | 1061 | experimental |
| hackerxphantom/Facebook_hack A Python command-line tool that performs brute-force password attacks against Facebook accounts using an email or profile ID as the target,… | 10 | 1038 | experimental |
| fikrado/fikrado.py A Python 2.7 command-line script that attempts to gain access to Facebook accounts via the Facebook API using brute-force techniques. It ta… | 23 | 1035 | experimental |
| DragoQCC/CrucibleC2 HardHat C2 (CrucibleC2) is a cross-platform, multi-user Command & Control framework written in C#/.NET for red team engagements and penetra… | 22 | 1024 | experimental |
| PowerShellMafia/PowerSploit PowerSploit is a collection of PowerShell modules for post-exploitation tasks during penetration tests, covering code execution, persistenc… | 10 | 13085 | abandoned |
| aliasrobotics/cai Cybersecurity AI (CAI) is an open-source Python framework of specialized AI agents for offensive security tasks such as penetration testing… | 10 | 9810 | abandoned |
| byt3bl33d3r/CrackMapExec CrackMapExec is a Python-based command-line swiss army knife for pentesting Windows and Active Directory networks, supporting protocols lik… | 10 | 9159 | abandoned |
| EmpireProject/Empire Empire is a post-exploitation framework with a pure PowerShell Windows agent and a pure Python Linux/OS X agent, offering encrypted communi… | 10 | 7863 | abandoned |
| zhzyker/exphub Exphub is a collection of standalone Python, Java, PHP, and shell exploit scripts for known CVE vulnerabilities in products like Weblogic, … | 32 | 4291 | abandoned |
| Greenwolf/social_mapper Social Mapper is a Python 3 OSINT tool that enumerates and correlates social media profiles across sites like LinkedIn, Facebook, Twitter, … | 32 | 4073 | abandoned |
| Arachni/arachni Arachni is a modular, high-performance Ruby framework for scanning web applications for security vulnerabilities, including XSS and SQL inj… | 10 | 4039 | abandoned |
| offensive-security/kali-nethunter Kali NetHunter is an Android ROM overlay providing a mobile penetration testing platform, combining a custom kernel, a Kali Linux chroot, a… | 10 | 3806 | abandoned |
| cSploit/android cSploit is an open-source Android network analysis and penetration testing suite for rooted devices, integrating Metasploit RPC, MITM attac… | 23 | 3648 | abandoned |
| byt3bl33d3r/MITMf MITMf is a Python framework for performing Man-In-The-Middle and network attacks, featuring built-in SMB, HTTP, and DNS servers, an SSLStri… | 10 | 3645 | abandoned |
| Proxmark/proxmark3 The official (now archived) client software, FPGA logic, and design documentation for the Proxmark3, a general-purpose RFID tool that can s… | 50 | 3534 | abandoned |
| FeeiCN/Cobra Cobra is a source code security audit (SAST) tool that scans PHP, Java, and other languages for common vulnerabilities like SQL injection, … | 10 | 3186 | abandoned |
| NewEraCracker/LOIC LOIC (Low Orbit Ion Cannon) is an open-source network stress testing tool written in C#, based on Praetox's original LOIC. It supports TCP/… | 10 | 2967 | abandoned |