domain: penetration-testing
1317 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| optiv/ScareCrow ScareCrow is a Go-based payload creation framework designed to bypass EDR (Endpoint Detection and Response) and application whitelisting co… | 10 | 2890 | abandoned |
| DanMcInerney/LANs.py A Python-based penetration testing tool that scans WiFi networks for active clients, performs targeted ARP spoofing, and intercepts or inje… | 32 | 2630 | abandoned |
| CrimsonForge-io/king-phisher King Phisher is a phishing campaign toolkit for testing and promoting user awareness by simulating real-world phishing attacks, with contro… | 66 | 2583 | abandoned |
| WiFi-Pumpkin WiFi-Pumpkin is a Python framework for auditing Wi-Fi security by creating rogue wireless access points and performing man-in-the-middle at… | 23 | 2497 | abandoned |
| evilsocket/bettercap bettercap is a network attack and reconnaissance framework, described as a Swiss Army knife for WiFi, BLE, HID hijacking, CAN-bus, and IPv4… | 10 | 2490 | abandoned |
| Marten4n6/EvilOSX EvilOSX is a Remote Administration Tool (RAT) for macOS/OS X written in pure Python, with a server providing both GUI and CLI interfaces an… | 32 | 2415 | abandoned |
| jaeles-project/jaeles Jaeles is a Go-based framework for building and running automated web application vulnerability scanners using customizable YAML signatures… | 62 | 2370 | abandoned |
| codebutler/firesheep Firesheep is a Firefox extension that demonstrates HTTP session hijacking attacks by sniffing unencrypted Wi-Fi traffic and capturing sessi… | 32 | 2352 | abandoned |
| aress31/burpgpt burpgpt is a Burp Suite extension that sends HTTP traffic to OpenAI GPT models for AI-driven passive vulnerability scanning and traffic ana… | 30 | 2351 | abandoned |
| praetorian-inc/noseyparker Nosey Parker is a Rust-based command-line secrets scanner that finds credentials and sensitive information in files, directories, GitHub, a… | 10 | 2341 | abandoned |
| sevagas/macro_pack macro_pack is a Python CLI tool that automates obfuscation and generation of MS Office documents, VBA/VBS scripts, shortcuts, and other for… | 10 | 2307 | abandoned |
| secgroundzero/warberry WarBerryPi is a tactical exploitation toolkit built to run on a Raspberry Pi, acting as a drop-box/implant for red-team engagements to scan… | 32 | 2220 | abandoned |
| PowerShellEmpire/PowerTools PowerTools is a collection of PowerShell projects focused on offensive security operations, including tools like PowerView, PowerUp, PowerP… | 23 | 2204 | abandoned |
| AdrMXR/KitHack KitHack is a Python-based framework that automates downloading and installing a curated pack of penetration testing tools, organized into c… | 26 | 2085 | abandoned |
| yahoo/gryffin Gryffin is a large-scale web security scanning platform written in Go, built on a publisher-subscriber architecture for horizontal scaling.… | 10 | 2052 | abandoned |
| rasta-mouse/Sherlock Sherlock is a PowerShell script that identifies missing software patches for known Windows local privilege escalation vulnerabilities. It i… | 10 | 2020 | abandoned |
| Fadi002/unshackle Unshackle is a bootable Linux-based ISO that resets or bypasses Windows and Linux user login passwords from a USB drive. It works offline b… | 10 | 1981 | abandoned |
| feihong-cs/ShiroExploit-Deprecated A Java-based one-click exploitation tool for Apache Shiro vulnerabilities Shiro550 (hardcoded key) and Shiro721 (Padding Oracle), supportin… | 23 | 1956 | abandoned |
| Veil-Framework/Veil-Evasion Veil-Evasion is a Python tool that generates Metasploit payloads designed to bypass common antivirus solutions, optionally compiling them i… | 10 | 1840 | abandoned |
| samyk/skyjack SkyJack is a drone hacking tool that autonomously seeks out, disconnects the owner of, and takes wireless control of nearby Parrot AR.Drone… | 32 | 1831 | abandoned |
| govolution/avet AVET (AntiVirus Evasion Tool) is a shell-based toolbox for pentesters to build Windows executables that evade antivirus detection, using te… | 40 | 1755 | abandoned |
| xdavidhu/mitmAP A Python program that creates a fake wireless access point and performs man-in-the-middle data sniffing using tools like SSLstrip2, mitmpro… | 10 | 1695 | abandoned |
| DesignativeDave/androrat Androrat is a client/server Remote Administration Tool for Android devices, with the client written in Java Android and the server in Java/… | 32 | 1634 | abandoned |
| carmaa/inception Inception is a Python-based physical memory manipulation tool that exploits PCI-based DMA (over FireWire, Thunderbolt, ExpressCard, PC Card… | 34 | 1602 | abandoned |
| chinoogawa/fbht A Python 2 command-line tool for interacting with and scraping Facebook accounts, including graph-based analysis of social connections. It … | 23 | 1591 | abandoned |
| byt3bl33d3r/SprayingToolkit A set of Python 3 scripts for performing fast password spraying attacks against Lync/Skype for Business, OWA, IMAP, and Office 365, built o… | 10 | 1576 | abandoned |
| SofianeHamlaoui/Lockdoor-Framework Lockdoor Framework is a Python-based penetration testing framework that bundles a curated selection of security tools (information gatherin… | 34 | 1549 | abandoned |
| ring04h/wydomain wydomain is a Python command-line tool for discovering subdomains of a target domain. It combines dictionary-based DNS bruteforcing with qu… | 32 | 1479 | abandoned |
| D4Vinci/Dr0p1t-Framework Dr0p1t-Framework is a Python-based penetration testing framework that generates stealthy Windows dropper executables designed to bypass ant… | 10 | 1473 | abandoned |
| jseidl/GoldenEye GoldenEye is a Python 3 command-line tool for testing HTTP servers against Layer 7 denial-of-service attacks using the HTTP KeepAlive + NoC… | 10 | 1468 | abandoned |
| OpenRCE/sulley Sulley is a pure-Python fuzzing engine and framework for automated, unattended fuzz testing of network protocols and targets. It handles da… | 23 | 1450 | abandoned |
| Lucifer1993/AngelSword AngelSword is a simple CMS vulnerability detection framework written in Python3, designed to help security engineers quickly discover known… | 32 | 1441 | abandoned |
| dark-kingA/superSearchPlus superSearchPlus is a Chrome browser extension that aggregates information gathering for white-hat hackers, integrating common asset mapping… | 32 | 1436 | abandoned |
| ReversecLabs/needle Needle is an open-source, modular Python framework for streamlining security assessments of iOS applications, covering areas like data stor… | 10 | 1401 | abandoned |
| hahwul/XSpear XSpear is a Ruby-based XSS (cross-site scripting) scanner and parameter analysis tool distributed as a gem, usable both as a CLI and as a R… | 10 | 1364 | abandoned |
| byt3bl33d3r/gcat Gcat is a proof-of-concept Python backdoor that uses a Gmail account as its command-and-control channel, with an implant deployed on target… | 10 | 1351 | abandoned |
| WWILLV/GodOfHacker GodOfHacker is a satirical C# 'hacker all-in-one tool' whose feature list is intentionally absurd (one-click 0day attacks, stealing QQ acco… | 23 | 1340 | abandoned |
| hackappcom/ibrute A Python proof-of-concept tool that brute-forces AppleID passwords via the Find My iPhone service API, which lacked bruteforce protection. … | 32 | 1322 | abandoned |
| clymb3r/PowerShell A collection of useful PowerShell scripts, most notably security and penetration testing tools that were contributed to PowerSploit. The re… | 32 | 1284 | abandoned |
| cisagov/log4j-scanner A CISA-derived scanner for detecting web services vulnerable to the Log4Shell remote code execution vulnerabilities (CVE-2021-44228 and CVE… | 10 | 1278 | abandoned |
| uknowsec/SharpDecryptPwd SharpDecryptPwd is a Windows command-line tool that decrypts passwords saved locally by popular applications such as Navicat, TeamViewer, F… | 32 | 1270 | abandoned |
| samyk/usbdriveby USBdriveby is an Arduino/Teensy microcontroller project that emulates a USB HID keyboard and mouse to covertly install a backdoor, evade fi… | 32 | 1263 | abandoned |
| LOoLzeC/ASU ASU is a Python-based Facebook hacking toolkit offering account checking and spamming features, distributed via a Termux/Linux install scri… | 32 | 1251 | abandoned |
| vaycore/OneScan OneScan is a BurpSuite extension written in Java for recursive directory scanning, helping discover hidden vulnerabilities in deeper direct… | 10 | 1251 | abandoned |
| optiv/Mangle Mangle is a Go-based CLI tool that manipulates compiled Windows executables (.exe and DLL) to evade EDR detection. It strips known indicato… | 10 | 1235 | abandoned |
| Ha3MrX/Gemail-Hack A Python command-line script that performs brute-force password attacks against Gmail accounts. It is a simple educational/offensive-securi… | 66 | 1231 | abandoned |
| the-robot/sqliv SQLiv is a Python command-line tool that scans websites for SQL injection vulnerabilities. It supports dork-based scanning via search engin… | 10 | 1229 | abandoned |
| DeimosC2/DeimosC2 DeimosC2 is a Golang-based command and control (C2) framework for post-exploitation, supporting TCP, HTTPS, DoH, and QUIC agent communicati… | 30 | 1160 | abandoned |
| ring04h/weakfilescan A Python-based multi-threaded sensitive information leakage detection tool that crawls a target site, dynamically builds dictionary rules f… | 32 | 1138 | abandoned |
| NYAN-x-CAT/Lime-RAT LimeRAT is a remote administration tool (RAT) for Windows written in Visual Basic .NET, providing remote desktop, file management, keyloggi… | 10 | 1134 | abandoned |
| vesche/scanless A Python CLI utility and library that scrapes online port scanning websites to perform port scans on a target IP or domain on your behalf. … | 10 | 1121 | abandoned |
| BuffaloWill/Serpico Serpico is a self-hosted web application for writing and collaborating on penetration testing reports. Users assemble findings from a share… | 10 | 1115 | abandoned |
| sensepost/mana MANA is a toolkit for rogue access point (evilAP) attacks, implementing improved KARMA attacks via a modified hostapd plus MitM configurati… | 23 | 1110 | abandoned |
| evilsocket/bleah A deprecated command-line tool for scanning and enumerating Bluetooth Low Energy (BLE) devices. It has been ported into bettercap's BLE mod… | 10 | 1094 | abandoned |
| arnaucube/coffeeMiner CoffeeMiner is a Python tool that performs a man-in-the-middle attack on a WiFi/LAN network, injecting a JavaScript cryptocurrency miner in… | 32 | 1077 | abandoned |
| ekkoo-z/Z-Godzilla_ekp A modified (second-development) fork of the Godzilla webshell management tool, customized to evade network traffic detection devices and an… | 42 | 1075 | abandoned |
| 1n7erface/PocList A Java-based collection of proof-of-concept (PoC) tools for verifying and exploiting known vulnerabilities in products like Nacos, WebLogic… | 32 | 1075 | abandoned |
| WyAtu/Perun Perun is a Python-based network asset vulnerability scanner and scanning framework designed for penetration testers and red teams, primaril… | 32 | 1051 | abandoned |
| Netflix-Skunkworks/sleepy-puppy Sleepy Puppy is a cross-site scripting (XSS) payload management framework from Netflix Skunkworks that captures, manages, and tracks XSS pa… | 32 | 1044 | abandoned |
| M4cs/BabySploit BabySploit is a beginner-friendly penetration testing toolkit and framework written in Python, designed to ease newcomers into using more c… | 23 | 1042 | abandoned |
| utkusen/leviathan Leviathan is a Python-based mass audit toolkit that combines masscan, ncrack, and DSSS to discover services, brute-force credentials, detec… | 10 | 1041 | abandoned |
| denandz/KeeFarce KeeFarce is a security tool that extracts passwords and other cleartext data from a running KeePass 2.x process by injecting a DLL into its… | 32 | 1029 | abandoned |
| ba0gu0/520apkhook A Java-based tool that attaches an Android remote-access APK payload to a legitimate app, producing a trojanized APK where the original app… | 32 | 1015 | abandoned |
| qwqdanchun/DcRat DcRat is an open-source remote administration tool (RAT) written in C# for Windows, providing remote desktop, file management, and remote c… | 10 | 1011 | abandoned |
| rhaidiz/broxy Broxy is an open-source HTTP/HTTPS intercepting proxy written in Go, built on goproxy with a Qt5-based GUI. It offers an interceptor, filte… | 23 | 1008 | abandoned |
| mitmproxy/mitmproxy mitmproxy is an interactive, SSL/TLS-capable intercepting proxy for HTTP/1, HTTP/2, HTTP/3, and WebSockets, offered as a console tool (mitm… | 89 | 44820 | stable |
| secdev/scapy Scapy is a powerful Python-based interactive packet manipulation program and library that can forge, decode, send, capture, and match packe… | 75 | 12501 | stable |
| firerpa/lamda FIRERPA (lamda) is an all-in-one Android device control platform whose server runs directly on the device (root or non-root) and exposes 16… | 98 | 8243 | active |
| EmenstaNougat/ESP32-BlueJammer ESP32-BlueJammer is firmware for an ESP32 paired with nRF24 modules that disrupts 2.4GHz communications (Bluetooth, BLE, WiFi, RC) by flood… | 50 | 7822 | active |
| Tencent/AI-Infra-Guard Tencent's full-stack AI red teaming platform that scans AI infrastructure, agents, MCP servers, and skills for vulnerabilities and evaluate… | 88 | 5984 | active |
| aidlearning/AidLearning-FrameWork AidLux (originally AidLearning) is an AIoT development platform that runs a native Ubuntu Linux environment with GUI, deep learning tooling… | 70 | 5797 | active |
| sensity-ai/dot dot (Deepfake Offensive Toolkit) is a Python tool that generates real-time, controllable deepfakes from a webcam feed and injects them into… | 23 | 4586 | active |
| microsoft/PyRIT PyRIT is Microsoft's open-source Python framework for identifying security and safety risks in generative AI systems. It provides automatio… | 88 | 4361 | active |
| google/tamperchrome Tamper Dev is a browser extension that intercepts and edits HTTP/HTTPS requests and responses in real time without requiring a proxy or aux… | 54 | 4218 | active |
| ivre/ivre IVRE is an open-source network recon framework written in Python that collects, stores, and analyzes network intelligence from active scann… | 66 | 4119 | active |
| nabla-c0d3/sslyze SSLyze is a fast SSL/TLS scanning tool and Python library that analyzes a server's TLS configuration, including certificates, cipher suites… | 83 | 3775 | stable |
| edoardottt/cariddi Cariddi is a fast command-line web crawler written in Go that takes a list of domains, crawls URLs, and scans for endpoints, secrets, API k… | 84 | 3753 | active |
| e-m-b-a/emba EMBA is an open-source firmware security analyzer for embedded Linux devices, written in Bash. It automates firmware extraction, static and… | 93 | 3614 | active |
| google/honggfuzz Honggfuzz is a security-oriented, feedback-driven evolutionary fuzzer that uses software and hardware code coverage to discover bugs in bin… | 62 | 3376 | active |
| techgaun/github-dorks A Python CLI tool that automates GitHub code searches using a curated list of dorks to find leaked secrets like credentials, private keys, … | 43 | 3271 | active |
| m0bilesecurity/RMS-Runtime-Mobile-Security Runtime Mobile Security (RMS) is a NodeJS-powered web interface built on FRIDA for manipulating Android and iOS apps at runtime. It lets us… | 83 | 3075 | active |
| Qianlitp/crawlergo crawlergo is a Go-based browser crawler that uses headless Chrome to discover URLs for web vulnerability scanners. It renders pages, fills … | 27 | 3034 | active |
| protectai/vulnhuntr Vulnhuntr is a Python CLI tool that uses large language models combined with static code analysis to autonomously discover exploitable vuln… | 24 | 2747 | active |
| dirkjanm/ROADtools ROADtools is a Python framework for interacting with Azure AD/Entra ID, comprising the roadlib authentication library, the ROADrecon explor… | 75 | 2704 | active |
| musana/CF-Hero CF-Hero is a Go-based reconnaissance CLI tool that discovers the real origin IP addresses of Cloudflare-protected web applications. It aggr… | 66 | 2632 | active |
| confident-ai/deepteam DeepTeam is an open-source Python framework for red teaming LLM systems, AI agents, RAG pipelines, and chatbots. It simulates adversarial a… | 67 | 2623 | active |
| NVISOsecurity/AlwaysTrustUserCerts A Magisk/KernelSU module that automatically copies user-installed certificates into the Android system root CA store. It enables TLS traffi… | 47 | 2549 | active |
| quasar/Quasar Quasar is a free, open-source remote administration tool (RAT) for Windows written in C#, offering remote desktop, shell, file management, … | 10 | 9908 | maintenance |
| SafeGroceryStore/MDUT MDUT is a cross-platform desktop application for managing and exploiting multiple databases (MySQL, MSSQL, PostgreSQL, Oracle, Redis) built… | 95 | 2262 | active |
| Trail of Bits Claude Code Config A Claude Code plugin marketplace from Trail of Bits offering skills for AI-assisted security analysis, code auditing, and vulnerability det… | 60 | 2079 | active |
| Kritt-ai/open-kritt open·kritt is an open-source, self-hosted AI vulnerability research platform that decomposes a codebase into focused security tasks, runs A… | 79 | 2011 | active |
| Fr4nkFletcher/ESP32-Marauder-Cheap-Yellow-Display A port of the ESP32-Marauder WiFi/Bluetooth testing firmware to the Cheap Yellow Display (CYD) family of ESP32 boards with ILI9341/ST7789/S… | 47 | 1734 | active |
| Gerenios/AADInternals AADInternals is a PowerShell module for administering and hacking Entra ID (Azure AD), Office 365, and related endpoints. It includes tools… | 52 | 1683 | active |
| attify/firmware-analysis-toolkit Firmware Analysis Toolkit (FAT) is a Python-based automation wrapper around Firmadyne that emulates IoT and embedded device firmware images… | 23 | 1582 | active |
| newaetech/chipwhisperer ChipWhisperer is an open-source toolchain for hardware security research, providing capture hardware designs, FPGA/USB firmware, and a Pyth… | 79 | 1557 | active |
| tillson/git-hound GitHound is a Go-based CLI tool that hunts for exposed API keys, secrets, and credentials across all of GitHub using GitHub dorks, pattern … | 70 | 1451 | active |
| ChiChou/grapefruit Grapefruit is an open-source mobile security testing suite for iOS and Android that provides a browser-based GUI over Frida for runtime ins… | 91 | 1379 | active |
| yeswehack/PwnFox PwnFox is a Firefox extension paired with a Burp Suite extension that provides tools for web security audits, such as one-click Burp proxy … | 23 | 1339 | active |
| JailbrokenAI/wallbreaker Wallbreaker is a Claude-Code-style terminal harness for red-teaming LLMs, driving an autonomous agent loop that runs jailbreak attacks (PAI… | 57 | 1310 | active |
| dwisiswant0/go-dork go-dork is a fast command-line dork scanner written in Go that automates Google dorking across multiple search engines. It supports Google,… | 23 | 1301 | stable |