domain: penetration-testing
1317 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| FluxionNetwork/fluxion Fluxion is a security auditing and social-engineering research tool that retrieves WPA/WPA2 keys via phishing attacks using rogue access po… | 91 | 5907 | active |
| lanmaster53/recon-ng Recon-ng is a full-featured, modular reconnaissance framework for conducting web-based open source intelligence (OSINT) gathering. It offer… | 32 | 5871 | active |
| RedSiege/EyeWitness EyeWitness is a Python CLI tool that takes screenshots of websites using headless Chromium, captures server header information, and identif… | 50 | 5829 | active |
| commixproject/commix Commix (short for command injection exploiter) is an open-source penetration testing tool that automates the detection and exploitation of … | 75 | 5824 | active |
| Pennyw0rth/NetExec NetExec (nxc) is a community-maintained, open-source network execution tool and successor to CrackMapExec, used for pentesting and red-team… | 74 | 5815 | active |
| elder-plinius/T3MP3ST T3MP3ST is a multi-agent offensive-security framework that turns existing AI coding agents (Claude Code, Codex, Ollama, etc.) into autonomo… | 58 | 5684 | active |
| trustedsec/ptf The PenTesters Framework (PTF) is a Python-based modular framework that installs, compiles, and keeps penetration testing tools up to date … | 32 | 5558 | active |
| OWASP/Nettacker OWASP Nettacker is a Python-based automated penetration testing and information-gathering framework for reconnaissance, vulnerability scann… | 88 | 5535 | active |
| Hackplayers/evil-winrm Evil-WinRM is a Ruby-based command-line WinRM shell designed for hacking and penetration testing of Windows servers. It supports features l… | 79 | 5448 | active |
| drk1wi/Modlishka Modlishka is an open-source penetration testing tool written in Go that acts as a transparent man-in-the-middle reverse proxy. It can proxy… | 66 | 5407 | active |
| PurpleAILAB/Decepticon Decepticon is an autonomous AI red-team hacking agent that uses LLMs (built on LangChain/LangGraph) to plan and execute context-aware offen… | 80 | 5335 | active |
| Ladon Ladon is a large-scale internal network penetration scanner written in C#, offering port scanning, service identification, network asset di… | 29 | 5320 | active |
| RhinoSecurityLabs/pacu Pacu is an open-source AWS exploitation framework for offensive security testing of Amazon Web Services environments. It provides a modular… | 73 | 5312 | active |
| FunnyWolf/Viper VIPER is a self-hosted red teaming and adversary simulation platform with a web UI, 100+ post-exploitation modules covering MITRE ATT&CK, a… | 85 | 5279 | active |
| hahwul/dalfox Dalfox is an open-source XSS vulnerability scanner written in Rust that automates discovery, injection, and DOM/AST-level verification of r… | 98 | 5256 | active |
| Ullaakut/cameradar Cameradar is a Go-based command-line tool that scans targets for open RTSP video surveillance endpoints and uses dictionary attacks to disc… | 94 | 5173 | active |
| GhostPack/Rubeus Rubeus is a C# command-line toolset for raw Kerberos interaction and abuse on Windows, adapted from Kekeo and MakeMeEnterpriseAdmin. It sup… | 60 | 5145 | active |
| hakluke/hakrawler Hakrawler is a fast command-line web crawler written in Go, built on the Gocolly library, that discovers URLs and JavaScript file locations… | 66 | 5116 | active |
| techchipnet/CamPhish CamPhish is a bash-based penetration-testing tool that hosts a fake webpage on a built-in PHP server and exposes it via ngrok or CloudFlare… | 40 | 5020 | active |
| bitsadmin/wesng WES-NG is a Python command-line tool that parses Windows `systeminfo` output (or missing KB listings) and cross-references it against a reg… | 76 | 4923 | active |
| nicocha30/ligolo-ng Ligolo-ng is a tunneling and pivoting tool written in Go that establishes tunnels over reverse TCP/TLS connections using a TUN interface in… | 98 | 4893 | active |
| UndeadSec/SocialFish SocialFish is a Python-based phishing toolkit that clones modern login pages using Playwright browser automation and captures credentials, … | 76 | 4851 | active |
| cdk-team/CDK CDK is a zero-dependency container penetration toolkit written in Go for security testing of Kubernetes, Docker, and Containerd environment… | 70 | 4740 | active |
| its-a-feature/Mythic Mythic is a collaborative, multi-platform post-exploitation red teaming framework built with Go, Docker, and a web browser UI. It provides … | 78 | 4725 | active |
| AntSwordProject/antSword AntSword is a cross-platform, open-source website administration toolkit built with Electron, designed for penetration testers, security re… | 73 | 4693 | active |
| TheWover/donut Donut is a shellcode generator that converts VBScript, JScript, EXE, DLL files, and .NET assemblies into x86, x64, or AMD64+x86 position-in… | 36 | 4689 | stable |
| GhostPack/Seatbelt Seatbelt is a C# command-line tool that performs security-oriented host-survey 'safety checks' on Windows systems. It enumerates system and… | 32 | 4683 | active |
| ReversecLabs/drozer drozer is an open-source security assessment framework for Android that lets testers assume the role of an app and interact with the Androi… | 57 | 4597 | active |
| projectdiscovery/interactsh Interactsh is an open-source tool for detecting out-of-band (OOB) interactions via DNS, HTTP(S), SMTP(S), and LDAP, useful for identifying … | 85 | 4512 | active |
| samsesh/SocialBox-Termux SocialBox-Termux is a shell-based brute-force attack framework targeting social media and email services like Facebook, Gmail, Instagram, a… | 72 | 4497 | active |
| Awarexone/Agentic-Bug-Hunter An AI-powered bug bounty hunting toolkit that automates reconnaissance, vulnerability testing, finding validation, and report generation fo… | 77 | 4464 | active |
| BeichenDream/Godzilla Godzilla is a Java-based webshell management tool supporting dynamic payloads for JSP, ASPX, and PHP targets with multiple AES/XOR encrypto… | 23 | 4455 | active |
| t3l3machus/Villain Villain is a high-level stage 0/1 command-and-control (C2) framework written in Python that handles multiple reverse TCP and HoaxShell-base… | 40 | 4439 | active |
| GerbenJavado/LinkFinder LinkFinder is a Python CLI script that discovers endpoints and their parameters in JavaScript files using jsbeautifier and regular expressi… | 32 | 4439 | stable |
| zan8in/afrog afrog is an open-source security tool written in Go for vulnerability scanning using PoC (Proof of Concept) rules. It is designed for bug b… | 96 | 4372 | active |
| overspace-labs/HaE HaE (Highlighter and Extractor) is a framework-style cybersecurity project for fine-grained tagging and extraction of sensitive information… | 98 | 4362 | active |
| TideSec/TscanPlus TscanPlus is a comprehensive network security detection and operations tool for rapid asset discovery, identification, and vulnerability de… | 82 | 4257 | active |
| jonaslejon/malicious-pdf A Python CLI tool that generates 67 malicious PDF test files embedding callbacks for SSRF, XSS, XXE, NTLM credential theft, and data exfilt… | 86 | 4254 | active |
| baihengaead/wlan-sec-test-tool A Python-based GUI tool for wireless network security testing that checks WiFi networks for weak passwords by attempting connections with a… | 70 | 4183 | active |
| guelfoweb/knockpy KnockPy is a modular Python 3 CLI tool for enumerating subdomains of a target domain using passive reconnaissance sources and DNS bruteforc… | 64 | 4178 | active |
| jasonxtn/Argus Argus is a Python-based all-in-one information gathering and reconnaissance toolkit with an interactive console and modular architecture. I… | 47 | 4082 | active |
| alexandreborges/malwoverview Malwoverview is a Python command-line first-response tool for threat hunting that queries many threat intelligence sources such as VirusTot… | 97 | 4075 | active |
| r0oth3x49/ghauri Ghauri is a cross-platform Python CLI tool that automates detection and exploitation of SQL injection vulnerabilities in web applications. … | 54 | 4070 | active |
| 0dayCTF/reverse-shell-generator A web-based reverse shell generator that produces common reverse shell payloads, listeners, MSFVenom commands, and HoaxShell integrations w… | 68 | 4047 | active |
| snooppr/snoop Snoop is a Python-based OSINT CLI tool that searches for a given username/nickname across ~5400+ websites, with a focus on the CIS region. … | 75 | 4009 | active |
| diego-treitos/linux-smart-enumeration A POSIX-compliant shell script that enumerates a local Linux system's security posture to help escalate privileges during pentesting and CT… | 59 | 3962 | active |
| trustedsec/unicorn Magic Unicorn is a Python CLI tool that generates PowerShell downgrade-attack commands to inject shellcode directly into memory. It support… | 70 | 3938 | active |
| itm4n/PrivescCheck A PowerShell enumeration script that identifies common Windows privilege escalation vulnerabilities and misconfigurations. It also collects… | 98 | 3928 | active |
| leebaird/discover A collection of custom Bash and Python scripts that automate penetration testing tasks including reconnaissance, scanning, enumeration, and… | 77 | 3928 | active |
| lanjelot/patator Patator is a multi-purpose, multi-threaded brute-forcing tool written in Python with a modular design supporting dozens of protocols (SSH, … | 42 | 3923 | active |
| cifertech/ESP32-DIV ESP32-DIV is open-source firmware (with open schematics and PCB files) for a custom ESP32-S3 handheld device that bundles Wi-Fi, BLE, 2.4GH… | 89 | 3890 | active |
| ambionics/phpggc PHPGGC is a library of PHP unserialize() payloads (gadget chains) with a command-line tool to generate them, covering frameworks like Larav… | 52 | 3876 | active |
| Pocsuite pocsuite3 is an open-source remote vulnerability testing and proof-of-concept development framework by Knownsec's 404 Team. It provides a P… | 27 | 3872 | active |
| elementalsouls/Claude-BugHunter A Claude Code skill bundle that turns Claude into a bug-hunting and red-team assistant, with 83 skills, 15 slash commands, and 681 disclose… | 77 | 3801 | active |
| Orange-Cyberdefense/arsenal Arsenal is a Python-based terminal tool that provides a searchable inventory of hard-to-remember pentest commands, letting users pick one a… | 32 | 3784 | active |
| pwntester/ysoserial.net ysoserial.net is a proof-of-concept command-line tool that generates deserialization payloads exploiting unsafe .NET object deserialization… | 62 | 3782 | active |
| scipag/vulscan Vulscan is an Nmap NSE script that turns Nmap into a vulnerability scanner by matching version-detected services against offline vulnerabil… | 52 | 3780 | active |
| RhinoSecurityLabs/cloudgoat CloudGoat is Rhino Security Labs' 'Vulnerable by Design' AWS deployment tool that provisions intentionally vulnerable cloud environments fo… | 78 | 3708 | active |
| S3cur3Th1sSh1t/WinPwn WinPwn is a PowerShell-based automation framework for internal Windows penetration testing and Active Directory security assessment. It bun… | 40 | 3693 | active |
| gadievron/raptor RAPTOR is an autonomous offensive/defensive security research framework built on top of Claude Code, chaining static analysis, binary analy… | 66 | 3672 | active |
| ly4k/Certipy Certipy is a Python CLI toolkit for enumerating and abusing Active Directory Certificate Services (AD CS) misconfigurations. It detects and… | 94 | 3643 | active |
| sooryathejas/METATRON METATRON is a CLI-based AI penetration testing assistant that runs a local LLM (via Ollama) entirely offline on Linux, primarily Parrot OS.… | 48 | 3616 | active |
| swisskyrepo/SSRFmap SSRFmap is a Python CLI framework that automatically detects and exploits Server-Side Request Forgery vulnerabilities. It takes a Burp Suit… | 76 | 3608 | active |
| s0md3v/XSStrike XSStrike is a Python command-line Cross Site Scripting (XSS) detection suite that uses hand-written HTML/JavaScript parsers, context analys… | 31 | 15151 | maintenance |
| arch3rPro/Pentest-Windows A pre-built Windows 11 penetration testing virtual machine image bundling 400+ security tools and scripts, distributed for VMware, Parallel… | 47 | 3549 | active |
| Adaptix-Framework/AdaptixC2 AdaptixC2 is an extensible post-exploitation and adversarial emulation (C2) framework for authorized penetration testing, with a Golang tea… | 67 | 3541 | active |
| SpacehuhnTech/esp8266_deauther ESP8266 Deauther is open-source firmware that turns an ESP8266 microcontroller into a WiFi testing tool capable of scanning networks, sendi… | 23 | 14943 | maintenance |
| epinna/weevely3 Weevely is a weaponized web shell for post-exploitation that generates a small obfuscated PHP agent to upload to a target web server, provi… | 46 | 3533 | active |
| wifiphisher/wifiphisher Wifiphisher is a rogue Access Point framework for Wi-Fi security testing and red team engagements, enabling man-in-the-middle positioning v… | 60 | 14788 | maintenance |
| fofapro/vulfocus Vulfocus is a self-hosted vulnerability integration platform that runs vulnerability environments as Docker images with one-click startup. … | 41 | 3492 | active |
| t3l3machus/hoaxshell Hoaxshell is a Windows reverse shell payload generator and handler that abuses the HTTP(S) protocol to establish a beacon-like reverse shel… | 33 | 3487 | active |
| BlackArch Linux BlackArch Linux is an Arch Linux-based penetration testing distribution bundling over 2,800 security tools for penetration testers and secu… | 77 | 3474 | active |
| ropnop/kerbrute Kerbrute is a Go-based CLI tool for brute-forcing and enumerating valid Active Directory accounts through Kerberos Pre-Authentication. It o… | 23 | 3429 | stable |
| vulnersCom/nmap-vulners A collection of Nmap NSE scripts that enrich service scans with CVEs, CVSS scores and known exploits from the Vulners database. It fingerpr… | 98 | 3415 | active |
| ph4ntonn/Stowaway Stowaway is a multi-hop proxy tool written in Go, designed for penetration testers to route external traffic through chains of nodes into r… | 54 | 3411 | active |
| L-codes/Neo-reGeorg Neo-reGeorg is a Python CLI tool that generates encrypted tunnel server files (aspx/jsp/php/etc.) to be uploaded to a compromised web serve… | 75 | 3401 | active |
| EntySec/Ghost Ghost Framework is a Python-based Android post-exploitation framework that leverages the Android Debug Bridge (ADB) to gain remote access t… | 54 | 3392 | active |
| H4ckForJob/dirmap Dirmap is an advanced web directory and file scanning tool written in Python, designed to be more powerful than DirBuster, Dirsearch, cansi… | 44 | 3374 | stable |
| BloodHound Community Edition BloodHound Community Edition is a free, open-source application that uses graph theory to reveal hidden relationships and attack paths in A… | 91 | 3355 | active |
| skelsec/pypykatz pypykatz is a pure Python implementation of parts of Mimikatz, the well-known Windows credential extraction tool. It parses LSASS process m… | 65 | 3352 | active |
| almandin/fuxploider Fuxploider is an open-source penetration testing tool that automates detection and exploitation of file upload form vulnerabilities. It ide… | 32 | 3328 | active |
| dbisu/pico-ducky A project that turns a Raspberry Pi Pico into a USB Rubber Ducky-style HID injection device running CircuitPython. It executes Ducky Script… | 71 | 3307 | active |
| s0md3v/Smap Smap is a passive port scanner powered by Shodan.io's free API that serves as a drop-in replacement for Nmap, accepting the same command-li… | 90 | 3287 | active |
| dafthack/MailSniper MailSniper is a PowerShell-based penetration testing tool for searching email in Microsoft Exchange environments for sensitive terms like p… | 77 | 3276 | active |
| rtcatc/Packer-Fuzzer Packer Fuzzer is a Python-based security scanner that targets websites built with JavaScript module bundlers like Webpack. It automatically… | 23 | 3249 | active |
| assetnote/kiterunner Kiterunner is a fast content discovery tool written in Go that bruteforces files, folders, and API routes on web servers. It uses a dataset… | 64 | 3247 | stable |
| D3Ext/WEF WEF is a Wi-Fi Exploitation Framework written in Bash that automates a wide range of wireless attacks against WPA/WPA2/WPA3, WPS, and WEP n… | 52 | 3209 | active |
| jaykali/maskphish MaskPhish is a simple Bash script that masks phishing URLs under normal-looking URLs (e.g., google.com or facebook.com) as a proof of conce… | 42 | 3191 | active |
| pingc0y/URLFinder URLFinder is a fast, easy-to-use Go CLI tool that extracts JS files, URLs, and sensitive information from web pages, including hidden unaut… | 80 | 3170 | active |
| sa7mon/S3Scanner A multi-threaded CLI tool written in Go that scans for misconfigured (open) S3 buckets across AWS and other S3-compatible providers like GC… | 77 | 3165 | active |
| 21y4d/nmapAutomator nmapAutomator is a POSIX-compatible shell script that automates nmap-based network reconnaissance and enumeration, running scans in the bac… | 32 | 3109 | active |
| ThePorgs/Exegol Exegol is a container-based, community-driven hacking environment for offensive security professionals, managed through a Python CLI wrappe… | 97 | 3072 | active |
| projectdiscovery/proxify Proxify is a portable MITM proxy written in Go for capturing, filtering, manipulating, and replaying HTTP/HTTPS and non-HTTP traffic. It su… | 68 | 3064 | active |
| darkoperator/dnsrecon DNSRecon is a Python-based DNS enumeration tool for security assessments and network troubleshooting. It supports zone transfer checks, gen… | 91 | 3061 | active |
| Kevin-Robertson/Inveigh Inveigh is a cross-platform .NET IPv4/IPv6 machine-in-the-middle tool for penetration testers, with a primary C# version and a legacy Power… | 53 | 3014 | active |
| GH05TCREW/pentestagent PentestAgent is a Python-based AI agent framework for black-box penetration testing that orchestrates LLM-driven security testing workflows… | 62 | 3010 | active |
| mgeeky/Penetration-Testing-Tools A curated collection of 170+ penetration testing tools, scripts, and cheatsheets developed by the author over years of red teaming and IT s… | 32 | 3001 | active |
| Netw0rkNoob/VulnClaw VulnClaw is an AI-driven penetration testing CLI tool that combines an LLM agent, MCP toolchain, and curated pentest skills to automate the… | 80 | 2997 | active |
| tegal1337/CiLocks CiLocks is a menu-driven Linux CLI toolkit for Android and iOS security testing, bundling lockscreen brute-force/bypass, ADB data extractio… | 23 | 2991 | active |
| Manisso/fsociety Fsociety is a Python-based penetration testing framework that bundles a menu of hacking tools covering information gathering, password atta… | 74 | 12275 | maintenance |