Ross ROSS = Recommend OSS · open-source software intelligence for agents

domain: penetration-testing

1317 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
FluxionNetwork/fluxion
Fluxion is a security auditing and social-engineering research tool that retrieves WPA/WPA2 keys via phishing attacks using rogue access po…
915907active
lanmaster53/recon-ng
Recon-ng is a full-featured, modular reconnaissance framework for conducting web-based open source intelligence (OSINT) gathering. It offer…
325871active
RedSiege/EyeWitness
EyeWitness is a Python CLI tool that takes screenshots of websites using headless Chromium, captures server header information, and identif…
505829active
commixproject/commix
Commix (short for command injection exploiter) is an open-source penetration testing tool that automates the detection and exploitation of …
755824active
Pennyw0rth/NetExec
NetExec (nxc) is a community-maintained, open-source network execution tool and successor to CrackMapExec, used for pentesting and red-team…
745815active
elder-plinius/T3MP3ST
T3MP3ST is a multi-agent offensive-security framework that turns existing AI coding agents (Claude Code, Codex, Ollama, etc.) into autonomo…
585684active
trustedsec/ptf
The PenTesters Framework (PTF) is a Python-based modular framework that installs, compiles, and keeps penetration testing tools up to date …
325558active
OWASP/Nettacker
OWASP Nettacker is a Python-based automated penetration testing and information-gathering framework for reconnaissance, vulnerability scann…
885535active
Hackplayers/evil-winrm
Evil-WinRM is a Ruby-based command-line WinRM shell designed for hacking and penetration testing of Windows servers. It supports features l…
795448active
drk1wi/Modlishka
Modlishka is an open-source penetration testing tool written in Go that acts as a transparent man-in-the-middle reverse proxy. It can proxy…
665407active
PurpleAILAB/Decepticon
Decepticon is an autonomous AI red-team hacking agent that uses LLMs (built on LangChain/LangGraph) to plan and execute context-aware offen…
805335active
Ladon
Ladon is a large-scale internal network penetration scanner written in C#, offering port scanning, service identification, network asset di…
295320active
RhinoSecurityLabs/pacu
Pacu is an open-source AWS exploitation framework for offensive security testing of Amazon Web Services environments. It provides a modular…
735312active
FunnyWolf/Viper
VIPER is a self-hosted red teaming and adversary simulation platform with a web UI, 100+ post-exploitation modules covering MITRE ATT&CK, a…
855279active
hahwul/dalfox
Dalfox is an open-source XSS vulnerability scanner written in Rust that automates discovery, injection, and DOM/AST-level verification of r…
985256active
Ullaakut/cameradar
Cameradar is a Go-based command-line tool that scans targets for open RTSP video surveillance endpoints and uses dictionary attacks to disc…
945173active
GhostPack/Rubeus
Rubeus is a C# command-line toolset for raw Kerberos interaction and abuse on Windows, adapted from Kekeo and MakeMeEnterpriseAdmin. It sup…
605145active
hakluke/hakrawler
Hakrawler is a fast command-line web crawler written in Go, built on the Gocolly library, that discovers URLs and JavaScript file locations…
665116active
techchipnet/CamPhish
CamPhish is a bash-based penetration-testing tool that hosts a fake webpage on a built-in PHP server and exposes it via ngrok or CloudFlare…
405020active
bitsadmin/wesng
WES-NG is a Python command-line tool that parses Windows `systeminfo` output (or missing KB listings) and cross-references it against a reg…
764923active
nicocha30/ligolo-ng
Ligolo-ng is a tunneling and pivoting tool written in Go that establishes tunnels over reverse TCP/TLS connections using a TUN interface in…
984893active
UndeadSec/SocialFish
SocialFish is a Python-based phishing toolkit that clones modern login pages using Playwright browser automation and captures credentials, …
764851active
cdk-team/CDK
CDK is a zero-dependency container penetration toolkit written in Go for security testing of Kubernetes, Docker, and Containerd environment…
704740active
its-a-feature/Mythic
Mythic is a collaborative, multi-platform post-exploitation red teaming framework built with Go, Docker, and a web browser UI. It provides …
784725active
AntSwordProject/antSword
AntSword is a cross-platform, open-source website administration toolkit built with Electron, designed for penetration testers, security re…
734693active
TheWover/donut
Donut is a shellcode generator that converts VBScript, JScript, EXE, DLL files, and .NET assemblies into x86, x64, or AMD64+x86 position-in…
364689stable
GhostPack/Seatbelt
Seatbelt is a C# command-line tool that performs security-oriented host-survey 'safety checks' on Windows systems. It enumerates system and…
324683active
ReversecLabs/drozer
drozer is an open-source security assessment framework for Android that lets testers assume the role of an app and interact with the Androi…
574597active
projectdiscovery/interactsh
Interactsh is an open-source tool for detecting out-of-band (OOB) interactions via DNS, HTTP(S), SMTP(S), and LDAP, useful for identifying …
854512active
samsesh/SocialBox-Termux
SocialBox-Termux is a shell-based brute-force attack framework targeting social media and email services like Facebook, Gmail, Instagram, a…
724497active
Awarexone/Agentic-Bug-Hunter
An AI-powered bug bounty hunting toolkit that automates reconnaissance, vulnerability testing, finding validation, and report generation fo…
774464active
BeichenDream/Godzilla
Godzilla is a Java-based webshell management tool supporting dynamic payloads for JSP, ASPX, and PHP targets with multiple AES/XOR encrypto…
234455active
t3l3machus/Villain
Villain is a high-level stage 0/1 command-and-control (C2) framework written in Python that handles multiple reverse TCP and HoaxShell-base…
404439active
GerbenJavado/LinkFinder
LinkFinder is a Python CLI script that discovers endpoints and their parameters in JavaScript files using jsbeautifier and regular expressi…
324439stable
zan8in/afrog
afrog is an open-source security tool written in Go for vulnerability scanning using PoC (Proof of Concept) rules. It is designed for bug b…
964372active
overspace-labs/HaE
HaE (Highlighter and Extractor) is a framework-style cybersecurity project for fine-grained tagging and extraction of sensitive information…
984362active
TideSec/TscanPlus
TscanPlus is a comprehensive network security detection and operations tool for rapid asset discovery, identification, and vulnerability de…
824257active
jonaslejon/malicious-pdf
A Python CLI tool that generates 67 malicious PDF test files embedding callbacks for SSRF, XSS, XXE, NTLM credential theft, and data exfilt…
864254active
baihengaead/wlan-sec-test-tool
A Python-based GUI tool for wireless network security testing that checks WiFi networks for weak passwords by attempting connections with a…
704183active
guelfoweb/knockpy
KnockPy is a modular Python 3 CLI tool for enumerating subdomains of a target domain using passive reconnaissance sources and DNS bruteforc…
644178active
jasonxtn/Argus
Argus is a Python-based all-in-one information gathering and reconnaissance toolkit with an interactive console and modular architecture. I…
474082active
alexandreborges/malwoverview
Malwoverview is a Python command-line first-response tool for threat hunting that queries many threat intelligence sources such as VirusTot…
974075active
r0oth3x49/ghauri
Ghauri is a cross-platform Python CLI tool that automates detection and exploitation of SQL injection vulnerabilities in web applications. …
544070active
0dayCTF/reverse-shell-generator
A web-based reverse shell generator that produces common reverse shell payloads, listeners, MSFVenom commands, and HoaxShell integrations w…
684047active
snooppr/snoop
Snoop is a Python-based OSINT CLI tool that searches for a given username/nickname across ~5400+ websites, with a focus on the CIS region. …
754009active
diego-treitos/linux-smart-enumeration
A POSIX-compliant shell script that enumerates a local Linux system's security posture to help escalate privileges during pentesting and CT…
593962active
trustedsec/unicorn
Magic Unicorn is a Python CLI tool that generates PowerShell downgrade-attack commands to inject shellcode directly into memory. It support…
703938active
itm4n/PrivescCheck
A PowerShell enumeration script that identifies common Windows privilege escalation vulnerabilities and misconfigurations. It also collects…
983928active
leebaird/discover
A collection of custom Bash and Python scripts that automate penetration testing tasks including reconnaissance, scanning, enumeration, and…
773928active
lanjelot/patator
Patator is a multi-purpose, multi-threaded brute-forcing tool written in Python with a modular design supporting dozens of protocols (SSH, …
423923active
cifertech/ESP32-DIV
ESP32-DIV is open-source firmware (with open schematics and PCB files) for a custom ESP32-S3 handheld device that bundles Wi-Fi, BLE, 2.4GH…
893890active
ambionics/phpggc
PHPGGC is a library of PHP unserialize() payloads (gadget chains) with a command-line tool to generate them, covering frameworks like Larav…
523876active
Pocsuite
pocsuite3 is an open-source remote vulnerability testing and proof-of-concept development framework by Knownsec's 404 Team. It provides a P…
273872active
elementalsouls/Claude-BugHunter
A Claude Code skill bundle that turns Claude into a bug-hunting and red-team assistant, with 83 skills, 15 slash commands, and 681 disclose…
773801active
Orange-Cyberdefense/arsenal
Arsenal is a Python-based terminal tool that provides a searchable inventory of hard-to-remember pentest commands, letting users pick one a…
323784active
pwntester/ysoserial.net
ysoserial.net is a proof-of-concept command-line tool that generates deserialization payloads exploiting unsafe .NET object deserialization…
623782active
scipag/vulscan
Vulscan is an Nmap NSE script that turns Nmap into a vulnerability scanner by matching version-detected services against offline vulnerabil…
523780active
RhinoSecurityLabs/cloudgoat
CloudGoat is Rhino Security Labs' 'Vulnerable by Design' AWS deployment tool that provisions intentionally vulnerable cloud environments fo…
783708active
S3cur3Th1sSh1t/WinPwn
WinPwn is a PowerShell-based automation framework for internal Windows penetration testing and Active Directory security assessment. It bun…
403693active
gadievron/raptor
RAPTOR is an autonomous offensive/defensive security research framework built on top of Claude Code, chaining static analysis, binary analy…
663672active
ly4k/Certipy
Certipy is a Python CLI toolkit for enumerating and abusing Active Directory Certificate Services (AD CS) misconfigurations. It detects and…
943643active
sooryathejas/METATRON
METATRON is a CLI-based AI penetration testing assistant that runs a local LLM (via Ollama) entirely offline on Linux, primarily Parrot OS.…
483616active
swisskyrepo/SSRFmap
SSRFmap is a Python CLI framework that automatically detects and exploits Server-Side Request Forgery vulnerabilities. It takes a Burp Suit…
763608active
s0md3v/XSStrike
XSStrike is a Python command-line Cross Site Scripting (XSS) detection suite that uses hand-written HTML/JavaScript parsers, context analys…
3115151maintenance
arch3rPro/Pentest-Windows
A pre-built Windows 11 penetration testing virtual machine image bundling 400+ security tools and scripts, distributed for VMware, Parallel…
473549active
Adaptix-Framework/AdaptixC2
AdaptixC2 is an extensible post-exploitation and adversarial emulation (C2) framework for authorized penetration testing, with a Golang tea…
673541active
SpacehuhnTech/esp8266_deauther
ESP8266 Deauther is open-source firmware that turns an ESP8266 microcontroller into a WiFi testing tool capable of scanning networks, sendi…
2314943maintenance
epinna/weevely3
Weevely is a weaponized web shell for post-exploitation that generates a small obfuscated PHP agent to upload to a target web server, provi…
463533active
wifiphisher/wifiphisher
Wifiphisher is a rogue Access Point framework for Wi-Fi security testing and red team engagements, enabling man-in-the-middle positioning v…
6014788maintenance
fofapro/vulfocus
Vulfocus is a self-hosted vulnerability integration platform that runs vulnerability environments as Docker images with one-click startup. …
413492active
t3l3machus/hoaxshell
Hoaxshell is a Windows reverse shell payload generator and handler that abuses the HTTP(S) protocol to establish a beacon-like reverse shel…
333487active
BlackArch Linux
BlackArch Linux is an Arch Linux-based penetration testing distribution bundling over 2,800 security tools for penetration testers and secu…
773474active
ropnop/kerbrute
Kerbrute is a Go-based CLI tool for brute-forcing and enumerating valid Active Directory accounts through Kerberos Pre-Authentication. It o…
233429stable
vulnersCom/nmap-vulners
A collection of Nmap NSE scripts that enrich service scans with CVEs, CVSS scores and known exploits from the Vulners database. It fingerpr…
983415active
ph4ntonn/Stowaway
Stowaway is a multi-hop proxy tool written in Go, designed for penetration testers to route external traffic through chains of nodes into r…
543411active
L-codes/Neo-reGeorg
Neo-reGeorg is a Python CLI tool that generates encrypted tunnel server files (aspx/jsp/php/etc.) to be uploaded to a compromised web serve…
753401active
EntySec/Ghost
Ghost Framework is a Python-based Android post-exploitation framework that leverages the Android Debug Bridge (ADB) to gain remote access t…
543392active
H4ckForJob/dirmap
Dirmap is an advanced web directory and file scanning tool written in Python, designed to be more powerful than DirBuster, Dirsearch, cansi…
443374stable
BloodHound Community Edition
BloodHound Community Edition is a free, open-source application that uses graph theory to reveal hidden relationships and attack paths in A…
913355active
skelsec/pypykatz
pypykatz is a pure Python implementation of parts of Mimikatz, the well-known Windows credential extraction tool. It parses LSASS process m…
653352active
almandin/fuxploider
Fuxploider is an open-source penetration testing tool that automates detection and exploitation of file upload form vulnerabilities. It ide…
323328active
dbisu/pico-ducky
A project that turns a Raspberry Pi Pico into a USB Rubber Ducky-style HID injection device running CircuitPython. It executes Ducky Script…
713307active
s0md3v/Smap
Smap is a passive port scanner powered by Shodan.io's free API that serves as a drop-in replacement for Nmap, accepting the same command-li…
903287active
dafthack/MailSniper
MailSniper is a PowerShell-based penetration testing tool for searching email in Microsoft Exchange environments for sensitive terms like p…
773276active
rtcatc/Packer-Fuzzer
Packer Fuzzer is a Python-based security scanner that targets websites built with JavaScript module bundlers like Webpack. It automatically…
233249active
assetnote/kiterunner
Kiterunner is a fast content discovery tool written in Go that bruteforces files, folders, and API routes on web servers. It uses a dataset…
643247stable
D3Ext/WEF
WEF is a Wi-Fi Exploitation Framework written in Bash that automates a wide range of wireless attacks against WPA/WPA2/WPA3, WPS, and WEP n…
523209active
jaykali/maskphish
MaskPhish is a simple Bash script that masks phishing URLs under normal-looking URLs (e.g., google.com or facebook.com) as a proof of conce…
423191active
pingc0y/URLFinder
URLFinder is a fast, easy-to-use Go CLI tool that extracts JS files, URLs, and sensitive information from web pages, including hidden unaut…
803170active
sa7mon/S3Scanner
A multi-threaded CLI tool written in Go that scans for misconfigured (open) S3 buckets across AWS and other S3-compatible providers like GC…
773165active
21y4d/nmapAutomator
nmapAutomator is a POSIX-compatible shell script that automates nmap-based network reconnaissance and enumeration, running scans in the bac…
323109active
ThePorgs/Exegol
Exegol is a container-based, community-driven hacking environment for offensive security professionals, managed through a Python CLI wrappe…
973072active
projectdiscovery/proxify
Proxify is a portable MITM proxy written in Go for capturing, filtering, manipulating, and replaying HTTP/HTTPS and non-HTTP traffic. It su…
683064active
darkoperator/dnsrecon
DNSRecon is a Python-based DNS enumeration tool for security assessments and network troubleshooting. It supports zone transfer checks, gen…
913061active
Kevin-Robertson/Inveigh
Inveigh is a cross-platform .NET IPv4/IPv6 machine-in-the-middle tool for penetration testers, with a primary C# version and a legacy Power…
533014active
GH05TCREW/pentestagent
PentestAgent is a Python-based AI agent framework for black-box penetration testing that orchestrates LLM-driven security testing workflows…
623010active
mgeeky/Penetration-Testing-Tools
A curated collection of 170+ penetration testing tools, scripts, and cheatsheets developed by the author over years of red teaming and IT s…
323001active
Netw0rkNoob/VulnClaw
VulnClaw is an AI-driven penetration testing CLI tool that combines an LLM agent, MCP toolchain, and curated pentest skills to automate the…
802997active
tegal1337/CiLocks
CiLocks is a menu-driven Linux CLI toolkit for Android and iOS security testing, bundling lockscreen brute-force/bypass, ADB data extractio…
232991active
Manisso/fsociety
Fsociety is a Python-based penetration testing framework that bundles a menu of hacking tools covering information gathering, password atta…
7412275maintenance

← prev page 2 / 14 next →