domain: penetration-testing
1317 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| makoto56/penetration-suite-toolkit A preconfigured Windows 11 penetration testing toolkit distributed as a VM image, bundling a large curated collection of security tools wit… | 34 | 2970 | active |
| xiv3r/Burpsuite-Professional A shell-based installer that deploys Burp Suite Professional (a commercial web security testing toolkit) on Linux and NixOS, bundled with a… | 66 | 2968 | active |
| thewhiteh4t/FinalRecon FinalRecon is an all-in-one automatic web reconnaissance tool written in Python that provides a fast overview of a web target. It bundles h… | 70 | 2953 | active |
| calebstewart/pwncat pwncat is a post-exploitation platform and handler for reverse and bind shells, written in Python. It wraps raw shell communication with an… | 10 | 2917 | active |
| SnaffCon/Snaffler Snaffler is a C# command-line tool for pentesters and red teamers that enumerates Windows/AD environments to find sensitive files (mostly c… | 76 | 2915 | active |
| palahsu/DDoS-Ripper DDoS-Ripper (DRipper) is a Python command-line tool that floods a target IP with traffic to simulate a distributed denial-of-service attack… | 72 | 2914 | active |
| jayofelony/pwnagotchi Pwnagotchi is a Raspberry Pi-based Wi-Fi penetration-testing gadget that leverages Bettercap to passively sniff or actively attack nearby W… | 93 | 2886 | active |
| pwndoc/pwndoc PwnDoc is a self-hosted web application for writing penetration test findings and generating customizable Docx reports. It supports multi-u… | 98 | 2882 | active |
| i-am-shodan/USBArmyKnife USB Army Knife is firmware for ESP32-based USB devices (like the T-Dongle-S3) that turns them into a close-access penetration testing tool.… | 71 | 2870 | active |
| flozz/p0wny-shell p0wny@shell is a single-file PHP webshell that provides a browser-based terminal for executing commands on a remote server. It is designed … | 39 | 2860 | active |
| LimerBoy/Impulse Impulse is a Python-based denial-of-service toolkit that bundles multiple attack methods including SYN, UDP, ICMP, HTTP floods, Slowloris, … | 39 | 2840 | active |
| gkbrk/slowloris A Python rewrite of the Slowloris low-bandwidth HTTP Denial of Service attack tool. It holds many connections open to threaded web servers … | 32 | 2820 | stable |
| screetsec/TheFatRat TheFatRat is a menu-driven exploiting tool that automates MSFvenom and Metasploit to generate backdoors and payloads for Windows, Linux, Ma… | 23 | 11444 | maintenance |
| digininja/CeWL CeWL is a Ruby command-line tool that spiders a target website to a specified depth and collects unique words into a custom wordlist for us… | 63 | 2801 | stable |
| zema1/suo5 Suo5 is a high-performance HTTP tunneling tool that creates a local SOCKS5 forward proxy by tunneling traffic through a compromised web ser… | 85 | 2796 | active |
| hasherezade/pe_to_shellcode A C++ command-line tool that converts Windows PE executables into shellcode-compatible form, adding a reflective loading stub post-compilat… | 40 | 2793 | active |
| calebmadrigal/trackerjacker A Python CLI tool that maps nearby WiFi networks and their connected devices via raw 802.11 monitor-mode packet capture, similar to nmap bu… | 56 | 2739 | active |
| Impact-I/reFlutter reFlutter is a Python CLI framework for reverse engineering Flutter mobile apps by repacking APK/IPA files with a specially patched, precom… | 95 | 2738 | active |
| NetSPI/PowerUpSQL PowerUpSQL is a PowerShell toolkit for attacking and auditing SQL Server instances, supporting discovery, weak configuration auditing, priv… | 32 | 2737 | active |
| aboul3la/Sublist3r Sublist3r is a Python command-line tool that enumerates subdomains of a target domain using OSINT sources such as Google, Bing, Yahoo, Baid… | 23 | 11023 | maintenance |
| f0rb1dd3n/Reptile Reptile is a Linux kernel module (LKM) rootkit written in C that provides privilege escalation, file/process/network connection hiding, per… | 67 | 2718 | active |
| ankit0183/Wifi-Hacking A Python-based menu-driven CLI tool that automates Wi-Fi penetration testing by wrapping built-in Kali Linux wireless tools. It supports mo… | 59 | 2667 | active |
| ryfineZ/codex-session-patcher A Python tool that cleans AI refusal responses from Codex CLI, Claude Code, and OpenCode session files so conversations can be resumed, wit… | 79 | 2649 | active |
| arthaud/git-dumper git-dumper is a Python CLI tool that reconstructs a full git repository from a website that exposes its .git directory, even when directory… | 64 | 2645 | stable |
| thewhiteh4t/pwnedOrNot pwnedOrNot is a Python command-line OSINT tool that checks email addresses against the HaveIBeenPwned v3 API for past breaches and then sea… | 66 | 2628 | active |
| TermuxHackz/X-osint X-osint is an open-source Python-based OSINT framework for gathering information about phone numbers, email addresses, IP addresses, VINs, … | 72 | 2627 | active |
| SummerSec/ShiroAttack2 A Java-based exploitation tool for the Apache Shiro-550 rememberMe deserialization vulnerability, offering both a JavaFX GUI and a CLI. It … | 88 | 2619 | active |
| rbsec/sslscan sslscan is a command-line tool that tests SSL/TLS enabled services to discover supported cipher suites, protocols, key exchange groups, and… | 75 | 2618 | active |
| googleprojectzero/winafl WinAFL is a Windows fork of American Fuzzy Lop (AFL) for coverage-guided fuzzing of Windows binaries, including closed-source black-box tar… | 65 | 2604 | active |
| honmashironeko/ProxyCat ProxyCat is a self-hosted tunnel proxy pool middleware that turns short-lived proxy IPs into a stable fixed tunnel endpoint over HTTP/SOCKS… | 66 | 2581 | active |
| BishopFox/cloudfox CloudFox is an open-source command line tool by Bishop Fox that automates situational awareness and enumeration in cloud environments, prim… | 90 | 2563 | active |
| Syslifters/sysreptor SysReptor is a customizable pentest reporting platform for penetration testers and red teamers, supporting report design in HTML, writing i… | 99 | 2560 | active |
| caido/caido Caido is a lightweight web security auditing toolkit and HTTP proxy for intercepting, viewing, and modifying traffic between browsers and w… | 99 | 2558 | active |
| s0lst1c3/eaphammer EAPHammer is a toolkit for performing targeted evil twin attacks against WPA2-Enterprise networks, including credential stealing and hostil… | 23 | 2552 | active |
| lgandx/PCredz PCredz is a Python CLI tool that extracts credentials and authentication tokens (NTLM, Kerberos, HTTP Basic, FTP, SMTP, IMAP, POP3, LDAP, S… | 64 | 2548 | active |
| monoxgas/sRDI sRDI is a shellcode implementation of Reflective DLL Injection that converts DLL files into position-independent shellcode via a compiled P… | 32 | 2547 | stable |
| splunk/attack_range Splunk Attack Range is a tool that builds instrumented, vulnerable lab environments in the cloud (AWS, Azure, GCP) or locally using Terrafo… | 84 | 2545 | active |
| 7h30th3r0n3/Evil-M5Project Evil-M5Project is a C++ firmware/tool for M5Stack devices (Cardputer, AtomS3, Fire, Core2) that scans, monitors, and interacts with WiFi ne… | 70 | 2543 | active |
| x90skysn3k/brutespray Brutespray is a fast, multi-protocol credential brute-forcing tool written in Go. It parses scan output from Nmap, Nessus, Nexpose, JSON, a… | 95 | 2525 | active |
| kpcyrd/sn0int sn0int is a semi-automatic OSINT framework and package manager written in Rust that enumerates attack surface by processing public informat… | 60 | 2515 | active |
| epsylon/ufonet UFONet is a free, P2P and cryptographic 'disruptive toolkit' written in Python for performing DoS and DDoS attacks at Layer 7 (HTTP) via Op… | 76 | 2509 | active |
| m4ll0k/SecretFinder SecretFinder is a Python CLI script based on LinkFinder that discovers sensitive data like API keys, access tokens, and JWTs in JavaScript … | 32 | 2500 | active |
| nil0x42/phpsploit PhpSploit is a full-featured command-and-control (C2) framework that persists on a webserver via a stealthy single-line PHP backdoor. It is… | 23 | 2491 | active |
| TH3xACE/SUDO_KILLER SUDO_KILLER is a Shell-based security tool that audits Linux systems for sudo-related privilege escalation vectors, including misconfigurat… | 64 | 2481 | active |
| sabri-zaki/EasY_HaCk EasY_HaCk is a Termux-based penetration testing menu tool that bundles and installs tools like Metasploit, Nmap, SQLmap, and recon-ng for n… | 43 | 2471 | active |
| Idov31/Nidhogg Nidhogg is an open-source Windows x64 kernel rootkit written in C++ that demonstrates a wide range of rootkit techniques such as process, t… | 83 | 2463 | active |
| assetnote/react2shell-scanner A Python command-line scanner that detects RCE vulnerabilities CVE-2025-55182 and CVE-2025-66478 in Next.js applications using React Server… | 41 | 2459 | active |
| Notselwyn/CVE-2024-1086 A proof-of-concept local privilege escalation exploit for CVE-2024-1086, a double-free vulnerability in the Linux kernel's nf_tables subsys… | 16 | 2457 | stable |
| noob-hackers/hacklock Hacklock is a bash-based Termux tool that generates pattern phishing pages to capture an Android victim's unlock pattern via a shared link … | 53 | 2445 | active |
| m0nad/Diamorphine Diamorphine is a loadable kernel module (LKM) rootkit for Linux kernels 2.6.x through 6.x on x86/x86_64 and ARM64. It demonstrates rootkit … | 68 | 2442 | active |
| XSS Hunter XSS Hunter Express is a self-hosted service for tracking and detecting blind cross-site scripting (XSS) vulnerabilities via injected payloa… | 32 | 2440 | active |
| dirkjanm/BloodHound.py BloodHound.py is a Python-based data ingestor for BloodHound that enumerates Active Directory domains, collecting users, groups, computers,… | 54 | 2437 | active |
| ZerBea/hcxtools A set of C command-line tools that convert WiFi packet captures (pcap/pcapng) into hash formats compatible with Hashcat and John the Ripper… | 79 | 2431 | active |
| drk1wi/Portspoof Portspoof is a lightweight C++ tool that emulates open TCP ports and convincing service signatures across all 65535 ports, making port scan… | 85 | 2427 | active |
| NetSPI/MicroBurst MicroBurst is a PowerShell toolkit for assessing Microsoft Azure security, including service discovery, weak configuration auditing, and po… | 73 | 2426 | active |
| GiacomoLaw/Keylogger A simple, bare-bones keylogger that records keystrokes and saves them to a local log file, with separate implementations for Windows, Linux… | 39 | 2421 | active |
| LoRexxar/Kunlun-M Kunlun-M is an open-source static code analysis (SAST) tool that detects security vulnerabilities in PHP, JavaScript/Node.js, Python, Golan… | 96 | 2413 | active |
| oritera/Cairn Cairn is a general-purpose AI state-space search engine built on a blackboard architecture with a fact-intent graph, where LLM agent worker… | 72 | 2395 | active |
| OpenBullet OpenBullet 2 is a cross-platform automation suite built on .NET for performing HTTP requests against target web applications and processing… | 85 | 2389 | active |
| DataDog/stratus-red-team Stratus Red Team is a self-contained Go CLI that emulates granular, actionable cloud attack techniques mapped to MITRE ATT&CK, against AWS,… | 99 | 2379 | active |
| lijiejie/BBScan BBScan is a fast, lightweight, high-concurrency web vulnerability scanner written in Python. It helps penetration testers quickly identify … | 23 | 2371 | active |
| jorhelp/Ingram Ingram is a Python-based vulnerability scanning framework targeting network cameras (IP/CCTV devices). It integrates known exploits for com… | 67 | 2356 | active |
| samugit83/redamon RedAmon is an AI-powered agentic red team framework that automates offensive security operations end-to-end, chaining reconnaissance, explo… | 81 | 2354 | active |
| jtpereyda/boofuzz boofuzz is a Python-based network protocol fuzzing framework and the successor to the Sulley Fuzzing Framework. It provides data generation… | 66 | 2354 | active |
| david942j/one_gadget A Ruby command-line tool that finds one-gadget RCE candidates (execve('/bin/sh',...) call sites) in libc binaries for CTF pwn challenges. I… | 67 | 2346 | active |
| MegaManSec/SSH-Snake SSH-Snake is a self-propagating, file-less bash script that automatically discovers SSH private keys on a system, attempts to connect to re… | 10 | 2342 | active |
| AabyssZG/SpringBoot-Scan SpringBoot-Scan is an open-source penetration testing framework targeting Spring Boot applications, written in Python. It scans for sensiti… | 53 | 2340 | active |
| googleprojectzero/fuzzilli Fuzzilli is a coverage-guided fuzzer for JavaScript engines, built in Swift by Google Project Zero. It generates test programs via a custom… | 67 | 2334 | active |
| BeichenDream/GodPotato GodPotato is a C# Windows privilege escalation tool that abuses a DCOM/RPCSS oxid resolution defect to elevate from a service account with … | 22 | 2334 | stable |
| Ch0pin/medusa MEDUSA is a modular automation framework and script repository for runtime testing and investigating Android and iOS apps, built on FRIDA. … | 84 | 2332 | active |
| bigbrodude6119/flipper-zero-evil-portal A Flipper Zero application that turns the Wi-Fi dev board (ESP32) into an open access point serving a fake captive portal login page. Captu… | 19 | 2332 | active |
| ssl/ezXSS ezXSS is a self-hosted PHP application that helps penetration testers and bug bounty hunters detect and exploit (blind) cross-site scriptin… | 64 | 2330 | active |
| safebuffer/vulnerable-AD A PowerShell script that configures a Windows Server domain controller into a deliberately vulnerable Active Directory environment for prac… | 32 | 2325 | active |
| p0dalirius/Coercer Coercer is a Python CLI tool that automatically coerces Windows servers to authenticate to an arbitrary machine via multiple RPC methods ov… | 58 | 2310 | active |
| 1N3/BruteX BruteX is a shell-based CLI tool that automatically brute forces all services running on a target, enumerating open ports, usernames, and p… | 23 | 2299 | active |
| n1nj4sec/pupy Pupy is an open-source, cross-platform (Windows, Linux, macOS, Android) command-and-control and post-exploitation framework written in Pyth… | 10 | 8999 | maintenance |
| jofpin/trape Trape is an OSINT analysis and research tool for tracking people online and executing real-time social engineering attacks, built in Python… | 32 | 8978 | maintenance |
| lz520520/railgun Railgun is a GUI-based penetration testing tool that automates common tasks from manual pentesting experience. It integrates port scanning,… | 35 | 2289 | active |
| API-Security/APIKit APIKit is a BurpSuite extension (Java plugin) that discovers, scans, and audits leaked API documentation such as GraphQL, OpenAPI/Swagger, … | 23 | 2286 | active |
| CravateRouge/bloodyAD bloodyAD is a Python CLI tool for Active Directory privilege escalation that performs specific LDAP calls against domain controllers. It su… | 97 | 2275 | active |
| spyboy-productions/CloakQuest3r CloakQuest3r is a Python-based open-source security research tool that identifies potential origin IP exposure of websites protected by Clo… | 54 | 2250 | active |
| pen4uin/java-memshell-generator A highly customizable Java in-memory webshell (memshell) generator supporting multiple middleware servers, frameworks, shell types, and out… | 37 | 2230 | active |
| DanOps-1/Gpt-Agreement-Payment A Python toolkit that reverse-engineers and replays the end-to-end ChatGPT Plus/Team/Pro subscription payment flow (Stripe Checkout, PayPal… | 53 | 2225 | active |
| zakirkun/deep-eye Deep Eye is an AI-driven penetration testing CLI that orchestrates multiple LLM providers (OpenAI, Claude, Gemini, OLLAMA, Groq, and others… | 68 | 2219 | active |
| punk-security/dnsReaper DNS Reaper is a Python CLI tool that scans DNS records for subdomain takeover vulnerabilities using over 50 signatures, at roughly 50 subdo… | 58 | 2216 | active |
| eeeeeeeeee-code/e0e1-wx A Windows GUI tool (PySide6, Python 3.10+) for analyzing and penetration-testing WeChat mini-programs locally. It automates mini-program pa… | 80 | 2214 | active |
| kismetwireless/kismet Kismet is a wireless network detector, sniffer, and intrusion detection system for Wi-Fi, Bluetooth, SDR, and other wireless protocols. It … | 77 | 2210 | active |
| login-securite/lsassy Lsassy is a Python CLI tool that remotely extracts credentials from the LSASS process memory of Windows hosts over the network. It uses imp… | 71 | 2210 | active |
| lefayjey/linWinPwn linWinPwn is a bash script that wraps and streamlines a large set of Active Directory penetration testing tools such as impacket, bloodhoun… | 77 | 2200 | active |
| bytecode77/r77-rootkit r77 is a fileless ring 3 (userland) rootkit for Windows that hides files, processes, registry keys, services, and network connections using… | 75 | 2191 | active |
| ZerBea/hcxdumptool hcxdumptool is a C-based command-line tool that captures packets from WLAN devices and runs layer 2 attacks against the WPA protocol to fin… | 79 | 2184 | active |
| mandiant/flare-fakenet-ng FakeNet-NG is a dynamic network analysis tool that intercepts and redirects network traffic while simulating legitimate network services. I… | 63 | 2183 | active |
| 0vercl0k/rp rp++ is a fast C++ command-line tool that finds ROP (Return-Oriented Programming) gadgets in PE, ELF, and Mach-O binaries for x86, x64, ARM… | 44 | 2180 | active |
| zmap/zgrab2 ZGrab2 is a fast, modular application-layer network scanner written in Go, designed for large Internet-wide surveys in tandem with ZMap. It… | 75 | 2167 | active |
| zhzyker/dismap Dismap is a Go-based asset discovery and identification tool that fingerprints web, TCP, UDP, and TLS services using a rule base of 4500+ w… | 23 | 2163 | active |
| dronesploit/dronesploit DroneSploit is a Metasploit-style console framework for pentesting commercial drones, built on sploitkit. It gathers drone-focused hacking … | 23 | 2161 | active |
| ffffffff0x/f8x f8x is a Bash-based automation deployment script that installs 100+ security and development tools for red team, blue team, CTF, and cloud-… | 65 | 2156 | active |
| vulhub/java-chains Java Chains is a self-hosted web platform for generating Java exploitation payloads, aimed at security researchers. It supports common Java… | 89 | 2152 | active |
| bit4woo/domain_hunter_pro Domain Hunter Pro is a Burp Suite plugin (Java jar) for automated domain and subdomain collection, web title fetching, and target managemen… | 63 | 2145 | active |
| fortra/nanodump NanoDump is a C-based tool that creates minidumps of the Windows LSASS process using a variety of stealthy handle-acquisition and dumping t… | 32 | 2137 | active |