domain: penetration-testing
1317 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| nettitude/PoshC2 PoshC2 is a proxy-aware Command and Control (C2) framework written in Python3 that aids penetration testers with red teaming, post-exploita… | 47 | 2132 | active |
| phra/PEzor PEzor is an open-source shellcode and PE packer that wraps executables or raw shellcode into new binaries with evasion features like unhook… | 32 | 2129 | active |
| chainreactors/gogo gogo is a high-performance, highly configurable automated scanning engine written in pure Go for red team operations. It combines port scan… | 91 | 2118 | active |
| hannob/snallygaster Snallygaster is a Python command-line scanner that probes HTTP servers for files that should not be publicly accessible, such as exposed gi… | 54 | 2110 | active |
| haccer/subjack Subjack is a DNS takeover scanner written in Go that concurrently scans lists of subdomains to identify ones vulnerable to hijacking. It de… | 87 | 2109 | active |
| virtualabs/btlejack BtleJack is a Python CLI tool for sniffing, jamming, and hijacking Bluetooth Low Energy (BLE) connections. It relies on BBC Micro:Bit, Blue… | 23 | 2107 | active |
| Wifite Wifite is a Python command-line tool that automates wireless network security auditing by running existing tools like the Aircrack-ng suite… | 66 | 8084 | maintenance |
| defparam/smuggler Smuggler is a Python 3 command-line tool that tests web servers and proxies for HTTP request smuggling and desync vulnerabilities. It fires… | 32 | 2093 | active |
| Sh1Yo/x8 x8 is a hidden parameter discovery suite written in Rust for security testing of web applications. It brute-forces parameter names against … | 23 | 2093 | active |
| hanc00l/nemo_go Nemo is an automated information-gathering platform for penetration testing that integrates common recon tools (Masscan, Nmap, Subfinder, H… | 88 | 2086 | active |
| rebootuser/LinEnum LinEnum is a shell script that performs scripted local Linux enumeration and privilege escalation checks. It gathers system, user, network,… | 32 | 8012 | maintenance |
| SamueleAmato/sosec sosec is a Python command-line toolkit with a terminal UI for automated credential testing and HTTP request orchestration against social me… | 63 | 2065 | active |
| lukechilds/reverse-shell A hosted service (reverse-shell.sh) that generates reverse shell payloads on demand; piping its URL output into sh on a target spawns a she… | 63 | 2055 | active |
| berdav/CVE-2021-4034 A proof-of-concept exploit and vulnerability checker for CVE-2021-4034 (PwnKit), a polkit pkexec local privilege escalation vulnerability i… | 32 | 2048 | stable |
| ine-labs/AWSGoat AWSGoat is a deliberately vulnerable AWS infrastructure deployed via Terraform, featuring OWASP Top 10 web vulnerabilities and cloud miscon… | 42 | 2044 | active |
| CyberStrikeus/CyberStrike CyberStrike is an open-source AI-powered offensive security harness that runs automated penetration testing from the terminal. It orchestra… | 81 | 2043 | active |
| brightio/penelope Penelope is a modern reverse shell handler for penetration testers and CTF players, serving as a more capable alternative to basic netcat l… | 92 | 2031 | active |
| GhostPack/Certify Certify is a C# command-line tool for enumerating and abusing misconfigurations in Active Directory Certificate Services (AD CS). It was re… | 76 | 2023 | active |
| sc0tfree/mentalist Mentalist is a graphical Python tool for generating custom password wordlists based on common human password-construction patterns. It can … | 63 | 2021 | active |
| wyzxxz/jndi_tool A Java-based JNDI exploitation tool that runs malicious RMI/LDAP reference servers to test and exploit JNDI injection vulnerabilities, incl… | 32 | 2021 | active |
| ASHWIN990/ADB-Toolkit ADB-Toolkit is a Bash script wrapping the Android Debug Bridge with 28 options plus a Metasploit section for testing and exploiting Android… | 23 | 2016 | active |
| bitbrute/evillimiter A Python command-line tool that monitors, analyzes, and limits the bandwidth of devices on a local network using ARP spoofing and traffic s… | 56 | 2007 | active |
| shivaya-dav/DogeRat DogeRat is a Telegram-controlled Android remote access tool (RAT) consisting of a Node.js/Express/Socket.IO server and a Kotlin Android APK… | 42 | 2005 | active |
| EgeBalci/sgn SGN is a polymorphic binary encoder that encodes shellcode using an additive feedback loop similar to an LFSR, producing statically undetec… | 91 | 2003 | active |
| t6x/reaver-wps-fork-t6x Reaver is a C-based command-line tool that performs brute force attacks against Wi-Fi Protected Setup (WPS) registrar PINs to recover WPA/W… | 45 | 1981 | active |
| msoedov/agentic_security Agentic Security is an open-source LLM vulnerability scanner and AI red-teaming toolkit that probes large language models and agent workflo… | 87 | 1977 | active |
| cifertech/nRFBox nRFBox is an open-source ESP32-based handheld tool that scans, analyzes, jams, and spoofs BLE, Wi-Fi, and 2.4GHz signals using an nRF24L01 … | 73 | 1971 | active |
| MichaelGrafnetter/DSInternals DSInternals is a PowerShell module and .NET framework for working with Active Directory internals, including offline NTDS.DIT database pars… | 92 | 1967 | active |
| bit4woo/knife Knife is a Burp Suite extension written in Java that adds useful right-click context menu functions to improve penetration testing workflow… | 63 | 1963 | active |
| intruder-io/autoswagger Autoswagger is a Python command-line tool that discovers Swagger/OpenAPI specifications, parses their endpoints, and automatically tests th… | 34 | 1960 | active |
| kkbo8005/mitan Mitan (密探) is an all-in-one penetration testing and security assessment desktop application integrating asset mapping, subdomain brute-forc… | 79 | 1955 | active |
| owtf/owtf OWASP OWTF (Offensive Web Testing Framework) is a penetration testing framework that unites multiple security tools and aligns testing work… | 67 | 1949 | active |
| f0ng/captcha-killer-modified A modified version of the captcha-killer Burp Suite extension that intercepts captcha images from HTTP responses and recognizes them using … | 41 | 1948 | active |
| ys1231/MoveCertificate A Magisk/KernelSU/APatch root module that moves user-installed certificates into Android's system CA store, supporting Android 7 through 16… | 98 | 1947 | active |
| Ragnt/AngryOxide AngryOxide is an 802.11 WiFi attack tool written in Rust that provides a single-interface survey capability with automated attacks to captu… | 70 | 1945 | active |
| vxunderground/VX-API VX-API is a C++ collection of functions implementing malicious functionality to aid in malware development, maintained by vx-underground. I… | 32 | 1938 | active |
| evilsocket/legba Legba is a fast, multiprotocol credentials bruteforcer, password sprayer, and enumerator written in Rust on top of the Tokio async runtime.… | 84 | 1934 | active |
| bee-san/pyWhat pyWhat is a Python CLI tool that identifies what arbitrary text, files, or pcap network captures contain - emails, IP addresses, API keys, … | 23 | 7313 | maintenance |
| SleepingBag945/dddd dddd is a Go-based batch information gathering and supply-chain vulnerability detection CLI tool designed to streamline red team workflows.… | 19 | 1924 | active |
| joaoviictorti/RustRedOps RustRedOps is a collection of red team tools and technique implementations written in Rust, primarily targeting Windows. It provides workin… | 53 | 1900 | active |
| netero1010/EDRSilencer A C-based Windows command-line tool that uses Windows Filtering Platform (WFP) APIs to block outbound traffic of running EDR agents, preven… | 17 | 1899 | active |
| GhostManager/Ghostwriter Ghostwriter is an open-source Django-based platform from SpecterOps for managing offensive security engagements, including client/project t… | 94 | 1893 | active |
| liamg/traitor Traitor is a Go-based CLI tool that automatically exploits common Linux misconfigurations and known vulnerabilities (GTFOBins, pwnkit, dirt… | 23 | 7160 | maintenance |
| sleeyax/burp-awesome-tls A Burp Suite extension that hijacks Burp's HTTP and TLS stack to spoof any browser's TLS fingerprint (JA3). It helps evade WAF bot detectio… | 89 | 1889 | active |
| federicodotta/Brida Brida is a Burp Suite extension that bridges Burp Suite and Frida, letting testers invoke and manipulate an application's own methods while… | 49 | 1889 | active |
| evildevill/instahack Instahack is a Bash and Python-based brute-force tool for testing Instagram account password strength, routing traffic through Tor for anon… | 62 | 1888 | active |
| pentestfunctions/BlueDucky BlueDucky is a Python tool that exploits CVE-2023-45866, an unauthenticated Bluetooth peering vulnerability, to execute keystroke injection… | 56 | 1888 | active |
| nsonaniya2010/SubDomainizer SubDomainizer is a Python CLI tool that discovers hidden subdomains and secrets in webpages, external JavaScript files, GitHub, and local f… | 66 | 1886 | active |
| niklasb/libc-database A shell-based tool that builds a searchable database of libc symbol offsets from Ubuntu, Debian, and other distributions to simplify binary… | 75 | 1869 | active |
| emsec/ChameleonMini ChameleonMini is a freely programmable, portable NFC device that can emulate and clone contactless smartcards, read RFID tags, and sniff/lo… | 23 | 1869 | active |
| trustedsec/CS-Situational-Awareness-BOF A collection of situational awareness commands implemented as Cobalt Strike Beacon Object Files (BOFs) in C, letting operators run low-foot… | 97 | 1868 | active |
| 0xKayala/NucleiFuzzer NucleiFuzzer is a Python-based automation tool that combines URL discovery tools (ParamSpider, Waybackurls, Gauplus, Hakrawler, Katana) wit… | 66 | 1862 | active |
| trustedsec/hate_crack hate_crack is a Python tool by TrustedSec that automates password cracking methodologies on top of Hashcat, orchestrating wordlists, masks,… | 95 | 1854 | active |
| zakirkun/guardian-cli Guardian is a Python CLI tool that automates penetration testing workflows using LLM providers (OpenAI, Claude, Gemini, Ollama, and others)… | 69 | 1853 | active |
| selinuxG/Golin Golin is a Go-based security assessment tool combining asset discovery, port/service scanning, weak password brute-forcing for 40+ services… | 66 | 1847 | active |
| wapiti-scanner/wapiti Wapiti is an open-source black-box web vulnerability scanner written in Python that crawls deployed web applications and fuzzes scripts and… | 98 | 1846 | active |
| devploit/nomore403 NoMore403 is a Go command-line tool that automates testing of HTTP 401/403 access-control bypasses via request path, method, header, and wi… | 87 | 1842 | active |
| pandasec888/taowu-cobalt_strike Taowu is a red team automation plugin (Aggressor script) for the Cobalt Strike platform, bundling a large collection of post-exploitation m… | 56 | 1835 | active |
| 78778443/QingScan QingScan is a self-hosted, open-source security operations platform that unifies vulnerability scanning, code auditing, asset inventory, an… | 66 | 1831 | active |
| bvcyber/CVE-2020-1472 A Python CLI script that tests domain controllers for the ZeroLogon vulnerability (CVE-2020-1472) using the Impacket library. It attempts t… | 45 | 1830 | stable |
| White-hua/Apt_t00ls A Java-based exploitation tool that aggregates proof-of-concept and weaponized exploits for high-severity vulnerabilities in Chinese enterp… | 26 | 1830 | active |
| initstring/linkedin2username A Python OSINT tool that scrapes LinkedIn employee lists for a target company and generates multiple probable username formats (e.g., first… | 76 | 1825 | active |
| 1N3/BlackWidow BlackWidow is a Python-based web application spider that crawls a target site to collect URLs, dynamic parameters, subdomains, email addres… | 57 | 1821 | active |
| vulnersCom/getsploit A Python command-line tool that searches and downloads public exploits from the Vulners database, aggregating sources like Exploit-DB, Meta… | 90 | 1813 | active |
| tdragon6/Supershell Supershell is a web-accessible C2 remote control platform that establishes reverse SSH tunnels to targets, yielding fully interactive shell… | 54 | 1810 | active |
| wagiro/BurpBounty Burp Bounty (Scan Check Builder) is a Burp Suite extension that lets users improve Burp's active and passive web vulnerability scanners wit… | 23 | 1809 | active |
| mschwager/fierce Fierce is a Python 3 DNS reconnaissance tool that locates non-contiguous IP space and hostnames for specified domains. It enumerates subdom… | 32 | 1808 | active |
| hashtopolis/server Hashtopolis is a multi-platform client-server application for distributing hashcat password cracking tasks across multiple computers. It pr… | 90 | 1802 | active |
| doyensec/inql InQL is an open-source Burp Suite extension for advanced GraphQL security testing. It provides schema introspection, vulnerability detectio… | 76 | 1801 | active |
| wgpsec/fofa_viewer Fofa Viewer is a JavaFX desktop client for the FOFA internet asset search engine, wrapping its API in a tabbed GUI. It helps security profe… | 57 | 1800 | active |
| wallarm/gotestwaf GoTestWAF is a Go-based tool that simulates OWASP and API attacks (SQL injection, XSS, etc.) across REST, GraphQL, gRPC, SOAP, and XMLRPC p… | 41 | 1799 | active |
| PortSwigger/turbo-intruder Turbo Intruder is a Burp Suite extension for sending large numbers of HTTP requests at exceptional speed and analyzing the results. It uses… | 66 | 1796 | active |
| 0vercl0k/wtf wtf (what the fuzz) is a distributed, code-coverage guided, snapshot-based fuzzer for attacking user- and kernel-mode targets on Windows an… | 74 | 1793 | active |
| R4gd0ll/I-Wanna-Get-All A comprehensive Java post-exploitation vulnerability exploitation tool integrating 470 exploit modules for detection and attack of known vu… | 59 | 1787 | active |
| ReversecLabs/C3 C3 (Custom Command and Control) is a C++ framework for rapidly prototyping custom command and control (C2) channels for red team operations… | 67 | 1785 | active |
| kost/dvcs-ripper dvcs-ripper is a set of Perl command-line tools that download (rip) web-accessible version control repositories such as GIT, SVN, Mercurial… | 32 | 1784 | stable |
| D4Vinci/One-Lin3r One-Lin3r is a lightweight, modular Python framework that provides a searchable database of over 176 one-liner commands for penetration tes… | 57 | 1783 | active |
| GoSecure/pyrdp PyRDP is a Python Remote Desktop Protocol (RDP) Monster-in-the-Middle (MITM) tool and library. It intercepts RDP connections to capture cre… | 60 | 1780 | active |
| ron190/jsql-injection jSQL Injection is a free, open-source Java application for automatic SQL database injection, used to find and extract database information … | 84 | 1776 | active |
| quentinhardy/odat ODAT (Oracle Database Attacking Tool) is an open-source Python penetration testing tool for assessing the security of remote Oracle Databas… | 57 | 1776 | active |
| j3ers3/Hello-Java-Sec A deliberately vulnerable Java Spring Boot application demonstrating common web vulnerabilities (SQLi, XSS, RCE, deserialization, SSTI, SSR… | 27 | 1763 | active |
| xaitax/Chrome-App-Bound-Encryption-Decryption A Windows post-exploitation research tool that bypasses Chromium's App-Bound Encryption using direct syscall-based reflective process hollo… | 63 | 1762 | active |
| qi4L/JYso JYso is a Java-based offensive security tool that combines the capabilities of ysoserial (Java deserialization gadget generation) and JNDIE… | 83 | 1761 | active |
| xmendez/wfuzz Wfuzz is a Python-based command-line web application fuzzer that replaces a FUZZ keyword in HTTP requests with values from configurable pay… | 60 | 6558 | maintenance |
| IvanGlinkin/Fast-Google-Dorks-Scan A shell-based OSINT tool that automates Google dork searches against a target website to uncover admin panels, exposed file types, and path… | 46 | 1742 | active |
| jm33-m0/emp3r0r emp3r0r is an open-source post-exploitation framework and command-and-control (C2) system written in Go, targeting Linux and Windows hosts.… | 95 | 1741 | active |
| wiire-a/pixiewps Pixiewps is a C command-line utility that brute-forces Wi-Fi Protected Setup (WPS) PINs offline, exploiting low- or non-entropy software im… | 57 | 1740 | active |
| samyk/poisontap PoisonTap is a USB-based attack tool built on a Raspberry Pi Zero and Node.js that exploits locked, password-protected computers by emulati… | 32 | 6475 | maintenance |
| MatheuZSecurity/Singularity Singularity is a stealthy Linux kernel module (LKM) rootkit targeting modern 6.x kernels, using ftrace-based syscall hooking to hide proces… | 56 | 1736 | active |
| j3ssie/metabigor Metabigor is a Go-based command-line OSINT tool that maps a target's infrastructure—IP ranges, subdomains, related domains, open ports, and… | 86 | 1735 | active |
| mandatoryprogrammer/CursedChrome CursedChrome is a Chrome extension implant that converts a victim's Chrome browser into a fully-functional HTTP proxy, letting an operator … | 32 | 1728 | active |
| S3cur3Th1sSh1t/PowerSharpPack PowerSharpPack wraps many useful offensive C# security projects (Seatbelt, Rubeus, SharpUp, winPEAS, etc.) into PowerShell scripts for easy… | 39 | 1708 | active |
| dolevf/Damn-Vulnerable-GraphQL-Application Damn Vulnerable GraphQL Application (DVGA) is an intentionally insecure GraphQL service built for learning and practicing GraphQL security … | 33 | 1705 | active |
| SiriusScan/Sirius Sirius is an open-source vulnerability scanner that automates network discovery via Nmap and performs CVE-based detection with CVSS scoring… | 88 | 1695 | active |
| dafthack/MFASweep MFASweep is a PowerShell script that attempts to log in to multiple Microsoft services with provided credentials to detect whether MFA is e… | 67 | 1692 | active |
| BC-SECURITY/Starkiller Starkiller is a web-based graphical frontend for PowerShell Empire, a post-exploitation C2 framework. It is written in VueJS and ships prep… | 93 | 1684 | active |
| whwlsfb/JDumpSpider JDumpSpider is a Java CLI tool that extracts sensitive information (datasource credentials, config properties, Redis configs, Shiro keys, u… | 70 | 1680 | active |
| MorDavid/BruteForceAI BruteForceAI is a Python-based penetration testing tool that uses LLMs (via Ollama or Groq) to automatically analyze login page HTML and id… | 60 | 1677 | active |
| rebeyond/Behinder Behinder ('冰蝎') is a cross-platform Java client for managing encrypted webshells on compromised web servers running PHP, Java, or .NET. It … | 23 | 6191 | maintenance |
| WangYihang/GitHacker GitHacker is a multi-threaded Python CLI tool that exploits exposed `.git` directories on web servers to reconstruct the entire Git reposit… | 77 | 1664 | active |