Ross ROSS = Recommend OSS · open-source software intelligence for agents

domain: penetration-testing

1317 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
nettitude/PoshC2
PoshC2 is a proxy-aware Command and Control (C2) framework written in Python3 that aids penetration testers with red teaming, post-exploita…
472132active
phra/PEzor
PEzor is an open-source shellcode and PE packer that wraps executables or raw shellcode into new binaries with evasion features like unhook…
322129active
chainreactors/gogo
gogo is a high-performance, highly configurable automated scanning engine written in pure Go for red team operations. It combines port scan…
912118active
hannob/snallygaster
Snallygaster is a Python command-line scanner that probes HTTP servers for files that should not be publicly accessible, such as exposed gi…
542110active
haccer/subjack
Subjack is a DNS takeover scanner written in Go that concurrently scans lists of subdomains to identify ones vulnerable to hijacking. It de…
872109active
virtualabs/btlejack
BtleJack is a Python CLI tool for sniffing, jamming, and hijacking Bluetooth Low Energy (BLE) connections. It relies on BBC Micro:Bit, Blue…
232107active
Wifite
Wifite is a Python command-line tool that automates wireless network security auditing by running existing tools like the Aircrack-ng suite…
668084maintenance
defparam/smuggler
Smuggler is a Python 3 command-line tool that tests web servers and proxies for HTTP request smuggling and desync vulnerabilities. It fires…
322093active
Sh1Yo/x8
x8 is a hidden parameter discovery suite written in Rust for security testing of web applications. It brute-forces parameter names against …
232093active
hanc00l/nemo_go
Nemo is an automated information-gathering platform for penetration testing that integrates common recon tools (Masscan, Nmap, Subfinder, H…
882086active
rebootuser/LinEnum
LinEnum is a shell script that performs scripted local Linux enumeration and privilege escalation checks. It gathers system, user, network,…
328012maintenance
SamueleAmato/sosec
sosec is a Python command-line toolkit with a terminal UI for automated credential testing and HTTP request orchestration against social me…
632065active
lukechilds/reverse-shell
A hosted service (reverse-shell.sh) that generates reverse shell payloads on demand; piping its URL output into sh on a target spawns a she…
632055active
berdav/CVE-2021-4034
A proof-of-concept exploit and vulnerability checker for CVE-2021-4034 (PwnKit), a polkit pkexec local privilege escalation vulnerability i…
322048stable
ine-labs/AWSGoat
AWSGoat is a deliberately vulnerable AWS infrastructure deployed via Terraform, featuring OWASP Top 10 web vulnerabilities and cloud miscon…
422044active
CyberStrikeus/CyberStrike
CyberStrike is an open-source AI-powered offensive security harness that runs automated penetration testing from the terminal. It orchestra…
812043active
brightio/penelope
Penelope is a modern reverse shell handler for penetration testers and CTF players, serving as a more capable alternative to basic netcat l…
922031active
GhostPack/Certify
Certify is a C# command-line tool for enumerating and abusing misconfigurations in Active Directory Certificate Services (AD CS). It was re…
762023active
sc0tfree/mentalist
Mentalist is a graphical Python tool for generating custom password wordlists based on common human password-construction patterns. It can …
632021active
wyzxxz/jndi_tool
A Java-based JNDI exploitation tool that runs malicious RMI/LDAP reference servers to test and exploit JNDI injection vulnerabilities, incl…
322021active
ASHWIN990/ADB-Toolkit
ADB-Toolkit is a Bash script wrapping the Android Debug Bridge with 28 options plus a Metasploit section for testing and exploiting Android…
232016active
bitbrute/evillimiter
A Python command-line tool that monitors, analyzes, and limits the bandwidth of devices on a local network using ARP spoofing and traffic s…
562007active
shivaya-dav/DogeRat
DogeRat is a Telegram-controlled Android remote access tool (RAT) consisting of a Node.js/Express/Socket.IO server and a Kotlin Android APK…
422005active
EgeBalci/sgn
SGN is a polymorphic binary encoder that encodes shellcode using an additive feedback loop similar to an LFSR, producing statically undetec…
912003active
t6x/reaver-wps-fork-t6x
Reaver is a C-based command-line tool that performs brute force attacks against Wi-Fi Protected Setup (WPS) registrar PINs to recover WPA/W…
451981active
msoedov/agentic_security
Agentic Security is an open-source LLM vulnerability scanner and AI red-teaming toolkit that probes large language models and agent workflo…
871977active
cifertech/nRFBox
nRFBox is an open-source ESP32-based handheld tool that scans, analyzes, jams, and spoofs BLE, Wi-Fi, and 2.4GHz signals using an nRF24L01 …
731971active
MichaelGrafnetter/DSInternals
DSInternals is a PowerShell module and .NET framework for working with Active Directory internals, including offline NTDS.DIT database pars…
921967active
bit4woo/knife
Knife is a Burp Suite extension written in Java that adds useful right-click context menu functions to improve penetration testing workflow…
631963active
intruder-io/autoswagger
Autoswagger is a Python command-line tool that discovers Swagger/OpenAPI specifications, parses their endpoints, and automatically tests th…
341960active
kkbo8005/mitan
Mitan (密探) is an all-in-one penetration testing and security assessment desktop application integrating asset mapping, subdomain brute-forc…
791955active
owtf/owtf
OWASP OWTF (Offensive Web Testing Framework) is a penetration testing framework that unites multiple security tools and aligns testing work…
671949active
f0ng/captcha-killer-modified
A modified version of the captcha-killer Burp Suite extension that intercepts captcha images from HTTP responses and recognizes them using …
411948active
ys1231/MoveCertificate
A Magisk/KernelSU/APatch root module that moves user-installed certificates into Android's system CA store, supporting Android 7 through 16…
981947active
Ragnt/AngryOxide
AngryOxide is an 802.11 WiFi attack tool written in Rust that provides a single-interface survey capability with automated attacks to captu…
701945active
vxunderground/VX-API
VX-API is a C++ collection of functions implementing malicious functionality to aid in malware development, maintained by vx-underground. I…
321938active
evilsocket/legba
Legba is a fast, multiprotocol credentials bruteforcer, password sprayer, and enumerator written in Rust on top of the Tokio async runtime.…
841934active
bee-san/pyWhat
pyWhat is a Python CLI tool that identifies what arbitrary text, files, or pcap network captures contain - emails, IP addresses, API keys, …
237313maintenance
SleepingBag945/dddd
dddd is a Go-based batch information gathering and supply-chain vulnerability detection CLI tool designed to streamline red team workflows.…
191924active
joaoviictorti/RustRedOps
RustRedOps is a collection of red team tools and technique implementations written in Rust, primarily targeting Windows. It provides workin…
531900active
netero1010/EDRSilencer
A C-based Windows command-line tool that uses Windows Filtering Platform (WFP) APIs to block outbound traffic of running EDR agents, preven…
171899active
GhostManager/Ghostwriter
Ghostwriter is an open-source Django-based platform from SpecterOps for managing offensive security engagements, including client/project t…
941893active
liamg/traitor
Traitor is a Go-based CLI tool that automatically exploits common Linux misconfigurations and known vulnerabilities (GTFOBins, pwnkit, dirt…
237160maintenance
sleeyax/burp-awesome-tls
A Burp Suite extension that hijacks Burp's HTTP and TLS stack to spoof any browser's TLS fingerprint (JA3). It helps evade WAF bot detectio…
891889active
federicodotta/Brida
Brida is a Burp Suite extension that bridges Burp Suite and Frida, letting testers invoke and manipulate an application's own methods while…
491889active
evildevill/instahack
Instahack is a Bash and Python-based brute-force tool for testing Instagram account password strength, routing traffic through Tor for anon…
621888active
pentestfunctions/BlueDucky
BlueDucky is a Python tool that exploits CVE-2023-45866, an unauthenticated Bluetooth peering vulnerability, to execute keystroke injection…
561888active
nsonaniya2010/SubDomainizer
SubDomainizer is a Python CLI tool that discovers hidden subdomains and secrets in webpages, external JavaScript files, GitHub, and local f…
661886active
niklasb/libc-database
A shell-based tool that builds a searchable database of libc symbol offsets from Ubuntu, Debian, and other distributions to simplify binary…
751869active
emsec/ChameleonMini
ChameleonMini is a freely programmable, portable NFC device that can emulate and clone contactless smartcards, read RFID tags, and sniff/lo…
231869active
trustedsec/CS-Situational-Awareness-BOF
A collection of situational awareness commands implemented as Cobalt Strike Beacon Object Files (BOFs) in C, letting operators run low-foot…
971868active
0xKayala/NucleiFuzzer
NucleiFuzzer is a Python-based automation tool that combines URL discovery tools (ParamSpider, Waybackurls, Gauplus, Hakrawler, Katana) wit…
661862active
trustedsec/hate_crack
hate_crack is a Python tool by TrustedSec that automates password cracking methodologies on top of Hashcat, orchestrating wordlists, masks,…
951854active
zakirkun/guardian-cli
Guardian is a Python CLI tool that automates penetration testing workflows using LLM providers (OpenAI, Claude, Gemini, Ollama, and others)…
691853active
selinuxG/Golin
Golin is a Go-based security assessment tool combining asset discovery, port/service scanning, weak password brute-forcing for 40+ services…
661847active
wapiti-scanner/wapiti
Wapiti is an open-source black-box web vulnerability scanner written in Python that crawls deployed web applications and fuzzes scripts and…
981846active
devploit/nomore403
NoMore403 is a Go command-line tool that automates testing of HTTP 401/403 access-control bypasses via request path, method, header, and wi…
871842active
pandasec888/taowu-cobalt_strike
Taowu is a red team automation plugin (Aggressor script) for the Cobalt Strike platform, bundling a large collection of post-exploitation m…
561835active
78778443/QingScan
QingScan is a self-hosted, open-source security operations platform that unifies vulnerability scanning, code auditing, asset inventory, an…
661831active
bvcyber/CVE-2020-1472
A Python CLI script that tests domain controllers for the ZeroLogon vulnerability (CVE-2020-1472) using the Impacket library. It attempts t…
451830stable
White-hua/Apt_t00ls
A Java-based exploitation tool that aggregates proof-of-concept and weaponized exploits for high-severity vulnerabilities in Chinese enterp…
261830active
initstring/linkedin2username
A Python OSINT tool that scrapes LinkedIn employee lists for a target company and generates multiple probable username formats (e.g., first…
761825active
1N3/BlackWidow
BlackWidow is a Python-based web application spider that crawls a target site to collect URLs, dynamic parameters, subdomains, email addres…
571821active
vulnersCom/getsploit
A Python command-line tool that searches and downloads public exploits from the Vulners database, aggregating sources like Exploit-DB, Meta…
901813active
tdragon6/Supershell
Supershell is a web-accessible C2 remote control platform that establishes reverse SSH tunnels to targets, yielding fully interactive shell…
541810active
wagiro/BurpBounty
Burp Bounty (Scan Check Builder) is a Burp Suite extension that lets users improve Burp's active and passive web vulnerability scanners wit…
231809active
mschwager/fierce
Fierce is a Python 3 DNS reconnaissance tool that locates non-contiguous IP space and hostnames for specified domains. It enumerates subdom…
321808active
hashtopolis/server
Hashtopolis is a multi-platform client-server application for distributing hashcat password cracking tasks across multiple computers. It pr…
901802active
doyensec/inql
InQL is an open-source Burp Suite extension for advanced GraphQL security testing. It provides schema introspection, vulnerability detectio…
761801active
wgpsec/fofa_viewer
Fofa Viewer is a JavaFX desktop client for the FOFA internet asset search engine, wrapping its API in a tabbed GUI. It helps security profe…
571800active
wallarm/gotestwaf
GoTestWAF is a Go-based tool that simulates OWASP and API attacks (SQL injection, XSS, etc.) across REST, GraphQL, gRPC, SOAP, and XMLRPC p…
411799active
PortSwigger/turbo-intruder
Turbo Intruder is a Burp Suite extension for sending large numbers of HTTP requests at exceptional speed and analyzing the results. It uses…
661796active
0vercl0k/wtf
wtf (what the fuzz) is a distributed, code-coverage guided, snapshot-based fuzzer for attacking user- and kernel-mode targets on Windows an…
741793active
R4gd0ll/I-Wanna-Get-All
A comprehensive Java post-exploitation vulnerability exploitation tool integrating 470 exploit modules for detection and attack of known vu…
591787active
ReversecLabs/C3
C3 (Custom Command and Control) is a C++ framework for rapidly prototyping custom command and control (C2) channels for red team operations…
671785active
kost/dvcs-ripper
dvcs-ripper is a set of Perl command-line tools that download (rip) web-accessible version control repositories such as GIT, SVN, Mercurial…
321784stable
D4Vinci/One-Lin3r
One-Lin3r is a lightweight, modular Python framework that provides a searchable database of over 176 one-liner commands for penetration tes…
571783active
GoSecure/pyrdp
PyRDP is a Python Remote Desktop Protocol (RDP) Monster-in-the-Middle (MITM) tool and library. It intercepts RDP connections to capture cre…
601780active
ron190/jsql-injection
jSQL Injection is a free, open-source Java application for automatic SQL database injection, used to find and extract database information …
841776active
quentinhardy/odat
ODAT (Oracle Database Attacking Tool) is an open-source Python penetration testing tool for assessing the security of remote Oracle Databas…
571776active
j3ers3/Hello-Java-Sec
A deliberately vulnerable Java Spring Boot application demonstrating common web vulnerabilities (SQLi, XSS, RCE, deserialization, SSTI, SSR…
271763active
xaitax/Chrome-App-Bound-Encryption-Decryption
A Windows post-exploitation research tool that bypasses Chromium's App-Bound Encryption using direct syscall-based reflective process hollo…
631762active
qi4L/JYso
JYso is a Java-based offensive security tool that combines the capabilities of ysoserial (Java deserialization gadget generation) and JNDIE…
831761active
xmendez/wfuzz
Wfuzz is a Python-based command-line web application fuzzer that replaces a FUZZ keyword in HTTP requests with values from configurable pay…
606558maintenance
IvanGlinkin/Fast-Google-Dorks-Scan
A shell-based OSINT tool that automates Google dork searches against a target website to uncover admin panels, exposed file types, and path…
461742active
jm33-m0/emp3r0r
emp3r0r is an open-source post-exploitation framework and command-and-control (C2) system written in Go, targeting Linux and Windows hosts.…
951741active
wiire-a/pixiewps
Pixiewps is a C command-line utility that brute-forces Wi-Fi Protected Setup (WPS) PINs offline, exploiting low- or non-entropy software im…
571740active
samyk/poisontap
PoisonTap is a USB-based attack tool built on a Raspberry Pi Zero and Node.js that exploits locked, password-protected computers by emulati…
326475maintenance
MatheuZSecurity/Singularity
Singularity is a stealthy Linux kernel module (LKM) rootkit targeting modern 6.x kernels, using ftrace-based syscall hooking to hide proces…
561736active
j3ssie/metabigor
Metabigor is a Go-based command-line OSINT tool that maps a target's infrastructure—IP ranges, subdomains, related domains, open ports, and…
861735active
mandatoryprogrammer/CursedChrome
CursedChrome is a Chrome extension implant that converts a victim's Chrome browser into a fully-functional HTTP proxy, letting an operator …
321728active
S3cur3Th1sSh1t/PowerSharpPack
PowerSharpPack wraps many useful offensive C# security projects (Seatbelt, Rubeus, SharpUp, winPEAS, etc.) into PowerShell scripts for easy…
391708active
dolevf/Damn-Vulnerable-GraphQL-Application
Damn Vulnerable GraphQL Application (DVGA) is an intentionally insecure GraphQL service built for learning and practicing GraphQL security …
331705active
SiriusScan/Sirius
Sirius is an open-source vulnerability scanner that automates network discovery via Nmap and performs CVE-based detection with CVSS scoring…
881695active
dafthack/MFASweep
MFASweep is a PowerShell script that attempts to log in to multiple Microsoft services with provided credentials to detect whether MFA is e…
671692active
BC-SECURITY/Starkiller
Starkiller is a web-based graphical frontend for PowerShell Empire, a post-exploitation C2 framework. It is written in VueJS and ships prep…
931684active
whwlsfb/JDumpSpider
JDumpSpider is a Java CLI tool that extracts sensitive information (datasource credentials, config properties, Redis configs, Shiro keys, u…
701680active
MorDavid/BruteForceAI
BruteForceAI is a Python-based penetration testing tool that uses LLMs (via Ollama or Groq) to automatically analyze login page HTML and id…
601677active
rebeyond/Behinder
Behinder ('冰蝎') is a cross-platform Java client for managing encrypted webshells on compromised web servers running PHP, Java, or .NET. It …
236191maintenance
WangYihang/GitHacker
GitHacker is a multi-threaded Python CLI tool that exploits exposed `.git` directories on web servers to reconstruct the entire Git reposit…
771664active

← prev page 4 / 14 next →