domain: penetration-testing
1317 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| summitt/Nope-Proxy NoPE Proxy is a Burp Suite extension that adds TCP and UDP traffic interception, a configurable DNS server, and a non-HTTP man-in-the-middl… | 23 | 1663 | active |
| longld/peda PEDA is a Python plugin for GDB that enhances the debugger's display and adds exploit development commands. It provides colorized disassemb… | 23 | 6147 | maintenance |
| dirkjanm/krbrelayx A Python toolkit for abusing Kerberos in Active Directory environments, including Kerberos relaying and unconstrained delegation attacks. I… | 64 | 1657 | active |
| WangYihang/Platypus Platypus is a cross-platform reverse-shell and host management hub written in Go. Agents on managed machines dial back to a central server … | 67 | 1656 | active |
| klezVirus/SysWhispers3 SysWhispers3 is a Python command-line tool that generates header and assembly (ASM) file pairs for direct system calls to the Windows kerne… | 32 | 1653 | active |
| whwlsfb/BurpCrypto BurpCrypto is a Burp Suite extension that encrypts Intruder payloads with algorithms like AES, RSA, and DES, or by executing arbitrary Java… | 23 | 1648 | active |
| cddmp/enum4linux-ng enum4linux-ng is a Python rewrite of the enum4linux.pl Windows/Samba enumeration tool, wrapping Samba utilities like nmblookup, net, rpccli… | 75 | 1644 | active |
| shekyan/slowhttptest SlowHTTPTest is a highly configurable command-line tool that simulates Application Layer Denial of Service attacks by prolonging HTTP conne… | 67 | 1644 | active |
| Pentest AI pentest-ai is an MIT-licensed local CLI and MCP server that turns Claude Code (or any LLM) into an offensive security assistant, pairing 50… | 80 | 1629 | active |
| JesseCHale/HaleHound-CYD HaleHound-CYD is a multi-protocol offensive security toolkit firmware for the ESP32 Cheap Yellow Display, offering 40+ attack modules acros… | 80 | 1623 | active |
| vladko312/SSTImap SSTImap is a Python-based penetration testing tool that automatically detects and exploits Server-Side Template Injection (SSTI) and code i… | 88 | 1621 | active |
| michenriksen/aquatone Aquatone is a Go CLI tool for visual inspection of websites across many hosts, taking screenshots via headless Chrome/Chromium and generati… | 10 | 5961 | maintenance |
| coffinxp/loxs Loxs is a Python-based multi-vulnerability scanner for web applications that detects SQL injection, XSS, LFI, open redirect, and CRLF injec… | 52 | 1612 | active |
| SecurityRiskAdvisors/VECTR VECTR is a self-hosted web application for tracking red and blue team testing activities to measure detection and prevention capabilities a… | 98 | 1611 | active |
| liamg/gitjacker Gitjacker is a Go CLI tool that downloads and reconstructs git repositories from websites where the .git directory has been mistakenly expo… | 48 | 1607 | active |
| repplus/rep-chrome rep+ is a Chrome DevTools extension inspired by Burp Suite's Repeater that captures and replays HTTP requests with modified methods, header… | 54 | 1603 | active |
| Orange-Cyberdefense/ocd-mindmaps A collection of interactive mindmaps from Orange Cyberdefense covering offensive security and penetration testing methodologies, published … | 37 | 1602 | active |
| 4lbH4cker/ALHacking ALHacking is a shell-script-based toolkit bundling a menu of so-called ethical hacking utilities, including social media account attacks, p… | 32 | 1601 | active |
| PentestPad/subzy Subzy is a Go-based command-line tool that checks subdomains for takeover vulnerabilities by matching HTTP response fingerprints from the c… | 32 | 1589 | active |
| Autumn-27/ScopeSentry ScopeSentry is a self-hosted attack surface and asset mapping platform that combines subdomain enumeration, port scanning, fingerprinting, … | 88 | 1587 | active |
| s0md3v/uro uro is a Python CLI tool that declutters URL lists for crawling and security testing without making any HTTP requests. It removes duplicate… | 29 | 1587 | stable |
| xnl-h4ck3r/xnLinkFinder xnLinkFinder is a Python CLI tool that discovers endpoints, potential parameters, target-specific wordlists, and secrets for a given target… | 78 | 1585 | active |
| m3n0sd0n4ld/GooFuzz GooFuzz is a Bash-based CLI tool that performs fuzzing-style reconnaissance using advanced Google searches (Google Dorking) via the Google … | 57 | 1585 | active |
| AlisamTechnology/ATSCAN ATSCAN is a Perl-based command-line scanner for mass dork searching and vulnerability exploitation. It combines search engine dorking with … | 23 | 1583 | active |
| m8sec/CrossLinked CrossLinked is a Python CLI tool that enumerates LinkedIn employee names for an organization by scraping search engine results, without nee… | 23 | 1582 | active |
| ReaJason/MemShellParty MemShellParty is a self-hosted, visual tool for rapidly generating Java memory shells (fileless webshells) for mainstream web middleware an… | 89 | 1581 | active |
| ultrasecurity/Storm-Breaker Storm-Breaker is a social engineering tool that generates phishing-style web pages to capture device information, location, webcam, and mic… | 32 | 5754 | maintenance |
| stealthcopter/deepce DEEPCE is a single-file pure-shell script for enumerating Docker environments and attempting privilege escalation and container escapes. It… | 58 | 1567 | active |
| wikiZ/RedGuard RedGuard is a C2 front flow control tool written in Go that acts as a filtering reverse proxy in front of command-and-control servers. It h… | 23 | 1567 | active |
| Tsojan/TsojanScan TsojanScan is an integrated BurpSuite plugin for vulnerability detection that bundles multiple common vulnerability POCs into a single exte… | 85 | 1563 | active |
| AD-Security/AD_Miner AD Miner is an Active Directory (on-premise and Entra ID) auditing tool that runs Cypher queries against a BloodHound Neo4j graph database … | 70 | 1562 | active |
| moom825/xeno-rat Xeno-RAT is an open-source remote access tool (RAT) written in C# for remotely controlling Windows 10/11 machines. It includes features suc… | 18 | 1562 | active |
| dwisiswant0/crlfuzz CRLFuzz is a fast command-line tool written in Go that scans websites for CRLF (carriage return/line feed) injection vulnerabilities. It su… | 66 | 1560 | active |
| OWASP/QRLJacking QRLJacking is an OWASP project documenting and exploiting the Quick Response Code Login Jacking attack vector, which hijacks user sessions … | 48 | 1559 | active |
| v-byte-cpu/sx sx is a fast, UNIX-philosophy command-line network scanner written in Go that supports ARP/NDP host discovery, ICMP, TCP SYN/FIN/NULL/Xmas,… | 83 | 1553 | active |
| Clats97/ClatScope ClatScope Info Tool is a Python-based OSINT utility offering 70+ reconnaissance features including geolocation, DNS, WHOIS, phone, email, a… | 48 | 1537 | active |
| xnl-h4ck3r/GAP-Burp-Extension GAP is a Burp Suite extension written in Python (Jython) that extracts potential endpoints, parameters, and links from Burp's site map, pro… | 66 | 1530 | active |
| BlackSnufkin/LitterBox LitterBox is a self-hosted payload-analysis sandbox for red teams that runs static, dynamic, and EDR-based analysis on samples and produces… | 62 | 1526 | active |
| nemesida-waf/waf-bypass WAF Bypass Tool is an open-source Python CLI tool that tests web application firewalls for false positives and false negatives using predef… | 83 | 1520 | active |
| gobysec/Goby Goby is a network security assessment tool that maps an organization's attack surface and scans for known vulnerabilities and weak password… | 23 | 1517 | active |
| overspace-labs/CaA CaA is a BurpSuite extension (Montoya API) that analyzes HTTP traffic to extract parameters, paths, files, and parameter values with freque… | 83 | 1516 | active |
| ztgrace/changeme changeme is a Python CLI tool that scans networks for devices and services using default or backdoor credentials. Credential definitions ar… | 36 | 1516 | active |
| webpwnized/mutillidae OWASP Mutillidae II is a deliberately vulnerable PHP web application used as a target for web-security training and practice. It includes o… | 72 | 1513 | active |
| blacklanternsecurity/writehat WriteHat is a self-hosted web application for generating penetration test reports, converting Markdown to HTML to PDF without Microsoft Wor… | 66 | 1513 | active |
| 0xsp-SRD/mortar Mortar Loader is a red team evasion tool that encrypts PE binaries and shellcode and executes them in memory using various injection techni… | 23 | 1508 | active |
| nikaiw/VMkatz VMkatz is a Rust CLI tool that extracts Windows credentials (NTLM hashes, DPAPI keys, Kerberos tickets, LSA secrets, BitLocker keys) direct… | 69 | 1507 | active |
| nikitastupin/clairvoyance Clairvoyance is a Python CLI tool that recovers a GraphQL API's schema even when introspection is disabled, by probing field and type names… | 57 | 1506 | active |
| Gowtham-Darkseid/AutoPentestX AutoPentestX is a Python-based automated penetration testing toolkit that scans targets for vulnerabilities and generates security reports.… | 45 | 1504 | active |
| assetnote/nowafpls nowafpls is a Jython-based Burp Suite plugin that bypasses web application firewalls (WAFs) by inserting junk data into HTTP request bodies… | 38 | 1502 | active |
| T4y1oR/RingQ RingQ is a post-exploitation antivirus evasion tool that obfuscates and loads arbitrary Windows executables or shellcode (e.g., Cobalt Stri… | 27 | 1497 | active |
| Meckazin/ChromeKatz ChromeKatz is a set of offensive security tools (CookieKatz, ElevationKatz) written in C that dump cookies and decryption keys directly fro… | 72 | 1495 | active |
| spyboy-productions/r4ven R4ven is a security awareness and penetration testing tool that hosts a web page which, when a user grants browser permissions, captures GP… | 60 | 1492 | active |
| Schira4396/VcenterKiller A Go-based all-in-one exploitation and verification tool targeting VMware vCenter, covering major CVEs such as CVE-2021-21972, CVE-2021-219… | 23 | 1485 | active |
| Fuzion24/JustTrustMe An Xposed module for rooted Android devices that disables SSL certificate pinning in apps, enabling traffic interception during security au… | 23 | 5361 | maintenance |
| inguardians/peirates Peirates is a Go-based, interactive Kubernetes penetration testing tool that automates privilege escalation, lateral movement, and cluster … | 90 | 1477 | active |
| LionSec/katoolin A Python CLI tool that lets users add or remove Kali Linux repositories on other Debian-based systems (like Ubuntu) and install Kali Linux … | 32 | 5348 | maintenance |
| lengjibo/RedTeamTools A collection of red team tools written and modified by the author, primarily in C++ and Python. It includes utilities for AV bypass, privil… | 53 | 1472 | active |
| shuanx/BurpAPIFinder BurpAPIFinder is a Burp Suite extension written in Java that passively analyzes HTTP traffic (HTML and JS files) to discover hidden API end… | 15 | 1472 | active |
| Greenwolf/ntlm_theft ntlm_theft is a Python3 CLI tool that generates 21 different types of NTLMv2 hash theft files (e.g., .url, .scf, .docx, .pdf, .jnlp) that t… | 52 | 1470 | active |
| t3l3machus/psudohash psudohash is a Python CLI tool that generates millions of keyword-based password mutations for brute-force attacks and hash cracking. It mi… | 34 | 1467 | active |
| ssh-mitm/ssh-mitm SSH-MITM is an open-source man-in-the-middle SSH server for authorized security audits and malware analysis. It proxies SSH client-server c… | 66 | 1464 | active |
| c0ny1/passive-scan-client A Burp Suite extension written in Java that forwards passive scanning traffic to external passive vulnerability scanners (like xray, w13sca… | 23 | 1462 | stable |
| epsylon/xsser XSSer is an automatic penetration testing framework for detecting, exploiting, and reporting cross-site scripting (XSS) vulnerabilities in … | 82 | 1461 | active |
| PortSwigger/param-miner Param Miner is a Burp Suite extension that identifies hidden, unlinked HTTP parameters, headers, and cookies using diffing logic and binary… | 78 | 1460 | active |
| urbanadventurer/username-anarchy Username Anarchy is a Ruby command-line tool that generates lists of likely usernames from people's first and last names for use in penetra… | 23 | 1458 | stable |
| AhMyth/AhMyth-Android-RAT AhMyth is an open-source Android Remote Administration Tool (RAT) consisting of an Electron-based desktop control panel and an Android back… | 10 | 5273 | maintenance |
| NullArray/AutoSploit AutoSploit is a Python CLI tool that automates mass exploitation of remote hosts by combining target discovery from Shodan, Censys, and Zoo… | 23 | 5253 | maintenance |
| NHAS/reverse_ssh A Go-based SSH server and client that enables SSH-based reverse shells, letting operators manage and connect to remote targets with native … | 98 | 1453 | active |
| GhostPack/SharpDPAPI SharpDPAPI is a C# port of Mimikatz's Windows DPAPI functionality, allowing triage of DPAPI masterkeys, credentials, vaults, certificates, … | 32 | 1449 | active |
| One-Fox-Security-Team/One-Fox-T00ls One-Fox-T00ls is a curated collection of penetration testing and security toolboxes from the One-Fox security team, covering information ga… | 56 | 1443 | active |
| EgeBalci/amber Amber is a reflective PE packer that converts Windows PE files (EXE, DLL, SYS) into position-independent shellcode payloads for in-memory e… | 23 | 1442 | active |
| t3l3machus/toxssin toxssin is an open-source penetration testing CLI tool that automates exploitation of Cross-Site Scripting (XSS) vulnerabilities. It pairs … | 33 | 1440 | active |
| boku7/BokuLoader BokuLoader is a proof-of-concept User-Defined Reflective Loader (UDRL) for Cobalt Strike written in C and assembly. It recreates, integrate… | 32 | 1431 | active |
| six2dez/burp-ai-agent Custom AI Agent (formerly Burp AI Agent) is a Burp Suite extension written in Kotlin that integrates LLMs into web security workflows via l… | 82 | 1427 | stable |
| dirkjanm/ldapdomaindump A Python CLI tool that dumps Active Directory information (users, groups, computers, policies, trusts) via LDAP and renders it as human-rea… | 30 | 1425 | stable |
| f0ng/autoDecoder A Burp Suite extension (written in Java) that lets users plug in custom encryption/decryption logic so intercepted HTTP traffic can be view… | 78 | 1424 | active |
| BiZken/PhishMailer A Python CLI tool that generates professional-looking phishing email templates for popular services like Instagram, PayPal, and Discord, ou… | 41 | 1424 | active |
| antonioCoco/RunasCs RunasCs is an open-source C# utility for running processes with explicit credentials on Windows, serving as an improved alternative to the … | 23 | 1424 | stable |
| login-securite/DonPAPI DonPAPI is a Python CLI tool that remotely dumps DPAPI-protected secrets (browser credentials, certificates, WiFi passwords, and more) from… | 29 | 1417 | active |
| Metarget/metarget Metarget is a Python-based framework that automatically builds vulnerable cloud-native infrastructures, installing vulnerable versions of D… | 65 | 1415 | active |
| RythmStick/AMSITrigger AMSITrigger is a C# command-line tool that identifies the specific strings in PowerShell scripts that trigger Microsoft's Antimalware Scan … | 32 | 1415 | active |
| outflanknl/C2-Tool-Collection A collection of C-based offensive security tools that integrate with Cobalt Strike and other C2 frameworks via Beacon Object Files (BOF) an… | 32 | 1415 | active |
| Jayy001/Search-That-Hash Search-That-Hash is a Python CLI tool that automatically submits hashes to popular online hash-cracking APIs to crack them in seconds. If n… | 27 | 1413 | active |
| Bitwise-01/Instagram- A Python CLI tool that performs brute-force password attacks against Instagram accounts using a supplied password list and rotating proxies… | 32 | 5081 | maintenance |
| blacklanternsecurity/MANSPIDER MANSPIDER is a Python CLI tool that crawls SMB shares across entire networks to find files by filename or content, with regex support and t… | 77 | 1406 | active |
| tihanyin/PSSW100AVB A curated collection of PowerShell scripts demonstrating antivirus evasion techniques, most notably reverse shells that go undetected by AV… | 70 | 1405 | active |
| superhedgy/AttackSurfaceMapper AttackSurfaceMapper is a Python CLI reconnaissance tool that expands a target's attack surface using OSINT and active techniques like subdo… | 32 | 1405 | active |
| karma9874/AndroRAT AndroRAT is an Android remote administration tool (RAT) with a Java-based Android client APK and a Python server, communicating over socket… | 32 | 5037 | maintenance |
| Flangvik/TeamFiltration TeamFiltration is a cross-platform penetration testing framework for enumerating, password spraying, exfiltrating data from, and backdoorin… | 55 | 1399 | active |
| INotGreen/XiebroC2 XiebroC2 is an open-source command-and-control (C2) framework for penetration testing, written in Go with a .NET teamserver. It supports Lu… | 27 | 1391 | active |
| RedByte1337/GraphSpy GraphSpy is an initial access and post-exploitation tool for Microsoft Entra ID (Azure AD) and Microsoft 365, offering a browser-based GUI … | 70 | 1386 | active |
| owasp-noir/noir OWASP Noir is a static analysis (SAST) CLI tool that scans source code to extract every endpoint an application exposes, including shadow A… | 99 | 1383 | active |
| xaitax/SploitScan SploitScan is a Python CLI cybersecurity utility that aggregates detailed vulnerability information for CVEs from sources like EPSS, CISA K… | 77 | 1379 | active |
| blacklanternsecurity/TREVORspray TREVORspray is a modular password spraying tool with threading, SSH/subnet proxy rotation, and loot modules targeting identity providers li… | 70 | 1379 | active |
| jonluca/anubis Anubis is a Python CLI tool for subdomain enumeration and information gathering that aggregates results from sources like HackerTarget, Vir… | 66 | 1375 | active |
| glitchedgitz/cook COOK is a Go-based wordlist framework that generates, splits, merges, and finds wordlists, with support for permutations, combinations, and… | 66 | 1371 | active |
| 0xacb/recollapse REcollapse is a Python CLI helper tool that generates fuzzing payloads for black-box regex fuzzing against web applications. It helps bypas… | 46 | 1371 | active |
| andresriancho/w3af w3af is an open source web application attack and audit framework that scans web applications for over 200 vulnerability types, including X… | 23 | 4900 | maintenance |
| SpiderLabs/Responder Responder is a Python-based LLMNR, NBT-NS, and mDNS poisoner with built-in rogue authentication servers (SMB, HTTP/S, MSSQL, FTP, LDAP, POP… | 10 | 4890 | maintenance |
| fasnow/fine Fine is a Chinese-language cyberspace asset mapping and reconnaissance tool integrating FOFA, Hunter, Quake, ZoomEye, and Shodan APIs, plus… | 82 | 1366 | active |