Ross ROSS = Recommend OSS · open-source software intelligence for agents

domain: penetration-testing

1317 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
summitt/Nope-Proxy
NoPE Proxy is a Burp Suite extension that adds TCP and UDP traffic interception, a configurable DNS server, and a non-HTTP man-in-the-middl…
231663active
longld/peda
PEDA is a Python plugin for GDB that enhances the debugger's display and adds exploit development commands. It provides colorized disassemb…
236147maintenance
dirkjanm/krbrelayx
A Python toolkit for abusing Kerberos in Active Directory environments, including Kerberos relaying and unconstrained delegation attacks. I…
641657active
WangYihang/Platypus
Platypus is a cross-platform reverse-shell and host management hub written in Go. Agents on managed machines dial back to a central server …
671656active
klezVirus/SysWhispers3
SysWhispers3 is a Python command-line tool that generates header and assembly (ASM) file pairs for direct system calls to the Windows kerne…
321653active
whwlsfb/BurpCrypto
BurpCrypto is a Burp Suite extension that encrypts Intruder payloads with algorithms like AES, RSA, and DES, or by executing arbitrary Java…
231648active
cddmp/enum4linux-ng
enum4linux-ng is a Python rewrite of the enum4linux.pl Windows/Samba enumeration tool, wrapping Samba utilities like nmblookup, net, rpccli…
751644active
shekyan/slowhttptest
SlowHTTPTest is a highly configurable command-line tool that simulates Application Layer Denial of Service attacks by prolonging HTTP conne…
671644active
Pentest AI
pentest-ai is an MIT-licensed local CLI and MCP server that turns Claude Code (or any LLM) into an offensive security assistant, pairing 50…
801629active
JesseCHale/HaleHound-CYD
HaleHound-CYD is a multi-protocol offensive security toolkit firmware for the ESP32 Cheap Yellow Display, offering 40+ attack modules acros…
801623active
vladko312/SSTImap
SSTImap is a Python-based penetration testing tool that automatically detects and exploits Server-Side Template Injection (SSTI) and code i…
881621active
michenriksen/aquatone
Aquatone is a Go CLI tool for visual inspection of websites across many hosts, taking screenshots via headless Chrome/Chromium and generati…
105961maintenance
coffinxp/loxs
Loxs is a Python-based multi-vulnerability scanner for web applications that detects SQL injection, XSS, LFI, open redirect, and CRLF injec…
521612active
SecurityRiskAdvisors/VECTR
VECTR is a self-hosted web application for tracking red and blue team testing activities to measure detection and prevention capabilities a…
981611active
liamg/gitjacker
Gitjacker is a Go CLI tool that downloads and reconstructs git repositories from websites where the .git directory has been mistakenly expo…
481607active
repplus/rep-chrome
rep+ is a Chrome DevTools extension inspired by Burp Suite's Repeater that captures and replays HTTP requests with modified methods, header…
541603active
Orange-Cyberdefense/ocd-mindmaps
A collection of interactive mindmaps from Orange Cyberdefense covering offensive security and penetration testing methodologies, published …
371602active
4lbH4cker/ALHacking
ALHacking is a shell-script-based toolkit bundling a menu of so-called ethical hacking utilities, including social media account attacks, p…
321601active
PentestPad/subzy
Subzy is a Go-based command-line tool that checks subdomains for takeover vulnerabilities by matching HTTP response fingerprints from the c…
321589active
Autumn-27/ScopeSentry
ScopeSentry is a self-hosted attack surface and asset mapping platform that combines subdomain enumeration, port scanning, fingerprinting, …
881587active
s0md3v/uro
uro is a Python CLI tool that declutters URL lists for crawling and security testing without making any HTTP requests. It removes duplicate…
291587stable
xnl-h4ck3r/xnLinkFinder
xnLinkFinder is a Python CLI tool that discovers endpoints, potential parameters, target-specific wordlists, and secrets for a given target…
781585active
m3n0sd0n4ld/GooFuzz
GooFuzz is a Bash-based CLI tool that performs fuzzing-style reconnaissance using advanced Google searches (Google Dorking) via the Google …
571585active
AlisamTechnology/ATSCAN
ATSCAN is a Perl-based command-line scanner for mass dork searching and vulnerability exploitation. It combines search engine dorking with …
231583active
m8sec/CrossLinked
CrossLinked is a Python CLI tool that enumerates LinkedIn employee names for an organization by scraping search engine results, without nee…
231582active
ReaJason/MemShellParty
MemShellParty is a self-hosted, visual tool for rapidly generating Java memory shells (fileless webshells) for mainstream web middleware an…
891581active
ultrasecurity/Storm-Breaker
Storm-Breaker is a social engineering tool that generates phishing-style web pages to capture device information, location, webcam, and mic…
325754maintenance
stealthcopter/deepce
DEEPCE is a single-file pure-shell script for enumerating Docker environments and attempting privilege escalation and container escapes. It…
581567active
wikiZ/RedGuard
RedGuard is a C2 front flow control tool written in Go that acts as a filtering reverse proxy in front of command-and-control servers. It h…
231567active
Tsojan/TsojanScan
TsojanScan is an integrated BurpSuite plugin for vulnerability detection that bundles multiple common vulnerability POCs into a single exte…
851563active
AD-Security/AD_Miner
AD Miner is an Active Directory (on-premise and Entra ID) auditing tool that runs Cypher queries against a BloodHound Neo4j graph database …
701562active
moom825/xeno-rat
Xeno-RAT is an open-source remote access tool (RAT) written in C# for remotely controlling Windows 10/11 machines. It includes features suc…
181562active
dwisiswant0/crlfuzz
CRLFuzz is a fast command-line tool written in Go that scans websites for CRLF (carriage return/line feed) injection vulnerabilities. It su…
661560active
OWASP/QRLJacking
QRLJacking is an OWASP project documenting and exploiting the Quick Response Code Login Jacking attack vector, which hijacks user sessions …
481559active
v-byte-cpu/sx
sx is a fast, UNIX-philosophy command-line network scanner written in Go that supports ARP/NDP host discovery, ICMP, TCP SYN/FIN/NULL/Xmas,…
831553active
Clats97/ClatScope
ClatScope Info Tool is a Python-based OSINT utility offering 70+ reconnaissance features including geolocation, DNS, WHOIS, phone, email, a…
481537active
xnl-h4ck3r/GAP-Burp-Extension
GAP is a Burp Suite extension written in Python (Jython) that extracts potential endpoints, parameters, and links from Burp's site map, pro…
661530active
BlackSnufkin/LitterBox
LitterBox is a self-hosted payload-analysis sandbox for red teams that runs static, dynamic, and EDR-based analysis on samples and produces…
621526active
nemesida-waf/waf-bypass
WAF Bypass Tool is an open-source Python CLI tool that tests web application firewalls for false positives and false negatives using predef…
831520active
gobysec/Goby
Goby is a network security assessment tool that maps an organization's attack surface and scans for known vulnerabilities and weak password…
231517active
overspace-labs/CaA
CaA is a BurpSuite extension (Montoya API) that analyzes HTTP traffic to extract parameters, paths, files, and parameter values with freque…
831516active
ztgrace/changeme
changeme is a Python CLI tool that scans networks for devices and services using default or backdoor credentials. Credential definitions ar…
361516active
webpwnized/mutillidae
OWASP Mutillidae II is a deliberately vulnerable PHP web application used as a target for web-security training and practice. It includes o…
721513active
blacklanternsecurity/writehat
WriteHat is a self-hosted web application for generating penetration test reports, converting Markdown to HTML to PDF without Microsoft Wor…
661513active
0xsp-SRD/mortar
Mortar Loader is a red team evasion tool that encrypts PE binaries and shellcode and executes them in memory using various injection techni…
231508active
nikaiw/VMkatz
VMkatz is a Rust CLI tool that extracts Windows credentials (NTLM hashes, DPAPI keys, Kerberos tickets, LSA secrets, BitLocker keys) direct…
691507active
nikitastupin/clairvoyance
Clairvoyance is a Python CLI tool that recovers a GraphQL API's schema even when introspection is disabled, by probing field and type names…
571506active
Gowtham-Darkseid/AutoPentestX
AutoPentestX is a Python-based automated penetration testing toolkit that scans targets for vulnerabilities and generates security reports.…
451504active
assetnote/nowafpls
nowafpls is a Jython-based Burp Suite plugin that bypasses web application firewalls (WAFs) by inserting junk data into HTTP request bodies…
381502active
T4y1oR/RingQ
RingQ is a post-exploitation antivirus evasion tool that obfuscates and loads arbitrary Windows executables or shellcode (e.g., Cobalt Stri…
271497active
Meckazin/ChromeKatz
ChromeKatz is a set of offensive security tools (CookieKatz, ElevationKatz) written in C that dump cookies and decryption keys directly fro…
721495active
spyboy-productions/r4ven
R4ven is a security awareness and penetration testing tool that hosts a web page which, when a user grants browser permissions, captures GP…
601492active
Schira4396/VcenterKiller
A Go-based all-in-one exploitation and verification tool targeting VMware vCenter, covering major CVEs such as CVE-2021-21972, CVE-2021-219…
231485active
Fuzion24/JustTrustMe
An Xposed module for rooted Android devices that disables SSL certificate pinning in apps, enabling traffic interception during security au…
235361maintenance
inguardians/peirates
Peirates is a Go-based, interactive Kubernetes penetration testing tool that automates privilege escalation, lateral movement, and cluster …
901477active
LionSec/katoolin
A Python CLI tool that lets users add or remove Kali Linux repositories on other Debian-based systems (like Ubuntu) and install Kali Linux …
325348maintenance
lengjibo/RedTeamTools
A collection of red team tools written and modified by the author, primarily in C++ and Python. It includes utilities for AV bypass, privil…
531472active
shuanx/BurpAPIFinder
BurpAPIFinder is a Burp Suite extension written in Java that passively analyzes HTTP traffic (HTML and JS files) to discover hidden API end…
151472active
Greenwolf/ntlm_theft
ntlm_theft is a Python3 CLI tool that generates 21 different types of NTLMv2 hash theft files (e.g., .url, .scf, .docx, .pdf, .jnlp) that t…
521470active
t3l3machus/psudohash
psudohash is a Python CLI tool that generates millions of keyword-based password mutations for brute-force attacks and hash cracking. It mi…
341467active
ssh-mitm/ssh-mitm
SSH-MITM is an open-source man-in-the-middle SSH server for authorized security audits and malware analysis. It proxies SSH client-server c…
661464active
c0ny1/passive-scan-client
A Burp Suite extension written in Java that forwards passive scanning traffic to external passive vulnerability scanners (like xray, w13sca…
231462stable
epsylon/xsser
XSSer is an automatic penetration testing framework for detecting, exploiting, and reporting cross-site scripting (XSS) vulnerabilities in …
821461active
PortSwigger/param-miner
Param Miner is a Burp Suite extension that identifies hidden, unlinked HTTP parameters, headers, and cookies using diffing logic and binary…
781460active
urbanadventurer/username-anarchy
Username Anarchy is a Ruby command-line tool that generates lists of likely usernames from people's first and last names for use in penetra…
231458stable
AhMyth/AhMyth-Android-RAT
AhMyth is an open-source Android Remote Administration Tool (RAT) consisting of an Electron-based desktop control panel and an Android back…
105273maintenance
NullArray/AutoSploit
AutoSploit is a Python CLI tool that automates mass exploitation of remote hosts by combining target discovery from Shodan, Censys, and Zoo…
235253maintenance
NHAS/reverse_ssh
A Go-based SSH server and client that enables SSH-based reverse shells, letting operators manage and connect to remote targets with native …
981453active
GhostPack/SharpDPAPI
SharpDPAPI is a C# port of Mimikatz's Windows DPAPI functionality, allowing triage of DPAPI masterkeys, credentials, vaults, certificates, …
321449active
One-Fox-Security-Team/One-Fox-T00ls
One-Fox-T00ls is a curated collection of penetration testing and security toolboxes from the One-Fox security team, covering information ga…
561443active
EgeBalci/amber
Amber is a reflective PE packer that converts Windows PE files (EXE, DLL, SYS) into position-independent shellcode payloads for in-memory e…
231442active
t3l3machus/toxssin
toxssin is an open-source penetration testing CLI tool that automates exploitation of Cross-Site Scripting (XSS) vulnerabilities. It pairs …
331440active
boku7/BokuLoader
BokuLoader is a proof-of-concept User-Defined Reflective Loader (UDRL) for Cobalt Strike written in C and assembly. It recreates, integrate…
321431active
six2dez/burp-ai-agent
Custom AI Agent (formerly Burp AI Agent) is a Burp Suite extension written in Kotlin that integrates LLMs into web security workflows via l…
821427stable
dirkjanm/ldapdomaindump
A Python CLI tool that dumps Active Directory information (users, groups, computers, policies, trusts) via LDAP and renders it as human-rea…
301425stable
f0ng/autoDecoder
A Burp Suite extension (written in Java) that lets users plug in custom encryption/decryption logic so intercepted HTTP traffic can be view…
781424active
BiZken/PhishMailer
A Python CLI tool that generates professional-looking phishing email templates for popular services like Instagram, PayPal, and Discord, ou…
411424active
antonioCoco/RunasCs
RunasCs is an open-source C# utility for running processes with explicit credentials on Windows, serving as an improved alternative to the …
231424stable
login-securite/DonPAPI
DonPAPI is a Python CLI tool that remotely dumps DPAPI-protected secrets (browser credentials, certificates, WiFi passwords, and more) from…
291417active
Metarget/metarget
Metarget is a Python-based framework that automatically builds vulnerable cloud-native infrastructures, installing vulnerable versions of D…
651415active
RythmStick/AMSITrigger
AMSITrigger is a C# command-line tool that identifies the specific strings in PowerShell scripts that trigger Microsoft's Antimalware Scan …
321415active
outflanknl/C2-Tool-Collection
A collection of C-based offensive security tools that integrate with Cobalt Strike and other C2 frameworks via Beacon Object Files (BOF) an…
321415active
Jayy001/Search-That-Hash
Search-That-Hash is a Python CLI tool that automatically submits hashes to popular online hash-cracking APIs to crack them in seconds. If n…
271413active
Bitwise-01/Instagram-
A Python CLI tool that performs brute-force password attacks against Instagram accounts using a supplied password list and rotating proxies…
325081maintenance
blacklanternsecurity/MANSPIDER
MANSPIDER is a Python CLI tool that crawls SMB shares across entire networks to find files by filename or content, with regex support and t…
771406active
tihanyin/PSSW100AVB
A curated collection of PowerShell scripts demonstrating antivirus evasion techniques, most notably reverse shells that go undetected by AV…
701405active
superhedgy/AttackSurfaceMapper
AttackSurfaceMapper is a Python CLI reconnaissance tool that expands a target's attack surface using OSINT and active techniques like subdo…
321405active
karma9874/AndroRAT
AndroRAT is an Android remote administration tool (RAT) with a Java-based Android client APK and a Python server, communicating over socket…
325037maintenance
Flangvik/TeamFiltration
TeamFiltration is a cross-platform penetration testing framework for enumerating, password spraying, exfiltrating data from, and backdoorin…
551399active
INotGreen/XiebroC2
XiebroC2 is an open-source command-and-control (C2) framework for penetration testing, written in Go with a .NET teamserver. It supports Lu…
271391active
RedByte1337/GraphSpy
GraphSpy is an initial access and post-exploitation tool for Microsoft Entra ID (Azure AD) and Microsoft 365, offering a browser-based GUI …
701386active
owasp-noir/noir
OWASP Noir is a static analysis (SAST) CLI tool that scans source code to extract every endpoint an application exposes, including shadow A…
991383active
xaitax/SploitScan
SploitScan is a Python CLI cybersecurity utility that aggregates detailed vulnerability information for CVEs from sources like EPSS, CISA K…
771379active
blacklanternsecurity/TREVORspray
TREVORspray is a modular password spraying tool with threading, SSH/subnet proxy rotation, and loot modules targeting identity providers li…
701379active
jonluca/anubis
Anubis is a Python CLI tool for subdomain enumeration and information gathering that aggregates results from sources like HackerTarget, Vir…
661375active
glitchedgitz/cook
COOK is a Go-based wordlist framework that generates, splits, merges, and finds wordlists, with support for permutations, combinations, and…
661371active
0xacb/recollapse
REcollapse is a Python CLI helper tool that generates fuzzing payloads for black-box regex fuzzing against web applications. It helps bypas…
461371active
andresriancho/w3af
w3af is an open source web application attack and audit framework that scans web applications for over 200 vulnerability types, including X…
234900maintenance
SpiderLabs/Responder
Responder is a Python-based LLMNR, NBT-NS, and mDNS poisoner with built-in rogue authentication servers (SMB, HTTP/S, MSSQL, FTP, LDAP, POP…
104890maintenance
fasnow/fine
Fine is a Chinese-language cyberspace asset mapping and reconnaissance tool integrating FOFA, Hunter, Quake, ZoomEye, and Shodan APIs, plus…
821366active

← prev page 5 / 14 next →