domain: penetration-testing
1317 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| Cracked5pider/Stardust Stardust is a modern 32/64-bit position independent shellcode (implant) template written in C++20. It provides compile-time FNV-1a hashing … | 70 | 1364 | active |
| Morsmalleo/AhMyth AhMyth is a cross-platform Android Remote Administration Tool (RAT) used to build APK payloads and remotely control Android devices through… | 66 | 1364 | active |
| alphasoc/flightsim flightsim is a lightweight Go CLI utility that safely generates malicious network traffic patterns such as DNS tunneling, DGA domains, C2 c… | 23 | 1363 | active |
| 61106960/adPEAS adPEAS is a single-file PowerShell tool that automates Active Directory security assessment, enumerating misconfigurations, vulnerabilities… | 99 | 1361 | active |
| boku7/Loki Loki is a stage-1 command and control (C2) framework written in Node.js that exploits script-jacking vulnerabilities in Electron applicatio… | 50 | 1360 | active |
| zalexdev/strykerapp StrykerOSS is a free, open-source mobile penetration testing suite for rooted Android devices that bundles network, wireless, and web secur… | 98 | 1359 | active |
| roottusk/vapi vAPI is a self-hostable deliberately vulnerable API that mimics the OWASP API Security Top 10 scenarios through hands-on exercises. It ship… | 23 | 1349 | active |
| JoasASantos/NeuroSploit NeuroSploit is an AI-powered penetration testing framework written in Rust that turns a URL, repository, app, or host into an autonomous se… | 85 | 1347 | active |
| projectdiscovery/nuclei-burp-plugin A Burp Suite plugin that helps generate Nuclei vulnerability scanner templates from HTTP requests and responses captured in Burp's Proxy, R… | 44 | 1344 | active |
| WKL-Sec/HiddenDesktop Hidden Desktop is a Cobalt Strike BOF implementation of HVNC (Hidden Virtual Network Computing), letting red team operators interact with a… | 20 | 1343 | active |
| urbanadventurer/Android-PIN-Bruteforce A shell script that turns a rooted Android device running Kali NetHunter into a USB HID keyboard that bruteforces the lockscreen PIN of a l… | 32 | 4782 | maintenance |
| x364e3ab6/DudeSuite DudeSuite is a lightweight, integrated web penetration testing toolkit distributed as a desktop application for Windows and macOS. It bundl… | 85 | 1336 | active |
| F6JO/RouteVulScan RouteVulScan is a Burp Suite extension written in Java that passively and recursively probes each path layer of web traffic for vulnerable … | 82 | 1334 | active |
| dafthack/GraphRunner GraphRunner is a post-exploitation toolset for interacting with the Microsoft Graph API, written in PowerShell. It enables reconnaissance, … | 62 | 1333 | active |
| silverhack/monkey365 Monkey365 is an open-source PowerShell-based security assessment framework for Microsoft 365, Azure, and Microsoft Entra ID. It collects te… | 97 | 1332 | active |
| cobbr/Covenant Covenant is a collaborative .NET command and control (C2) framework for red teamers, built as an ASP.NET Core cross-platform application wi… | 32 | 4730 | maintenance |
| bugbasesecurity/pentest-copilot Pentest Copilot is an open-source, AI-driven penetration testing agent that connects to a Kali attack box, autonomously runs security tools… | 64 | 1327 | active |
| wafinfo/DecryptTools A comprehensive encryption/decryption tool for penetration testers, supporting 22+ decryption schemes for Chinese enterprise software (OA s… | 22 | 1327 | active |
| ly4k/PwnKit A self-contained exploit for CVE-2021-4034 (PwnKit), a local privilege escalation vulnerability in polkit's pkexec. It ships as a prebuilt … | 32 | 1326 | stable |
| cseroad/Webshell_Generate A JavaFX desktop tool that generates evasive (antivirus-bypassing) webshells in multiple languages, supporting cmd shells and clients like … | 59 | 1323 | active |
| MrTuxx/SocialPwned SocialPwned is a Python-based OSINT tool that harvests emails published on Instagram, LinkedIn, and Twitter to find credential leaks via Pw… | 10 | 1320 | active |
| test502git/awvs14-scan A Python batch-scanning script built on the Acunetix (AWVS) 14/15 API that automates bulk URL scanning with specialized templates for log4j… | 48 | 1318 | active |
| 0x727/BypassPro BypassPro is a Burp Suite extension written in Java that automates bypass attempts against authorization controls (401/403) and WAFs. It co… | 79 | 1317 | active |
| cseroad/Exp-Tools A Java-based integrated exploitation tool that bundles proof-of-concept exploits for high-risk vulnerabilities in Chinese enterprise softwa… | 21 | 1316 | active |
| nccgroup/singularity Singularity of Origin is a DNS rebinding attack framework that includes a DNS server, a web server, a management UI, and sample attack payl… | 74 | 1315 | active |
| erev0s/VAmPI VAmPI is a deliberately vulnerable REST API built with Flask that implements the OWASP Top 10 vulnerabilities for APIs. It is designed for … | 66 | 1311 | active |
| PlumHound/PlumHound PlumHound is a Python CLI reporting engine that wraps BloodHoundAD's Neo4j Cypher queries into consumable security reports for Blue and Pur… | 63 | 1310 | active |
| codingo/VHostScan VHostScan is a Python-based virtual host scanner that discovers hidden vhosts on a web server using wordlists, reverse lookups, and catch-a… | 39 | 1309 | active |
| sulab999/AppMessenger AppMessenger is a free cross-platform (Windows/Mac/Linux, Java-based) GUI tool for analyzing mobile application packages including APK (And… | 86 | 1308 | active |
| PentesterFlow/agent PentesterFlow is a terminal-based agentic AI CLI assistant for penetration testers and bug bounty hunters. It orchestrates LLM-driven recon… | 71 | 1308 | active |
| freelabz/secator secator is a task and workflow runner for security assessments that unifies dozens of well-known security tools (subfinder, httpx, ffuf, nm… | 93 | 1306 | active |
| codingo/Interlace Interlace is a Python CLI tool that wraps single-threaded command-line applications and runs them in parallel across many targets, adding C… | 41 | 1303 | active |
| lanyi1998/DNSlog-GO DNSLog-GO is a self-hosted tool written in Go that monitors DNS resolution records, with a built-in web interface and API mode. It supports… | 83 | 1302 | active |
| 0xInfection/XSRFProbe XSRFProbe is a Python-based Cross Site Request Forgery (CSRF/XSRF) audit and exploitation toolkit. It crawls web applications, runs systema… | 82 | 1302 | stable |
| Marven11/Fenjing Fenjing is an automated Jinja2 SSTI (server-side template injection) exploitation tool designed for CTF competitions. It automatically anal… | 87 | 1301 | active |
| sighook/pixload pixload is a set of Perl CLI tools for creating and injecting payloads into image files (BMP, GIF, JPG, PNG, WebP). It is used in offensive… | 23 | 1300 | active |
| RedTeamPentesting/pretender Pretender is a Go-based penetration testing tool that gains machine-in-the-middle positions via spoofed local name resolution (mDNS, LLMNR,… | 92 | 1299 | active |
| XiaoliChan/wmiexec-Pro wmiexec-Pro is a Python CLI tool built on Impacket that provides an enhanced version of wmiexec.py for remote command execution on Windows … | 67 | 1295 | active |
| h4r5h1t/webcopilot WebCopilot is a Bash-based automation script for bug bounty reconnaissance that enumerates subdomains using multiple tools, filters paramet… | 23 | 1295 | active |
| n0xa/m5stick-nemo NEMO is a firmware for M5Stack ESP32 devices (M5StickC, Cardputer) that implements high-tech pranks and digital self-defense tools such as … | 89 | 1294 | active |
| qwqdanchun/Pillager Pillager is a C# post-exploitation information gathering tool that exports and decrypts sensitive data from target Windows machines, includ… | 20 | 1294 | active |
| hausec/PowerZure PowerZure is a PowerShell framework for assessing and exploiting resources in Microsoft Azure and Entra ID. It provides both reconnaissance… | 53 | 1293 | active |
| BishopFox/eyeballer Eyeballer is a convolutional neural network tool that classifies screenshots of web hosts taken during large-scope penetration tests. It la… | 55 | 1290 | active |
| knavesec/CredMaster CredMaster is a Python CLI tool for password spraying and brute-force attacks that rotates the source IP address on every authentication at… | 38 | 1290 | active |
| P1-Team/AlliN AlliN is a flexible, dependency-free Python scanner designed to assist penetration testing projects, especially lateral movement and intran… | 40 | 1288 | active |
| RickdeJager/stegseek Stegseek is a lightning-fast command-line cracker for steghide steganography, built as a fork of the original steghide project that can tes… | 23 | 1288 | stable |
| SafeBreach-Labs/PoolParty PoolParty is a C++ command-line tool implementing eight novel, fully-undetectable process injection techniques that abuse Windows Thread Po… | 20 | 1284 | active |
| bit4woo/Fiora Fiora is a graphical interface for the Nuclei vulnerability PoC framework, enabling quick PoC search and one-click execution of Nuclei scan… | 57 | 1282 | active |
| larlarua/AutoCVE AutoCVE is a self-hosted multi-agent platform that automates CVE discovery: it filters target projects, imports repositories, audits source… | 77 | 1280 | active |
| SanMuzZzZz/LuaN1aoAgent LuaN1aoAgent is an autonomous AI-driven penetration testing agent built in TypeScript on the Pi SDK, using graph-based cognitive reasoning … | 81 | 1276 | active |
| icyguider/Shhhloader Shhhloader is a Python-based builder that compiles C++ shellcode loader stubs designed to bypass AV/EDR on Windows. It supports multiple sh… | 32 | 1276 | active |
| zhuifengshaonianhanlu/pikachu Pikachu is a deliberately vulnerable PHP/MySQL web application designed as a practice range for learning web security and penetration testi… | 71 | 4504 | maintenance |
| W01fh4cker/VcenterKit A comprehensive penetration testing toolkit targeting VMware vCenter, bundling exploitation modules for known CVEs such as CVE-2021-21972, … | 42 | 1270 | active |
| xploitstech/Xteam Xteam is an all-in-one, menu-driven hacking toolkit written in Python and launched via bash scripts, bundling Instagram information gatheri… | 42 | 1268 | active |
| UndeadSec/EvilURL EvilURL is a Python CLI tool that generates Unicode (IDN) domain permutations used in homograph attacks, where look-alike characters trick … | 10 | 1267 | active |
| Athena-OS/athena Athena OS is an Arch/Nix-based Linux distribution focused on cybersecurity and penetration testing, available as ISO, Docker images, and WS… | 83 | 1266 | active |
| edoardottt/scilla Scilla is a Go-based command-line information gathering (recon) tool for penetration testers and bug bounty hunters. It enumerates DNS reco… | 80 | 1262 | active |
| 3xpl01tc0d3r/ProcessInjection A C# command-line tool that demonstrates and performs multiple Windows process injection techniques, including DLL injection, process hollo… | 48 | 1259 | active |
| cybersecsi/houdini HOUDINI is a curated catalog of hundreds of Docker images for network security and intrusion testing tools, presented through a searchable … | 47 | 1258 | active |
| RoganDawes/P4wnP1_aloa P4wnP1 A.L.O.A. is a framework that turns a Raspberry Pi Zero W into a low-cost offensive security appliance for pentesting, red teaming, a… | 23 | 4422 | maintenance |
| pry0cc/axiom Axiom is a dynamic infrastructure framework for spinning up disposable multi-cloud instances pre-loaded with security scanning tools like n… | 23 | 4415 | maintenance |
| wh1t3p1g/ysomap Ysomap is a Java deserialization exploit framework that lets users dynamically configure gadget chain payloads with different execution eff… | 26 | 1247 | active |
| f4rih/websploit Websploit is a high-level man-in-the-middle (MITM) security framework written in Python with a modular console interface similar to Metaspl… | 23 | 1247 | stable |
| lemono0/FastJsonParty FastJsonParty is a collection of Dockerized vulnerable environments covering multiple FastJson versions (1.2.47, 1.2.68, 1.2.80) for practi… | 28 | 1246 | active |
| antonioCoco/ConPtyShell ConPtyShell is a fully interactive reverse shell for Windows that leverages the Windows Pseudo Console (ConPTY) API to turn a remote PowerS… | 23 | 1246 | stable |
| RoganDawes/P4wnP1 P4wnP1 is a highly customizable USB attack platform built on a Raspberry Pi Zero or Zero W, providing features like a Windows LockPicker an… | 23 | 4383 | maintenance |
| HotBoy-java/PotatoTool PotatoTool is a comprehensive Java-based network security GUI tool for security professionals, red/blue team members, and enthusiasts. It i… | 29 | 1237 | active |
| PortSwigger/http-request-smuggler A Burp Suite extension that automatically detects and exploits HTTP Request Smuggling vulnerabilities, including HTTP/1.1 CL.TE/TE.CL desyn… | 76 | 1236 | active |
| arismelachroinos/lscript A shell script for Kali Linux that automates common WiFi penetration testing and hacking procedures through an interactive menu. It bundles… | 10 | 4330 | maintenance |
| danielbohannon/Invoke-Obfuscation Invoke-Obfuscation is a PowerShell command and script obfuscation framework compatible with PowerShell 2.0+. It generates obfuscated varian… | 32 | 4320 | maintenance |
| saeeddhqan/Maryam OWASP Maryam is a modular open-source OSINT framework for harvesting data from open sources, search engines, and social networks. It provid… | 10 | 1228 | active |
| RUB-NDS/PRET PRET is a Python command-line toolkit for printer security testing that connects to devices via network (port 9100) or USB and exploits pri… | 32 | 4301 | maintenance |
| DanMcInerney/wifijammer A Python script that continuously jams Wi-Fi clients and access points within range by sending deauthentication packets. It hops channels, … | 32 | 4291 | maintenance |
| ipa-lab/hackingBuddyGPT HackingBuddyGPT is a Python framework that helps ethical hackers and security researchers use LLMs and LLM-based autonomous agents for pene… | 67 | 1223 | active |
| xchwarze/wifi-pineapple-cloner A set of shell scripts that port the WiFi Pineapple NANO/TETRA penetration-testing firmware onto generic routers and other hardware. It inc… | 64 | 1223 | active |
| lcvvvv/kscan Kscan is an all-in-one reconnaissance scanner written in pure Go that combines port scanning, protocol detection, service/application finge… | 23 | 4287 | maintenance |
| Tylous/SourcePoint SourcePoint is a Go-based polymorphic C2 profile generator for Cobalt Strike command and control servers. It generates unique malleable C2 … | 30 | 1220 | active |
| nmap/ncrack Ncrack is a high-speed network authentication cracking tool from the Nmap project, designed to audit hosts and network devices for weak pas… | 23 | 1220 | active |
| bitquark/shortscan Shortscan is a Go CLI tool that enumerates files with short (8.3) filenames on IIS web servers and attempts to recover their full filenames… | 29 | 1215 | active |
| jxy-s/herpaderping A proof-of-concept tool and technical write-up demonstrating Process Herpaderping, a Windows technique that maps a process image from a fil… | 32 | 1210 | active |
| mgeeky/PackMyPayload PackMyPayload is a Python CLI proof-of-concept tool that packages files or directories into container formats (ZIP, 7zip, PDF, ISO, IMG, CA… | 32 | 1209 | active |
| strozfriedberg/Windows-Exploit-Suggester A Python CLI tool that compares a Windows host's patch level (from systeminfo output) against the Microsoft security bulletin database to d… | 10 | 4229 | maintenance |
| Veil-Framework/Veil Veil is a Python-based command-line tool that generates Metasploit payloads designed to bypass common antivirus solutions. It supports mult… | 10 | 4226 | maintenance |
| qi4L/qscan Qscan is an extremely fast internal network scanner written in Go, offering port scanning, protocol detection, service fingerprinting, brut… | 72 | 1206 | active |
| CERT-Polska/Artemis Artemis is a modular, open-source vulnerability scanner developed by CERT Polska that checks website security at scale. It automatically ge… | 74 | 1204 | active |
| mbrg/power-pwn Power Pwn is an offensive and defensive security toolset for Microsoft 365 Power Platform and AI services, including Copilot Studio, custom… | 63 | 1201 | active |
| zgjx6/SocialEngineeringDictionaryGenerator A browser-based social engineering password dictionary generator that builds candidate password lists from personal information such as nam… | 48 | 1201 | active |
| epinna/tplmap Tplmap is a Python command-line tool that automatically detects and exploits Server-Side Template Injection (SSTI) and code injection vulne… | 23 | 4197 | maintenance |
| Hackmanit/Web-Cache-Vulnerability-Scanner A fast, Go-based CLI scanner for detecting web cache poisoning and web cache deception vulnerabilities. It supports many attack techniques,… | 60 | 1200 | active |
| 7h30th3r0n3/Raspyjack RaspyJack is a portable offensive security toolkit for Raspberry Pi (with Waveshare LCD HAT) and Cardputer Zero, offering 231 payloads acro… | 78 | 1198 | active |
| ycdxsb/PocOrExp_in_Github A Python CLI tool that automatically aggregates proof-of-concept (POC) and exploit (EXP) code from GitHub by CVE ID, using CVE information … | 77 | 1198 | active |
| ozguralp/gmapsapiscanner A Python CLI tool that tests whether a leaked or discovered Google Maps API key is vulnerable to unauthorized usage across many Google Maps… | 70 | 1198 | active |
| The-Viper-One/PsMapExec PsMapExec is a PowerShell-based post-exploitation framework inspired by CrackMapExec/NetExec for assessing Active Directory environments. I… | 61 | 1198 | active |
| internetwache/GitTools GitTools is a collection of three shell/Python scripts for finding and exploiting websites that publicly expose their .git directory. It in… | 64 | 4178 | maintenance |
| vanhauser-thc/thc-ipv6 A comprehensive IPv6 attack toolkit written in C, providing dozens of tools for spoofing, man-in-the-middle, denial-of-service, scanning, a… | 58 | 1196 | active |
| niudaii/zpscan zpscan is a Go-based command-line information gathering and reconnaissance tool for security assessments. It bundles subdomain enumeration,… | 23 | 1196 | active |
| huntergregal/mimipenguin MimiPenguin is a post-exploitation tool that dumps the current Linux desktop user's cleartext login password from process memory, inspired … | 41 | 4157 | maintenance |
| jayus0821/swagger-hack A Python CLI tool that automatically crawls all endpoints exposed by leaked Swagger/OpenAPI documentation and sends configured test request… | 57 | 1189 | active |
| chaitin/xpoc xpoc is a fast emergency-response vulnerability scanner from Chaitin's xray community, designed for supply chain vulnerability scanning. It… | 20 | 1186 | active |
| trustedsec/CS-Remote-OPs-BOF A collection of Beacon Object Files (BOFs) by TrustedSec implementing remote operations commands for Cobalt Strike, covering tasks like use… | 94 | 1183 | active |