domain: penetration-testing
1317 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| yazgx97/frida-ios-hook A Python/JavaScript CLI tool that wraps Frida to make it easy to trace classes and functions, hook methods, and modify return values on iOS… | 69 | 1183 | active |
| runZeroInc/sshamble SSHamble is a Go-based research and scanning tool for probing SSH server implementations. It enumerates SSH capabilities and tests for auth… | 68 | 1180 | active |
| JoelGMSec/EvilnoVNC EvilnoVNC is a ready-to-run phishing platform that gives victims a real Chromium browser session over a noVNC connection inside Docker, whi… | 41 | 1176 | active |
| S3cur3Th1sSh1t/Creds A collection of PowerShell scripts and executables useful for penetration testing and forensics, mostly Windows and Active Directory domain… | 76 | 1174 | active |
| jenish-sojitra/JSAnalyzer A Burp Suite extension written in Python (Jython) that performs static analysis on JavaScript files proxied through Burp. It extracts API e… | 44 | 1171 | active |
| NH-RED-TEAM/RustHound RustHound is a cross-platform Active Directory data collector for BloodHound Legacy 4.x, written in Rust. It enumerates users, groups, comp… | 23 | 1171 | active |
| Quitten/Autorize Autorize is a Burp Suite extension, written in Jython, that automatically detects authorization and authentication enforcement flaws in web… | 56 | 1169 | active |
| jasonxtn/Kraken Kraken is a Python-based menu-driven toolkit that centralizes brute-force attacks across network protocols (SSH, FTP, LDAP, Telnet, WiFi), … | 23 | 1169 | active |
| rverton/webanalyze webanalyze is a Go port of Wappalyzer that detects the technologies used on websites, built for performant mass scanning of large host list… | 71 | 1168 | active |
| dark-kingA/cloudTools A cross-platform desktop tool for cloud asset management and cloud security assessment, built with Electron, Vue, Node.js, and Go. It manag… | 59 | 1168 | active |
| v4lkyr0/Buildware-Tools Buildware-Tools is a Python-based terminal multitool combining OSINT reconnaissance, network diagnostics, Discord automation, cryptography … | 78 | 1167 | active |
| citronneur/pamspy pamspy is a Linux credentials dumper that uses eBPF to hook the pam_get_authtok function in libpam.so, capturing passwords from processes l… | 23 | 1164 | active |
| 0xthirteen/SharpRDP SharpRDP is a C# console application that executes authenticated commands on remote Windows hosts via the Remote Desktop Protocol, using th… | 75 | 1162 | active |
| arthepsy/CVE-2021-4034 A proof-of-concept exploit for CVE-2021-4034 (PwnKit), a local privilege escalation vulnerability in polkit's pkexec utility. It is a small… | 32 | 1160 | stable |
| 0x727/ShuiZe_0x727 ShuiZe_0x727 is a Python-based automated information gathering (reconnaissance) tool for red team operators. Given a root domain, C-segment… | 23 | 4019 | maintenance |
| evyatarmeged/Raccoon Raccoon is a Python-based offensive security CLI tool for reconnaissance and information gathering. It performs DNS lookups, WHOIS, TLS ana… | 67 | 4001 | maintenance |
| 0xsha/CloudBrute CloudBrute is a Go CLI tool that enumerates a company's infrastructure, files, and applications across major cloud providers (Amazon, Googl… | 27 | 1145 | active |
| pureqh/Hyacinth Hyacinth is a Java-based GUI tool that bundles detection and exploitation modules for common Java vulnerabilities such as Struts2, Fast, We… | 55 | 1144 | active |
| iagox86/dnscat2 dnscat2 is an encrypted DNS tunneling tool designed to create a command-and-control (C&C) channel over the DNS protocol. It consists of a C… | 23 | 3958 | maintenance |
| laluka/bypass-url-parser A Python CLI tool (usable as a library) that generates and tests many URL bypass payloads to access 40X-protected pages, using curl as its … | 74 | 1138 | active |
| the-useless-one/pywerview PywerView is a partial Python rewrite of PowerSploit's PowerView for Active Directory enumeration, built on impacket. It lets pentesters ru… | 76 | 1133 | active |
| Arinerron/CVE-2022-0847-DirtyPipe-Exploit A C-based root privilege escalation exploit for CVE-2022-0847 (Dirty Pipe), a Linux kernel vulnerability. It modifies Max Kellermann's proo… | 32 | 1133 | stable |
| hasanfirnas/symbiote Symbiote is a Python-based social engineering tool that generates a phishing page to trick a target into granting camera permission, then c… | 37 | 1132 | active |
| SabyasachiRana/WebMap WebMap is a self-hosted web dashboard for visualizing and reporting on Nmap scan results stored as XML files. It provides charts, host insp… | 76 | 1128 | active |
| RedSiege/C2concealer C2concealer is a Python command line tool that generates randomized Cobalt Strike malleable C2 profiles. It builds profile blocks from rand… | 67 | 1124 | active |
| RuoJi6/CACM CACM is a Linux post-exploitation and privilege persistence tool that bundles port scanning, sensitive information gathering, EDR/AV identi… | 85 | 1121 | active |
| spyboy-productions/CamXploit CamXploit is a Python-based security reconnaissance tool that checks whether an IP address hosts a potentially exposed IP camera or CCTV se… | 48 | 1118 | active |
| r3nt0n/bopscrk bopscrk is a Python CLI tool that generates smart, targeted wordlists for password cracking, combining user-provided words with transformat… | 23 | 1117 | active |
| outlaws-bai/Galaxy Galaxy is a Burp Suite extension that automatically decrypts and re-encrypts HTTP traffic whose payloads are encrypted, letting testers wor… | 88 | 1109 | active |
| PortSwigger/mcp-server A Burp Suite extension by PortSwigger that exposes Burp's capabilities to AI clients via the Model Context Protocol (MCP). It includes an S… | 70 | 1107 | active |
| mgeeky/cobalt-arsenal A collection of battle-tested Aggressor Scripts (CNA) for Cobalt Strike 4.0+ that extend and enhance the red team operator's workflow. It i… | 32 | 1107 | active |
| CuriousLearnerDev/Online_tools A security tool marketplace application that lets users download, update, and automatically install a large catalog of penetration testing … | 96 | 1106 | active |
| D00Movenok/BounceBack BounceBack is a stealth reverse proxy with WAF-like filtering designed to hide red team C2 and phishing infrastructure from blue teams, san… | 73 | 1103 | active |
| tracelabs/tlosint-vm Trace Labs OSINT VM is a Kali Linux-based virtual machine distribution pre-loaded with open-source intelligence (OSINT) tools and Firefox h… | 87 | 1101 | active |
| hakluke/hakoriginfinder hakoriginfinder is a Go CLI tool that discovers the origin host behind a reverse proxy or WAF. It sends requests with the original Host hea… | 75 | 1101 | active |
| dafthack/MSOLSpray MSOLSpray is a PowerShell-based password spraying tool for Microsoft Online (Azure AD/O365) accounts. It leverages Azure AD OAuth2 error co… | 32 | 1100 | stable |
| EnableSecurity/sipvicious SIPVicious OSS is a Python-based toolset for auditing SIP-based VoIP systems, including tools to scan for SIP servers (svmap), enumerate ex… | 89 | 1098 | active |
| mgeeky/ProtectMyTooling A multi-packer wrapper script that daisy-chains various packers, obfuscators, and shellcode loaders to produce obfuscated Red Team implants… | 53 | 1097 | active |
| martin-olivier/airgorah Airgorah is a WiFi security auditing application built in Rust with a GTK4 graphical interface, wrapping the aircrack-ng tools suite. It ca… | 90 | 1096 | active |
| c3c/ADExplorerSnapshot A Python CLI tool that parses AD Explorer snapshot (.dat) files and converts them to BOFHound, BloodHound-compatible JSON, or NDJSON format… | 73 | 1096 | active |
| GamehunterKaan/AutoPWN-Suite AutoPWN Suite is a Python-based automated vulnerability scanning and exploitation framework that wraps nmap for host discovery, version-bas… | 94 | 1094 | active |
| Tuhinshubhra/RED_HAWK RED_HAWK is a PHP-based all-in-one reconnaissance and vulnerability scanning tool for websites. It performs information gathering (whois, D… | 32 | 3748 | maintenance |
| mbechler/marshalsec marshalsec is a Java tool and research project that generates exploitation payloads for insecure unmarshalling across many Java marshalling… | 32 | 3708 | maintenance |
| muraenateam/muraena Muraena is an almost-transparent reverse proxy written in Go that automates phishing and post-phishing activities by dynamically proxying a… | 66 | 1079 | active |
| Gameye98/Lazymux Lazymux is a Python-based menu-driven installer for Termux that lets users install and run many penetration testing and hacking tools (e.g.… | 32 | 3700 | maintenance |
| APTRS/APTRS APTRS (Automated Penetration Testing Reporting System) is a Python/Django and TypeScript web application that automates generation of PDF a… | 72 | 1078 | active |
| m-sec-org/EZ EZ is a cross-platform vulnerability scanner that combines information gathering, port scanning, service brute-forcing, URL crawling, finge… | 24 | 1078 | active |
| AlephNullSK/dnsgen DNSGen is a Python CLI tool that generates intelligent permutations of domain names to aid subdomain discovery during security assessments.… | 32 | 1076 | active |
| hahwul/jwt-hack jwt-hack is a fast, single-binary Rust CLI toolkit for testing, analyzing, and attacking JSON Web Tokens (JWT) and JWE tokens. It supports … | 91 | 1075 | active |
| xiaogang000/XG_NTAI A Java-based GUI tool for generating obfuscated webshell payloads (ASP, PHP, JSP, JSPX) that evade WAF and antivirus detection, compatible … | 37 | 1075 | active |
| knownsec/Kunyu Kunyu is a Python command-line tool for efficient corporate asset collection using cyberspace mapping engines like ZoomEye and Seebug. It h… | 25 | 1074 | active |
| qiwentaidi/Slack Slack is an integrated security services toolkit built with Go and the Wails desktop framework, bundling website fingerprinting and vulnera… | 78 | 1073 | active |
| thehackingsage/hackdroid HackDroid is a curated collection of 364+ pentesting and security-related Android apps organized into categories like MITM, forensics, snif… | 32 | 1072 | active |
| nathanlopez/Stitch Stitch is a cross-platform Python Remote Administration Tool (RAT) framework for building custom payloads for Windows, macOS, and Linux. It… | 32 | 3660 | maintenance |
| LandGrey/pydictor pydictor is a Python-based wordlist (dictionary) builder for brute-force and dictionary attacks. It generates general, custom, and social-e… | 23 | 3650 | maintenance |
| clr2of8/DPAT DPAT is a Python-based Domain Password Audit Tool for penetration testers that analyzes NTDS password dumps combined with cracking results … | 58 | 1065 | active |
| synacktiv/php_filter_chain_generator A Python CLI tool by Synacktiv that generates PHP filter chains (php://filter gadget chains) to achieve remote code execution when an attac… | 32 | 1065 | stable |
| Lazarus-AI/clearwing Clearwing is a dual-mode autonomous offensive-security tool that combines a network-pentest ReAct agent with an LLM-driven source-code vuln… | 63 | 1063 | active |
| itsreyi/BlockSuite Block-Suite is a modular JavaFX desktop application for authorized Minecraft server security assessments. It deploys a transparent MITM pro… | 67 | 1060 | active |
| bitsadmin/nopowershell NoPowerShell is a C# implementation of PowerShell-like commands that avoids using System.Management.Automation.dll, making execution invisi… | 59 | 1060 | active |
| ElevenPaths/FOCA FOCA is a Windows desktop application that finds metadata and hidden information in documents discovered via search engines (Google, Bing, … | 23 | 3622 | maintenance |
| lijiejie/subDomainsBrute A fast DNS subdomain brute-forcing tool for penetration testers, written in Python with multi-process and coroutine support. It enumerates … | 23 | 3621 | maintenance |
| chainreactors/spray Spray is a high-performance HTTP directory fuzzing and content discovery tool written in Go, positioned as a next-generation alternative to… | 93 | 1058 | active |
| Fahrj/reverse-ssh A statically-linked SSH server written in Go with reverse connection functionality, designed for remote access during CTFs, HackTheBox chal… | 65 | 1056 | active |
| vigolium/vigolium Vigolium is a high-fidelity web vulnerability scanner written in Go that combines deterministic multi-phase scanning (317 modules for conte… | 82 | 1055 | active |
| ysrc/xunfeng Xunfeng is a self-hosted web application for rapid vulnerability emergency response and continuous scanning of enterprise internal networks… | 23 | 3597 | maintenance |
| Zarcolio/sitedorks A Python CLI tool that runs Google dork-style searches across multiple search engines (Google, Bing, DuckDuckGo, Yandex, Yahoo, Ecosia, Bra… | 76 | 1053 | active |
| nshalabi/ATTACK-Tools A collection of utilities for working with the MITRE ATT&CK framework, including a relational SQLite data model of ATT&CK data enriched wit… | 50 | 1053 | active |
| NetSPI/PowerHuntShares PowerHuntShares is a PowerShell audit tool that inventories, analyzes, and reports excessive privileges on SMB share ACLs across Active Dir… | 53 | 1052 | active |
| robotshell/magicRecon MagicRecon is a Bash shell script that automates reconnaissance and vulnerability scanning of target domains, including subdomain enumerati… | 23 | 1052 | active |
| 0xZDH/o365spray o365spray is a Python CLI tool for username enumeration and password spraying against Microsoft Office 365 domains. It implements multiple … | 32 | 1050 | active |
| smxiazi/NEW_xp_CAPTCHA xp_CAPTCHA is a Burp Suite extension (Java plugin) that automatically recognizes CAPTCHAs during brute-force attacks, using a companion Pyt… | 23 | 1050 | active |
| lijiejie/GitHack GitHack is a Python CLI exploit tool that reconstructs a website's source code from an exposed .git folder. It parses the .git/index file, … | 32 | 3576 | maintenance |
| p0dalirius/smbclient-ng smbclient-ng is a Python command-line tool providing a fast, user-friendly interactive shell for interacting with SMB shares on remote Wind… | 82 | 1048 | active |
| Ullaakut/nmap An idiomatic Go library that wraps the nmap network scanner by shelling out to the nmap binary and parsing its XML output. It lets Go devel… | 90 | 1047 | active |
| bountyyfi/lonkero Lonkero is a professional-grade web application security scanner written in Rust, built for real penetration testing with 125+ scan modules… | 73 | 1047 | active |
| xm1k3/cent Cent is a Go CLI tool that aggregates and organizes community-contributed Nuclei vulnerability scanning templates into a single local folde… | 81 | 1046 | active |
| kelvinBen/AppInfoScanner A Python-based static information-gathering scanner for mobile apps (Android APK/DEX, iOS IPA/Mach-O) and static web content (HTML, JS, H5)… | 23 | 3554 | maintenance |
| PhonePe/mantis Mantis is a command-line security framework that automates asset discovery, reconnaissance, and vulnerability scanning for given top-level … | 67 | 1039 | active |
| nickvourd/Supernova Supernova is an open-source command-line tool written in Go for encrypting and obfuscating raw shellcode. It supports multiple ciphers incl… | 87 | 1036 | active |
| TheRook/subbrute SubBrute is a Python DNS meta-query spider that enumerates subdomains and arbitrary DNS record types by leveraging open resolvers to bypass… | 23 | 3526 | maintenance |
| vanhoefm/krackattacks-scripts Scripts by Mathy Vanhoef to test whether Wi-Fi clients or access points are vulnerable to the KRACK attack against WPA2. They include a mod… | 23 | 3524 | maintenance |
| zhzyker/vulmap Vulmap is a Python 3 command-line tool that scans web applications for known CVE vulnerabilities and can immediately verify or exploit them… | 23 | 3521 | maintenance |
| carlospolop/legion Legion is a Python-based automatic enumeration tool that orchestrates well-known open-source pentesting tools (nmap, hydra, metasploit) to … | 74 | 1032 | active |
| EdgeSecurityTeam/EHole EHole (棱洞) is a Go-based fingerprint identification tool for red team reconnaissance that pinpoints high-value, easily attackable systems (… | 23 | 3511 | maintenance |
| kyleavery/AceLdr AceLdr is a position-independent reflective loader (UDRL) for Cobalt Strike written in C, designed to evade memory scanners like Moneta, PE… | 23 | 1031 | active |
| k3yomi/Wall-of-Flippers Wall of Flippers is a Python-based tool for discovering Flipper Zero devices and detecting Bluetooth Low Energy based attacks. It provides … | 57 | 1027 | active |
| AsjadOooO/Zero-attacker Zero-attacker is a multipurpose Python-based hacking toolkit bundling 15+ tools for ethical hacking and Discord operations, including DDoS,… | 45 | 1021 | active |
| Dheerajmadhukar/karma_v2 karma_v2 is a Bash-based passive OSINT reconnaissance framework that automates Shodan queries to enumerate assets, exposed services, CVEs, … | 42 | 1020 | active |
| chAng-L19/codex-redteam-mode An opt-in red-team mode plugin for OpenAI Codex App and Codex CLI that compiles offensive-security objectives into GoalContracts and execut… | 80 | 1016 | active |
| AKCodez/hackingtool-plugin A Claude Code plugin that wraps 183+ pentesting and OSINT tools from Z4nzu/hackingtool, letting Claude automatically select and run securit… | 50 | 1016 | active |
| techchipnet/hound Hound is a lightweight PHP-based information gathering tool that captures a target device's exact GPS coordinates along with system and ISP… | 30 | 1016 | active |
| Spade-sec/First A WeChat mini-program security debugging tool (fork/extension of WMPFDebugger) that uses Frida injection and Chrome DevTools Protocol bridg… | 74 | 1015 | active |
| redcode-labs/neurax Neurax is a Go framework for constructing self-spreading binaries (worms) that propagate across LAN/WAN networks without external servers. … | 32 | 1015 | active |
| secretsquirrel/the-backdoor-factory The Backdoor Factory (BDF) is a Python command-line tool that patches Windows PE, Linux ELF, and macOS Mach-O executables with user-supplie… | 32 | 3439 | maintenance |
| fullhunt/log4j-scan A Python-based automated scanner for detecting the Log4j RCE vulnerability (CVE-2021-44228, Log4Shell) and related CVEs across lists of URL… | 23 | 3422 | maintenance |
| JackJuly/linkook Linkook is a Python-based OSINT command-line tool that discovers linked social media accounts and associated email addresses across multipl… | 53 | 1008 | active |
| tarunkant/Gopherus Gopherus is a Python CLI tool that generates Gopher protocol payloads for exploiting SSRF vulnerabilities to achieve remote code execution.… | 32 | 3411 | maintenance |
| dedsec1121fk/DedSec DedSec Project is an educational cybersecurity and Termux toolkit for Android that bundles scripts, utilities, local web interfaces, and pr… | 88 | 1005 | active |
| RuoJi6/audit-skills A lightweight Claude/Codex skill package for AI-assisted source code security auditing, covering Java, .NET, and PHP. It provides vulnerabi… | 73 | 1005 | active |