Ross ROSS = Recommend OSS · open-source software intelligence for agents

domain: penetration-testing

1317 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
yazgx97/frida-ios-hook
A Python/JavaScript CLI tool that wraps Frida to make it easy to trace classes and functions, hook methods, and modify return values on iOS…
691183active
runZeroInc/sshamble
SSHamble is a Go-based research and scanning tool for probing SSH server implementations. It enumerates SSH capabilities and tests for auth…
681180active
JoelGMSec/EvilnoVNC
EvilnoVNC is a ready-to-run phishing platform that gives victims a real Chromium browser session over a noVNC connection inside Docker, whi…
411176active
S3cur3Th1sSh1t/Creds
A collection of PowerShell scripts and executables useful for penetration testing and forensics, mostly Windows and Active Directory domain…
761174active
jenish-sojitra/JSAnalyzer
A Burp Suite extension written in Python (Jython) that performs static analysis on JavaScript files proxied through Burp. It extracts API e…
441171active
NH-RED-TEAM/RustHound
RustHound is a cross-platform Active Directory data collector for BloodHound Legacy 4.x, written in Rust. It enumerates users, groups, comp…
231171active
Quitten/Autorize
Autorize is a Burp Suite extension, written in Jython, that automatically detects authorization and authentication enforcement flaws in web…
561169active
jasonxtn/Kraken
Kraken is a Python-based menu-driven toolkit that centralizes brute-force attacks across network protocols (SSH, FTP, LDAP, Telnet, WiFi), …
231169active
rverton/webanalyze
webanalyze is a Go port of Wappalyzer that detects the technologies used on websites, built for performant mass scanning of large host list…
711168active
dark-kingA/cloudTools
A cross-platform desktop tool for cloud asset management and cloud security assessment, built with Electron, Vue, Node.js, and Go. It manag…
591168active
v4lkyr0/Buildware-Tools
Buildware-Tools is a Python-based terminal multitool combining OSINT reconnaissance, network diagnostics, Discord automation, cryptography …
781167active
citronneur/pamspy
pamspy is a Linux credentials dumper that uses eBPF to hook the pam_get_authtok function in libpam.so, capturing passwords from processes l…
231164active
0xthirteen/SharpRDP
SharpRDP is a C# console application that executes authenticated commands on remote Windows hosts via the Remote Desktop Protocol, using th…
751162active
arthepsy/CVE-2021-4034
A proof-of-concept exploit for CVE-2021-4034 (PwnKit), a local privilege escalation vulnerability in polkit's pkexec utility. It is a small…
321160stable
0x727/ShuiZe_0x727
ShuiZe_0x727 is a Python-based automated information gathering (reconnaissance) tool for red team operators. Given a root domain, C-segment…
234019maintenance
evyatarmeged/Raccoon
Raccoon is a Python-based offensive security CLI tool for reconnaissance and information gathering. It performs DNS lookups, WHOIS, TLS ana…
674001maintenance
0xsha/CloudBrute
CloudBrute is a Go CLI tool that enumerates a company's infrastructure, files, and applications across major cloud providers (Amazon, Googl…
271145active
pureqh/Hyacinth
Hyacinth is a Java-based GUI tool that bundles detection and exploitation modules for common Java vulnerabilities such as Struts2, Fast, We…
551144active
iagox86/dnscat2
dnscat2 is an encrypted DNS tunneling tool designed to create a command-and-control (C&C) channel over the DNS protocol. It consists of a C…
233958maintenance
laluka/bypass-url-parser
A Python CLI tool (usable as a library) that generates and tests many URL bypass payloads to access 40X-protected pages, using curl as its …
741138active
the-useless-one/pywerview
PywerView is a partial Python rewrite of PowerSploit's PowerView for Active Directory enumeration, built on impacket. It lets pentesters ru…
761133active
Arinerron/CVE-2022-0847-DirtyPipe-Exploit
A C-based root privilege escalation exploit for CVE-2022-0847 (Dirty Pipe), a Linux kernel vulnerability. It modifies Max Kellermann's proo…
321133stable
hasanfirnas/symbiote
Symbiote is a Python-based social engineering tool that generates a phishing page to trick a target into granting camera permission, then c…
371132active
SabyasachiRana/WebMap
WebMap is a self-hosted web dashboard for visualizing and reporting on Nmap scan results stored as XML files. It provides charts, host insp…
761128active
RedSiege/C2concealer
C2concealer is a Python command line tool that generates randomized Cobalt Strike malleable C2 profiles. It builds profile blocks from rand…
671124active
RuoJi6/CACM
CACM is a Linux post-exploitation and privilege persistence tool that bundles port scanning, sensitive information gathering, EDR/AV identi…
851121active
spyboy-productions/CamXploit
CamXploit is a Python-based security reconnaissance tool that checks whether an IP address hosts a potentially exposed IP camera or CCTV se…
481118active
r3nt0n/bopscrk
bopscrk is a Python CLI tool that generates smart, targeted wordlists for password cracking, combining user-provided words with transformat…
231117active
outlaws-bai/Galaxy
Galaxy is a Burp Suite extension that automatically decrypts and re-encrypts HTTP traffic whose payloads are encrypted, letting testers wor…
881109active
PortSwigger/mcp-server
A Burp Suite extension by PortSwigger that exposes Burp's capabilities to AI clients via the Model Context Protocol (MCP). It includes an S…
701107active
mgeeky/cobalt-arsenal
A collection of battle-tested Aggressor Scripts (CNA) for Cobalt Strike 4.0+ that extend and enhance the red team operator's workflow. It i…
321107active
CuriousLearnerDev/Online_tools
A security tool marketplace application that lets users download, update, and automatically install a large catalog of penetration testing …
961106active
D00Movenok/BounceBack
BounceBack is a stealth reverse proxy with WAF-like filtering designed to hide red team C2 and phishing infrastructure from blue teams, san…
731103active
tracelabs/tlosint-vm
Trace Labs OSINT VM is a Kali Linux-based virtual machine distribution pre-loaded with open-source intelligence (OSINT) tools and Firefox h…
871101active
hakluke/hakoriginfinder
hakoriginfinder is a Go CLI tool that discovers the origin host behind a reverse proxy or WAF. It sends requests with the original Host hea…
751101active
dafthack/MSOLSpray
MSOLSpray is a PowerShell-based password spraying tool for Microsoft Online (Azure AD/O365) accounts. It leverages Azure AD OAuth2 error co…
321100stable
EnableSecurity/sipvicious
SIPVicious OSS is a Python-based toolset for auditing SIP-based VoIP systems, including tools to scan for SIP servers (svmap), enumerate ex…
891098active
mgeeky/ProtectMyTooling
A multi-packer wrapper script that daisy-chains various packers, obfuscators, and shellcode loaders to produce obfuscated Red Team implants…
531097active
martin-olivier/airgorah
Airgorah is a WiFi security auditing application built in Rust with a GTK4 graphical interface, wrapping the aircrack-ng tools suite. It ca…
901096active
c3c/ADExplorerSnapshot
A Python CLI tool that parses AD Explorer snapshot (.dat) files and converts them to BOFHound, BloodHound-compatible JSON, or NDJSON format…
731096active
GamehunterKaan/AutoPWN-Suite
AutoPWN Suite is a Python-based automated vulnerability scanning and exploitation framework that wraps nmap for host discovery, version-bas…
941094active
Tuhinshubhra/RED_HAWK
RED_HAWK is a PHP-based all-in-one reconnaissance and vulnerability scanning tool for websites. It performs information gathering (whois, D…
323748maintenance
mbechler/marshalsec
marshalsec is a Java tool and research project that generates exploitation payloads for insecure unmarshalling across many Java marshalling…
323708maintenance
muraenateam/muraena
Muraena is an almost-transparent reverse proxy written in Go that automates phishing and post-phishing activities by dynamically proxying a…
661079active
Gameye98/Lazymux
Lazymux is a Python-based menu-driven installer for Termux that lets users install and run many penetration testing and hacking tools (e.g.…
323700maintenance
APTRS/APTRS
APTRS (Automated Penetration Testing Reporting System) is a Python/Django and TypeScript web application that automates generation of PDF a…
721078active
m-sec-org/EZ
EZ is a cross-platform vulnerability scanner that combines information gathering, port scanning, service brute-forcing, URL crawling, finge…
241078active
AlephNullSK/dnsgen
DNSGen is a Python CLI tool that generates intelligent permutations of domain names to aid subdomain discovery during security assessments.…
321076active
hahwul/jwt-hack
jwt-hack is a fast, single-binary Rust CLI toolkit for testing, analyzing, and attacking JSON Web Tokens (JWT) and JWE tokens. It supports …
911075active
xiaogang000/XG_NTAI
A Java-based GUI tool for generating obfuscated webshell payloads (ASP, PHP, JSP, JSPX) that evade WAF and antivirus detection, compatible …
371075active
knownsec/Kunyu
Kunyu is a Python command-line tool for efficient corporate asset collection using cyberspace mapping engines like ZoomEye and Seebug. It h…
251074active
qiwentaidi/Slack
Slack is an integrated security services toolkit built with Go and the Wails desktop framework, bundling website fingerprinting and vulnera…
781073active
thehackingsage/hackdroid
HackDroid is a curated collection of 364+ pentesting and security-related Android apps organized into categories like MITM, forensics, snif…
321072active
nathanlopez/Stitch
Stitch is a cross-platform Python Remote Administration Tool (RAT) framework for building custom payloads for Windows, macOS, and Linux. It…
323660maintenance
LandGrey/pydictor
pydictor is a Python-based wordlist (dictionary) builder for brute-force and dictionary attacks. It generates general, custom, and social-e…
233650maintenance
clr2of8/DPAT
DPAT is a Python-based Domain Password Audit Tool for penetration testers that analyzes NTDS password dumps combined with cracking results …
581065active
synacktiv/php_filter_chain_generator
A Python CLI tool by Synacktiv that generates PHP filter chains (php://filter gadget chains) to achieve remote code execution when an attac…
321065stable
Lazarus-AI/clearwing
Clearwing is a dual-mode autonomous offensive-security tool that combines a network-pentest ReAct agent with an LLM-driven source-code vuln…
631063active
itsreyi/BlockSuite
Block-Suite is a modular JavaFX desktop application for authorized Minecraft server security assessments. It deploys a transparent MITM pro…
671060active
bitsadmin/nopowershell
NoPowerShell is a C# implementation of PowerShell-like commands that avoids using System.Management.Automation.dll, making execution invisi…
591060active
ElevenPaths/FOCA
FOCA is a Windows desktop application that finds metadata and hidden information in documents discovered via search engines (Google, Bing, …
233622maintenance
lijiejie/subDomainsBrute
A fast DNS subdomain brute-forcing tool for penetration testers, written in Python with multi-process and coroutine support. It enumerates …
233621maintenance
chainreactors/spray
Spray is a high-performance HTTP directory fuzzing and content discovery tool written in Go, positioned as a next-generation alternative to…
931058active
Fahrj/reverse-ssh
A statically-linked SSH server written in Go with reverse connection functionality, designed for remote access during CTFs, HackTheBox chal…
651056active
vigolium/vigolium
Vigolium is a high-fidelity web vulnerability scanner written in Go that combines deterministic multi-phase scanning (317 modules for conte…
821055active
ysrc/xunfeng
Xunfeng is a self-hosted web application for rapid vulnerability emergency response and continuous scanning of enterprise internal networks…
233597maintenance
Zarcolio/sitedorks
A Python CLI tool that runs Google dork-style searches across multiple search engines (Google, Bing, DuckDuckGo, Yandex, Yahoo, Ecosia, Bra…
761053active
nshalabi/ATTACK-Tools
A collection of utilities for working with the MITRE ATT&CK framework, including a relational SQLite data model of ATT&CK data enriched wit…
501053active
NetSPI/PowerHuntShares
PowerHuntShares is a PowerShell audit tool that inventories, analyzes, and reports excessive privileges on SMB share ACLs across Active Dir…
531052active
robotshell/magicRecon
MagicRecon is a Bash shell script that automates reconnaissance and vulnerability scanning of target domains, including subdomain enumerati…
231052active
0xZDH/o365spray
o365spray is a Python CLI tool for username enumeration and password spraying against Microsoft Office 365 domains. It implements multiple …
321050active
smxiazi/NEW_xp_CAPTCHA
xp_CAPTCHA is a Burp Suite extension (Java plugin) that automatically recognizes CAPTCHAs during brute-force attacks, using a companion Pyt…
231050active
lijiejie/GitHack
GitHack is a Python CLI exploit tool that reconstructs a website's source code from an exposed .git folder. It parses the .git/index file, …
323576maintenance
p0dalirius/smbclient-ng
smbclient-ng is a Python command-line tool providing a fast, user-friendly interactive shell for interacting with SMB shares on remote Wind…
821048active
Ullaakut/nmap
An idiomatic Go library that wraps the nmap network scanner by shelling out to the nmap binary and parsing its XML output. It lets Go devel…
901047active
bountyyfi/lonkero
Lonkero is a professional-grade web application security scanner written in Rust, built for real penetration testing with 125+ scan modules…
731047active
xm1k3/cent
Cent is a Go CLI tool that aggregates and organizes community-contributed Nuclei vulnerability scanning templates into a single local folde…
811046active
kelvinBen/AppInfoScanner
A Python-based static information-gathering scanner for mobile apps (Android APK/DEX, iOS IPA/Mach-O) and static web content (HTML, JS, H5)…
233554maintenance
PhonePe/mantis
Mantis is a command-line security framework that automates asset discovery, reconnaissance, and vulnerability scanning for given top-level …
671039active
nickvourd/Supernova
Supernova is an open-source command-line tool written in Go for encrypting and obfuscating raw shellcode. It supports multiple ciphers incl…
871036active
TheRook/subbrute
SubBrute is a Python DNS meta-query spider that enumerates subdomains and arbitrary DNS record types by leveraging open resolvers to bypass…
233526maintenance
vanhoefm/krackattacks-scripts
Scripts by Mathy Vanhoef to test whether Wi-Fi clients or access points are vulnerable to the KRACK attack against WPA2. They include a mod…
233524maintenance
zhzyker/vulmap
Vulmap is a Python 3 command-line tool that scans web applications for known CVE vulnerabilities and can immediately verify or exploit them…
233521maintenance
carlospolop/legion
Legion is a Python-based automatic enumeration tool that orchestrates well-known open-source pentesting tools (nmap, hydra, metasploit) to …
741032active
EdgeSecurityTeam/EHole
EHole (棱洞) is a Go-based fingerprint identification tool for red team reconnaissance that pinpoints high-value, easily attackable systems (…
233511maintenance
kyleavery/AceLdr
AceLdr is a position-independent reflective loader (UDRL) for Cobalt Strike written in C, designed to evade memory scanners like Moneta, PE…
231031active
k3yomi/Wall-of-Flippers
Wall of Flippers is a Python-based tool for discovering Flipper Zero devices and detecting Bluetooth Low Energy based attacks. It provides …
571027active
AsjadOooO/Zero-attacker
Zero-attacker is a multipurpose Python-based hacking toolkit bundling 15+ tools for ethical hacking and Discord operations, including DDoS,…
451021active
Dheerajmadhukar/karma_v2
karma_v2 is a Bash-based passive OSINT reconnaissance framework that automates Shodan queries to enumerate assets, exposed services, CVEs, …
421020active
chAng-L19/codex-redteam-mode
An opt-in red-team mode plugin for OpenAI Codex App and Codex CLI that compiles offensive-security objectives into GoalContracts and execut…
801016active
AKCodez/hackingtool-plugin
A Claude Code plugin that wraps 183+ pentesting and OSINT tools from Z4nzu/hackingtool, letting Claude automatically select and run securit…
501016active
techchipnet/hound
Hound is a lightweight PHP-based information gathering tool that captures a target device's exact GPS coordinates along with system and ISP…
301016active
Spade-sec/First
A WeChat mini-program security debugging tool (fork/extension of WMPFDebugger) that uses Frida injection and Chrome DevTools Protocol bridg…
741015active
redcode-labs/neurax
Neurax is a Go framework for constructing self-spreading binaries (worms) that propagate across LAN/WAN networks without external servers. …
321015active
secretsquirrel/the-backdoor-factory
The Backdoor Factory (BDF) is a Python command-line tool that patches Windows PE, Linux ELF, and macOS Mach-O executables with user-supplie…
323439maintenance
fullhunt/log4j-scan
A Python-based automated scanner for detecting the Log4j RCE vulnerability (CVE-2021-44228, Log4Shell) and related CVEs across lists of URL…
233422maintenance
JackJuly/linkook
Linkook is a Python-based OSINT command-line tool that discovers linked social media accounts and associated email addresses across multipl…
531008active
tarunkant/Gopherus
Gopherus is a Python CLI tool that generates Gopher protocol payloads for exploiting SSRF vulnerabilities to achieve remote code execution.…
323411maintenance
dedsec1121fk/DedSec
DedSec Project is an educational cybersecurity and Termux toolkit for Android that bundles scripts, utilities, local web interfaces, and pr…
881005active
RuoJi6/audit-skills
A lightweight Claude/Codex skill package for AI-assisted source code security auditing, covering Java, .NET, and PHP. It provides vulnerabi…
731005active

← prev page 7 / 14 next →