domain: penetration-testing
1317 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| ki9mu/ARL-plus-docker A Docker-based fork of ARL (Asset Reconnaissance Lighthouse) v2.6.2 that performs automated asset discovery and vulnerability scanning for … | 35 | 1005 | active |
| d78ui98/APKDeepLens APKDeepLens is a Python-based static analysis tool that decompiles Android APK files with JADX and scans them for security vulnerabilities … | 64 | 1004 | active |
| odedshimon/BruteShark BruteShark is an open-source Network Forensic Analysis Tool (NFAT) that deeply inspects network traffic from PCAP/PCAPng files or live capt… | 23 | 3395 | maintenance |
| linkedin/qark QARK (Quick Android Review Kit) is a Python command-line tool from LinkedIn that scans Android applications, either as Java source code or … | 23 | 3382 | maintenance |
| noraj/haiti Haiti is a CLI tool and Ruby library that identifies hash types, detecting 675+ hash formats including modern algorithms like SHA3, Keccak,… | 76 | 999 | active |
| codingo/NoSQLMap NoSQLMap is an open-source Python command-line tool that audits, automates injection attacks against, and exploits default configuration we… | 65 | 3345 | maintenance |
| gwen001/pentest-tools A collection of small custom security scripts in Bash, Python, and PHP for penetration testing and bug bounty quick tasks, covering DNS enu… | 23 | 3323 | maintenance |
| nabla-c0d3/ssl-kill-switch2 SSL Kill Switch 2 is a blackbox Cydia Substrate tweak that disables SSL/TLS certificate validation, including certificate pinning, in iOS a… | 23 | 3311 | maintenance |
| SpacehuhnTech/WiFiDuck WiFi Duck is an open-source firmware for ESP8266 + ATmega32u4 hardware that emulates a USB keyboard to perform keystroke injection (BadUSB)… | 23 | 3274 | maintenance |
| Ignitetch/AdvPhishing A command-line phishing toolkit that hosts fake login pages for popular services (Facebook, Google, Paytm, Zomato, etc.) and performs real-… | 50 | 3268 | maintenance |
| sensepost/reGeorg reGeorg is a Python tool that creates a SOCKS proxy through a compromised bastion webserver by tunneling traffic over HTTP(S) via uploaded … | 37 | 3183 | maintenance |
| Hax4us/Nethunter-In-Termux A shell script that installs Kali NetHunter (Kali Linux) inside the Termux app on Android without requiring a rooted phone. It provides com… | 32 | 3128 | maintenance |
| risinek/esp32-wifi-penetration-tool An extensible Wi-Fi penetration testing framework for the ESP32 microcontroller, implementing attacks such as PMKID capture, WPA/WPA2 hands… | 23 | 3050 | maintenance |
| NYAN-x-CAT/AsyncRAT-C-Sharp AsyncRAT is an open-source Remote Access Tool (RAT) written in C# that lets an operator remotely monitor and control Windows client machine… | 23 | 3008 | maintenance |
| noob-hackers/infect Infect is a Bash-based Termux script that generates a link which, when opened on an Android device, executes a destructive payload that for… | 50 | 2984 | maintenance |
| christophetd/CloudFlair CloudFlair is a Python CLI tool that finds the origin servers of websites protected by Cloudflare or CloudFront by searching Censys interne… | 41 | 2972 | maintenance |
| google/nogotofail Nogotofail is an on-path (man-in-the-middle) blackbox network traffic security testing tool built in Python. It detects weak TLS/SSL connec… | 10 | 2951 | maintenance |
| Ekultek/WhatWaf WhatWaf is a Python command-line tool that detects web application firewalls (WAFs) protecting a target web application and attempts to fin… | 23 | 2924 | maintenance |
| mrd0x/BITB A collection of HTML/JavaScript templates implementing the Browser In The Browser (BITB) phishing technique, which renders fake browser win… | 32 | 2897 | maintenance |
| pentestmonkey/php-reverse-shell A PHP script that opens an interactive reverse shell connection back to an attacker-controlled listener. It is a well-known utility for pen… | 32 | 2853 | maintenance |
| AntSwordProject/AntSword-Loader AntSword Loader is the official Electron-based launcher for AntSword, a cross-platform webshell management and post-exploitation tool used … | 23 | 2835 | maintenance |
| tiagorlampert/CHAOS CHAOS is a free and open-source Remote Administration Tool written in Go that generates cross-platform binaries (Windows and Linux) for con… | 23 | 2830 | maintenance |
| welk1n/JNDI-Injection-Exploit A Java-based penetration testing tool that generates workable JNDI links and starts RMI, LDAP, and HTTP servers to exploit JNDI injection v… | 23 | 2823 | maintenance |
| ohpe/juicy-potato Juicy Potato is a C++ Windows local privilege escalation tool that abuses COM/DCOM activation and impersonation privileges (SeImpersonate/S… | 23 | 2820 | maintenance |
| aydinnyunus/Keylogger A Python-based keylogger that captures keyboard, mouse, screenshot, and microphone inputs from a target computer and emails the data via SM… | 32 | 2811 | maintenance |
| esc0rtd3w/wifi-hacker A shell script that automates attacking wireless connections using the built-in tools of Kali Linux. It supports WEP, WPS, WPA, and WPA2 se… | 23 | 2799 | maintenance |
| Ettercap/ettercap Ettercap is a comprehensive open-source suite for man-in-the-middle attacks on local networks. It supports live connection sniffing, on-the… | 81 | 2784 | maintenance |
| bhavsec/reconspider ReconSpider is an open-source OSINT framework written in Python for scanning IP addresses, emails, websites, and organizations to gather in… | 23 | 2778 | maintenance |
| cisagov/RedEye RedEye is an open-source visual analytic tool from CISA and PNNL for visualizing and reporting Red Team command-and-control activities. It … | 10 | 2767 | maintenance |
| NextronSystems/APTSimulator APT Simulator is a Windows Batch script toolset that makes a system look as if it was the victim of an APT attack, using tools and output f… | 42 | 2764 | maintenance |
| 1y0n/AV_Evasion_Tool YanRi (AV_Evasion_Tool) is a Windows GUI tool for red teams that generates loaders to evade antivirus detection of shellcode payloads, supp… | 39 | 2763 | maintenance |
| rootm0s/WinPwnage WinPwnage is a Python tool and library that implements UAC bypass, privilege elevation, and persistence techniques for Windows. It can scan… | 32 | 2753 | maintenance |
| shack2/SNETCracker A Windows GUI tool for auditing weak passwords across many network services such as SSH, RDP, SMB, MySQL, Redis, and FTP. It supports batch… | 23 | 2740 | maintenance |
| FuzzySecurity/PowerShell-Suite A collection of PowerShell utilities for interacting with low-level Windows APIs, covering tasks like process creation, runas-style credent… | 32 | 2731 | maintenance |
| m0rtem/CloudFail CloudFail is a Python 3 command-line reconnaissance tool that attempts to discover the real IP address of servers hidden behind Cloudflare.… | 32 | 2683 | maintenance |
| k4m4/kickthemout KickThemOut is a Python command-line tool that kicks devices off a local network by performing an ARP spoofing attack against selected targ… | 23 | 2674 | maintenance |
| flipkart-incubator/Astra Astra is an automated REST API security testing tool from Flipkart that detects vulnerabilities like SQL injection, XSS, broken authenticat… | 32 | 2658 | maintenance |
| b374k/b374k b374k is a single-file PHP webshell providing browser-based remote server management, including a file manager, command and script executio… | 23 | 2657 | maintenance |
| ParrotSec/mimikatz mimikatz is a well-known Windows security tool that extracts plaintext passwords, hashes, PINs, and Kerberos tickets from memory, and suppo… | 32 | 2630 | maintenance |
| matterpreter/DefenderCheck A C# command-line tool that takes a binary as input and splits it iteratively to pinpoint the exact bytes that Microsoft Defender flags on.… | 59 | 2623 | maintenance |
| AlessandroZ/BeRoot BeRoot is a post-exploitation tool that checks common misconfigurations on Windows, Linux, and macOS hosts to identify potential privilege … | 23 | 2621 | maintenance |
| obheda12/GitDorker GitDorker is a Python CLI tool that uses the GitHub Search API with a curated list of over 200 dorks to find sensitive information exposed … | 32 | 2577 | maintenance |
| Tuhinshubhra/CMSeeK CMSeeK is a Python 3 command-line suite that detects the content management system (CMS) powering a website, supporting over 180 CMSs inclu… | 65 | 2571 | maintenance |
| gloxec/CrossC2 CrossC2 is a framework that generates cross-platform Cobalt Strike beacon payloads for Linux, macOS, and other Unix-like targets, extending… | 23 | 2568 | maintenance |
| brendan-rius/c-jwt-cracker A multi-threaded JWT brute-force secret key cracker written in C using OpenSSL. It attempts to recover the HMAC signing key of a JWT token … | 32 | 2559 | maintenance |
| chrisk44/Hijacker Hijacker is an Android GUI wrapper for wireless penetration testing tools including Aircrack-ng, Airodump-ng, MDK3, and Reaver. It lets use… | 10 | 2544 | maintenance |
| joaomatosf/jexboss JexBoss is a Python command-line tool for testing and exploiting JBoss Application Server and Java deserialization vulnerabilities. It supp… | 32 | 2518 | maintenance |
| infosec-au/altdns Altdns is a Python CLI tool for DNS reconnaissance that generates permutations, alterations, and mutations of known subdomains using a word… | 32 | 2503 | maintenance |
| screetsec/Sudomy Sudomy is a Bash-based subdomain enumeration and reconnaissance framework that collects subdomains via active brute-forcing and passive thi… | 23 | 2432 | maintenance |
| Chora10/Cknife Cknife (China Chopper Knife) is a Java-based cross-platform webshell management tool, an open-source client compatible with the China Chopp… | 32 | 2422 | maintenance |
| secretsquirrel/SigThief SigThief is a Python CLI tool that rips the Authenticode signature off a signed PE file and appends it to another binary, patching the cert… | 32 | 2416 | maintenance |
| knownsec/ksubdomain ksubdomain is a stateless subdomain enumeration tool written in Go that performs extremely fast DNS brute-forcing by separating packet send… | 23 | 2393 | maintenance |
| besimorhino/powercat powercat is a PowerShell reimplementation of netcat supporting TCP, UDP, and DNS (dnscat2) connections, file transfer, and shell serving. I… | 32 | 2387 | maintenance |
| tr0uble-mAker/POC-bomber POC-bomber is a Python-based offensive security tool that bundles a large arsenal of high-impact POCs and EXPs (RCE, deserialization, file … | 23 | 2369 | maintenance |
| dana-at-cp/backdoor-apk A shell script that automates injecting a Metasploit backdoor payload into any Android APK by decompiling, hooking smali code, and re-signi… | 32 | 2367 | maintenance |
| byt3bl33d3r/SILENTTRINITY SILENTTRINITY is an asynchronous, multiplayer and multiserver C2/post-exploitation framework built with Python 3 and .NET's DLR. It uses em… | 32 | 2341 | maintenance |
| bugcrowd/HUNT HUNT Suite is a collection of Burp Suite and OWASP ZAP proxy extensions that identify common parameters vulnerable to vulnerability classes… | 67 | 2331 | maintenance |
| Hax4us/TermuxBlack TermuXBlacK is an unofficial third-party APT repository for Termux on Android that packages hacking and penetration-testing tools not avail… | 32 | 2321 | maintenance |
| noob-hackers/mrphish mrphish is a Bash-based Termux script that hosts fake social media login pages (60+ templates) with port forwarding via ngrok and OTP bypas… | 50 | 2320 | maintenance |
| sensepost/ruler Ruler is a Go-based command-line tool for interacting with and abusing Microsoft Exchange servers via MAPI/HTTP or RPC/HTTP. It enables off… | 23 | 2313 | maintenance |
| ustayready/fireprox FireProx is a Python CLI tool that uses AWS API Gateway to create on-the-fly HTTP pass-through proxies that rotate the source IP address wi… | 32 | 2282 | maintenance |
| xtr4nge/FruityWifi FruityWiFi is an open-source wireless network auditing tool with a web-based control panel for deploying advanced WiFi attacks. It is modul… | 23 | 2278 | maintenance |
| itm4n/PrintSpoofer PrintSpoofer is a Windows privilege escalation tool that abuses SeImpersonatePrivilege via the Print Spooler 'Printer Bug' to escalate from… | 10 | 2268 | maintenance |
| topotam/PetitPotam PetitPotam is a proof-of-concept tool that coerces Windows hosts to authenticate to attacker-controlled machines via the MS-EFSRPC protocol… | 32 | 2267 | maintenance |
| davidprowe/BadBlood BadBlood is a PowerShell tool that populates a Microsoft Active Directory domain with thousands of randomized users, groups, computers, and… | 32 | 2265 | maintenance |
| rabbitmask/WeblogicScan A one-click Python vulnerability scanner for Oracle WebLogic servers, covering nearly all historical WebLogic CVEs (SSRF, Java deserializat… | 32 | 2261 | maintenance |
| worawit/MS17-010 A collection of Python exploit scripts and proof-of-concepts for the MS17-010 Windows SMB vulnerabilities, including Eternalblue, Eternalch… | 32 | 2260 | maintenance |
| outflanknl/EvilClippy Evil Clippy is a cross-platform C# command-line assistant for crafting malicious MS Office documents with hidden or stomped VBA macros. It … | 32 | 2257 | maintenance |
| shmilylty/netspy netspy is a fast, cross-platform Go CLI tool for discovering reachable intranet network segments from a compromised host. It supports ICMP,… | 23 | 2238 | maintenance |
| Ascotbe/Medusa Medusa is a self-hosted red team arsenal platform written in Python that bundles tools such as an XSS platform, collaborative platform, CVE… | 23 | 2235 | maintenance |
| evilcos/xssor2 XSS'OR is a self-hostable web application for penetration testers that provides XSS/CSRF payload generation, encoding/decoding utilities, a… | 32 | 2224 | maintenance |
| HatBoy/Struts2-Scan A Python CLI tool that scans and exploits known Apache Struts2 vulnerabilities (S2-001 through S2-057) using publicly disclosed exploits. I… | 32 | 2220 | maintenance |
| LionSec/xerosploit Xerosploit is a Ruby-based penetration testing toolkit that wraps bettercap and nmap to perform man-in-the-middle attacks, port scanning, a… | 23 | 2199 | maintenance |
| thehackingsage/hacktronian Hacktronian is a Python-based, menu-driven collection of penetration testing tools that bundles popular utilities for information gathering… | 32 | 2196 | maintenance |
| codingo/Reconnoitre Reconnoitre is a Python CLI tool for multithreaded information gathering and service enumeration of target hosts and ranges, built original… | 23 | 2196 | maintenance |
| iamj0ker/bypass-403 A shell script that attempts to bypass HTTP 403 Forbidden responses using 24 known bypass techniques via curl. It also compares responses u… | 32 | 2189 | maintenance |
| peewpw/Invoke-PSImage Invoke-PSImage is a PowerShell tool that encodes a PowerShell script into the pixels of a PNG image using steganography, then generates a o… | 32 | 2188 | maintenance |
| hexway/apple_bleee A collection of experimental Python PoC scripts for sniffing and injecting Apple Bluetooth Low Energy (BLE) and AWDL (AirDrop) traffic. It … | 23 | 2184 | maintenance |
| IAmBlackHacker/Facebook-BruteForce A Python script that performs brute-force password attacks against Facebook accounts using wordlists, intended for educational purposes. It… | 23 | 2182 | maintenance |
| bats3c/shad0w SHAD0W is a modular post-exploitation C2 (command and control) framework written in Python and C, designed to operate covertly in heavily m… | 23 | 2179 | maintenance |
| CedArctic/DigiSpark-Scripts A collection of hand-written Arduino IDE sketches for the DigiSpark ATtiny85 board that turn it into a USB HID keyboard for executing autom… | 32 | 2170 | maintenance |
| Dliv3/Venom Venom is a multi-hop proxy tool written in Go for penetration testers, connecting multiple nodes to build chained proxies through internal … | 23 | 2165 | maintenance |
| noob-hackers/ighack A bash-based Termux script that attempts to brute-force Instagram account passwords using wordlists, routing traffic through Tor for anonym… | 50 | 2141 | maintenance |
| hmaverickadams/breach-parse Breach-Parse is a shell-based command-line tool for searching breached password compilations (like the BreachCompilation torrent) for crede… | 32 | 2140 | maintenance |
| anouarbensaad/vulnx VulnX is a Python CLI tool that detects CMS types (WordPress, Joomla, Drupal, etc.), gathers target information like subdomains and DNS rec… | 23 | 2138 | maintenance |
| D4Vinci/Cr3dOv3r Cr3dOv3r is a Python command-line pentesting tool for investigating credential reuse attacks. Given an email, it searches public breach dat… | 57 | 2137 | maintenance |
| skavngr/rapidscan RapidScan is a Python CLI tool that automates web vulnerability scanning by orchestrating multiple security tools (nmap, nikto, wafw00f, ss… | 23 | 2128 | maintenance |
| UnaPibaGeek/ctfr CTFR is a Python command-line tool that enumerates HTTPS website subdomains by querying Certificate Transparency logs (via crt.sh) instead … | 32 | 2117 | maintenance |
| TideSec/WDScanner WDScanner is a self-hosted distributed web vulnerability scanning platform written in PHP with Python backend workers. It combines customer… | 32 | 2100 | maintenance |
| s0md3v/ReconDog ReconDog is a Python-based reconnaissance 'Swiss Army Knife' that gathers information about targets (domains, IPs) using third-party APIs l… | 23 | 2099 | maintenance |
| TideSec/TideFinger TideFinger is a Python web fingerprinting tool that merges rule sets from multiple open-source fingerprint databases (Wappalyzer, webanalyz… | 32 | 2086 | maintenance |
| dafthack/DomainPasswordSpray DomainPasswordSpray is a PowerShell tool that performs password spray attacks against domain user accounts, automatically generating a user… | 32 | 2082 | maintenance |
| iSafeBlue/TrackRay TrackRay (溯光) is an open-source penetration testing framework written in Java on SpringBoot that implements its own vulnerability scanning … | 23 | 2078 | maintenance |
| 0xn0ne/weblogicScanner A Python CLI vulnerability scanner for Oracle WebLogic servers that detects a wide range of known CVEs (2014-2020), including deserializati… | 32 | 2073 | maintenance |
| moxie0/sslstrip sslstrip is a Python command-line tool that implements Moxie Marlinspike's SSL stripping man-in-the-middle attack, downgrading HTTPS links … | 32 | 2073 | maintenance |
| Aabyss-Team/ARL ARL (Asset Reconnaissance Lighthouse) is a self-hosted asset reconnaissance system that quickly discovers internet-facing assets associated… | 29 | 2055 | maintenance |
| yzddmr6/WebCrack WebCrack is a Python CLI tool for batch detection of weak passwords and universal-password (SQL injection bypass) vulnerabilities on web ad… | 32 | 2051 | maintenance |
| wszf/androrat AndroRAT is a remote administration tool (RAT) for Android built as a client/server pair: an Android client that runs as a boot-started bac… | 32 | 2040 | maintenance |
| Cyb0r9/SocialBox SocialBox is a shell-based brute-force attack framework targeting Facebook, Gmail, Instagram, and Twitter login forms. It is a penetration-… | 32 | 2034 | maintenance |
| c0ny1/chunked-coding-converter A Burp Suite extension written in Java that converts HTTP request bodies to chunked transfer encoding, including delayed (sleep) chunking, … | 23 | 2029 | maintenance |