domain: penetration-testing
1317 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| fin3ss3g0d/evilgophish evilgophish is a Go-based framework combining evilginx3 and GoPhish for running authorized phishing and smishing campaigns with real-time c… | 32 | 2022 | maintenance |
| Nekmo/dirhunt Dirhunt is a Python CLI web crawler optimized for finding and analyzing web directories without brute-forcing paths. It detects 'index of' … | 23 | 2007 | maintenance |
| cube0x0/CVE-2021-1675 A proof-of-concept exploit tool implementing the PrintNightmare vulnerabilities (CVE-2021-1675/CVE-2021-34527) in both C# and Python (Impac… | 32 | 1999 | maintenance |
| Bashfuscator/Bashfuscator Bashfuscator is a modular, configurable Bash obfuscation framework written in Python 3 that transforms Bash commands and scripts into convo… | 32 | 1994 | maintenance |
| 411Hall/JAWS JAWS is a PowerShell enumeration script that helps penetration testers and CTF players quickly identify potential Windows privilege escalat… | 32 | 1993 | maintenance |
| mdsecactivebreach/SharpShooter SharpShooter is a payload creation framework for retrieving and executing arbitrary CSharp source code, generating payloads in formats like… | 32 | 1988 | maintenance |
| samyk/slipstream NAT Slipstreaming is a security research tool by Samy Kamkar that demonstrates remotely opening arbitrary firewall pinholes through a victi… | 32 | 1984 | maintenance |
| h3xduck/TripleCross TripleCross is a Linux eBPF rootkit demonstrating offensive capabilities of eBPF technology, including library injection, execution hijacki… | 23 | 1977 | maintenance |
| jondonas/linux-exploit-suggester-2 A Perl script that suggests Linux kernel privilege escalation exploits based on the running kernel version. It matches the kernel release a… | 32 | 1973 | maintenance |
| D35m0nd142/LFISuite LFISuite is a fully automatic Python tool that scans for and exploits Local File Inclusion (LFI) vulnerabilities using eight different atta… | 23 | 1961 | maintenance |
| r00t-3xp10it/venom VENOM is a shell-based framework that uses msfvenom to generate, obfuscate, and compile multi-format shellcode payloads (exe, dll, apk, elf… | 23 | 1961 | maintenance |
| cytopia/pwncat pwncat is a Python-based netcat replacement and reverse/bind shell handler with firewall and IDS/IPS evasion, self-injecting shells, and po… | 23 | 1954 | maintenance |
| w-digital-scanner/w13scan W13Scan is an open-source Python3 web vulnerability scanner supporting both passive (proxy-based) and active scanning modes. It ships with … | 32 | 1946 | maintenance |
| Xyntax/POC-T POC-T is a Python 2.7 plugin-based concurrent framework for penetration testing tasks such as crawling, bruteforcing, and batch PoC/EXP ver… | 23 | 1936 | maintenance |
| sense-of-security/ADRecon ADRecon is a PowerShell-based tool that extracts a wide range of artefacts from an Active Directory environment, including users, groups, t… | 32 | 1929 | maintenance |
| dirkjanm/mitm6 mitm6 is a Python pentesting tool that exploits Windows' default IPv6 configuration by answering DHCPv6 requests, assigning victims a link-… | 23 | 1918 | maintenance |
| SummerSec/SpringBootExploit A Java GUI tool for quickly exploiting Spring Boot actuator/env page vulnerabilities, built from the LandGrey SpringBootVulExploit checklis… | 10 | 1897 | maintenance |
| inbug-team/InScan InScan is a Go-based automated intranet penetration testing tool designed for use after breaching a network boundary. It provides port scan… | 32 | 1888 | maintenance |
| lobuhi/byp4xx byp4xx is a command-line tool written in Go that attempts to bypass HTTP 40X (access denied) responses using techniques like verb tampering… | 32 | 1888 | maintenance |
| corelan/mona mona.py is a Python plugin for debuggers (Immunity Debugger, x64dbg) that assists with exploit development tasks such as finding ROP gadget… | 10 | 1888 | maintenance |
| cobbr/SharpSploit SharpSploit is a .NET post-exploitation library written in C# that highlights the .NET attack surface for red teamers. It ports and extends… | 32 | 1884 | maintenance |
| google/security-research-pocs A collection of proof-of-concept exploit code produced during security research by the Google Security Team. It serves as a reference repos… | 10 | 1880 | maintenance |
| droe/sslsplit SSLsplit is a transparent SSL/TLS interception proxy for man-in-the-middle attacks against encrypted network connections. It terminates TLS… | 54 | 1876 | maintenance |
| 0xInfection/TIDoS-Framework TIDoS is a Python-based offensive web application penetration testing framework with a Metasploit-like console interface and an optional Qt… | 23 | 1868 | maintenance |
| orlyjamie/mimikittenz mimikittenz is a post-exploitation PowerShell tool that uses the Windows ReadProcessMemory() function to extract plain-text passwords and o… | 32 | 1867 | maintenance |
| trimstray/sandmap sandmap is a shell-based CLI wrapper around the Nmap engine that simplifies network and system reconnaissance. It offers 31 modules with 45… | 32 | 1862 | maintenance |
| eldraco/domain_analyzer Domain Analyzer is a Python-based security analysis tool that automatically discovers and reports information about a given domain, includi… | 32 | 1861 | maintenance |
| DanMcInerney/net-creds A Python command-line tool that sniffs passwords, hashes, and other sensitive data from a live network interface or a pcap file. It reassem… | 32 | 1859 | maintenance |
| jaykali/hackerpro HackerPro is an all-in-one penetration testing tool collection for Linux and Android (Termux) that bundles popular security tools like Nmap… | 32 | 1852 | maintenance |
| kozmer/log4j-shell-poc A proof-of-concept exploit tool for the Log4Shell vulnerability (CVE-2021-44228) in the Java log4j logging library. It automates setting up… | 10 | 1848 | maintenance |
| awake1t/linglong Linglong is a self-hosted asset reconnaissance and scanning system written in Go that continuously discovers network assets using masscan+n… | 32 | 1846 | maintenance |
| 1N3/Findsploit Findsploit is a simple bash script that instantly searches local and online exploit databases, including Exploit-DB, Metasploit modules, an… | 23 | 1846 | maintenance |
| wavestone-cdt/EDRSandblast EDRSandBlast is a C-based offensive security tool that weaponizes vulnerable signed drivers to bypass EDR detections on Windows, including … | 32 | 1844 | maintenance |
| CCob/SweetPotato SweetPotato is a C# command-line tool that collects multiple native Windows privilege escalation techniques (RottenPotato, PrintSpoofer, Ef… | 32 | 1839 | maintenance |
| Hackertrackersj/Instabruteforce A Python CLI tool that brute-forces Instagram account passwords using a wordlist and a rotating proxy list, with proxy scoring and pruning … | 32 | 1833 | maintenance |
| cyweb/hammer A Python 3 command-line script for performing DDoS (denial-of-service) flood attacks against target servers. It is a simple offensive secur… | 48 | 1832 | maintenance |
| sleventyeleven/linuxprivchecker A single-file Python script that enumerates a local Linux system and searches for common privilege escalation vectors such as world-writabl… | 32 | 1832 | maintenance |
| neex/phuip-fpizdam A Go-based exploit tool for CVE-2019-11043, a remote code execution vulnerability in php-fpm when used behind certain nginx configurations.… | 32 | 1831 | maintenance |
| p3nt4/PowerShdll PowerShdll is a C# tool that runs PowerShell commands and scripts without invoking powershell.exe, by loading PowerShell automation DLLs vi… | 23 | 1831 | maintenance |
| SysWhispers SysWhispers is a Python CLI tool that generates header and assembly files for making direct system calls on Windows, bypassing user-mode AP… | 32 | 1828 | maintenance |
| mm0r1/exploits A collection of PHP 'pwn' exploits that bypass the disable_functions restriction in PHP using known interpreter bugs (e.g., bug #81705, #72… | 32 | 1825 | maintenance |
| Matrix07ksa/Brute_Force A Python CLI tool that performs brute-force password attacks against Gmail, Hotmail, Twitter, Facebook, and Netflix accounts, with optional… | 32 | 1820 | maintenance |
| fsociety-team/fsociety fsociety is a modular penetration testing framework written in Python that wraps and organizes popular security tools (nmap, sqlmap, Sherlo… | 67 | 1819 | maintenance |
| klezVirus/inceptor Inceptor is a template-driven PE packer and AV/EDR evasion framework for Windows, aimed at penetration testers and red teamers. It automate… | 32 | 1817 | maintenance |
| whid-injector/WHID WHID Injector is an open-source WiFi HID injection tool that combines an ESP8266 with an ATmega32u4 to remotely deliver BadUSB keystroke at… | 32 | 1816 | maintenance |
| InteliSecureLabs/Linux_Exploit_Suggester A Perl script that suggests possible Linux kernel exploits based on the operating system release number (uname -r). It matches the kernel v… | 32 | 1812 | maintenance |
| hlldz/Phant0m Phant0m is a Windows Event Log Killer that identifies the process hosting the Windows Event Log service and terminates only its threads, so… | 10 | 1812 | maintenance |
| pmiaowu/BurpShiroPassiveScan A passive BurpSuite extension written in Java that automatically detects Apache Shiro framework usage and tests for known Shiro encryption … | 23 | 1806 | maintenance |
| KimJun1010/WeblogicTool A GUI-based vulnerability exploitation toolkit targeting Oracle WebLogic servers, supporting detection and exploitation of numerous CVEs vi… | 20 | 1804 | maintenance |
| Kevin-Robertson/Invoke-TheHash A collection of PowerShell functions for performing pass-the-hash attacks over WMI and SMB using NTLM hash authentication. It implements ra… | 32 | 1803 | maintenance |
| lockedbyte/CVE-2021-40444 A proof-of-concept exploit generator for CVE-2021-40444, a Microsoft Office Word remote code execution vulnerability. It generates maliciou… | 32 | 1800 | maintenance |
| Ha3MrX/DDos-Attack A simple Python script for launching DDoS (denial of service) attacks against online targets. It is a command-line tool intended for learni… | 66 | 1796 | maintenance |
| enjoiz/XXEinjector XXEinjector is a Ruby command-line tool that automates exploitation of XML External Entity (XXE) vulnerabilities using direct and out-of-ba… | 32 | 1795 | maintenance |
| sysdream/ligolo Ligolo is a lightweight Go tool for establishing SOCKS5 or TCP tunnels over reverse TLS connections, aimed at penetration testers pivoting … | 32 | 1788 | maintenance |
| iceyhexman/onlinetools A self-hosted web-based penetration testing toolbox written in Python that bundles common recon and scanning tasks behind a browser UI. It … | 10 | 1788 | maintenance |
| mrh0wl/Cloudmare Cloudmare is a Python CLI tool that discovers the origin servers of websites protected by Cloudflare, Sucuri, or Incapsula when their DNS i… | 10 | 1784 | maintenance |
| lucasjacks0n/EggShell EggShell is a Python-based post-exploitation surveillance and remote administration tool that provides a command-line session with a target… | 32 | 1768 | maintenance |
| s4n7h0/xvwa XVWA (Xtreme Vulnerable Web Application) is an intentionally insecure PHP/MySQL web application for learning application security. It conta… | 10 | 1763 | maintenance |
| tanweai/wooyun-legacy A Claude Code plugin that injects real-world case citations, statistics, and data-driven prioritization into AI-generated security reports,… | 57 | 1759 | maintenance |
| Moham3dRiahi/XAttacker XAttacker is a Perl-based command-line tool that scans websites for vulnerabilities and automatically exploits them. It detects the target'… | 32 | 1757 | maintenance |
| al0ne/Vxscan Vxscan is a Python3-based comprehensive security scanning tool for authorized penetration testing. It combines host liveness checks, port s… | 32 | 1755 | maintenance |
| DanMcInerney/xsscrapy A Python-based spider built on Scrapy that crawls a website and tests every link it finds for cross-site scripting (XSS) and basic SQL inje… | 32 | 1747 | maintenance |
| knownsec/shellcodeloader A Windows shellcode loader generator written in C++ that packages raw shellcode into encrypted executables with multiple loading techniques… | 23 | 1747 | maintenance |
| chenjj/espoofer espoofer is a Python-based testing tool that crafts spoofed emails to bypass SPF, DKIM, and DMARC authentication, including forged DKIM sig… | 32 | 1745 | maintenance |
| jtesta/ssh-mitm A penetration testing tool that intercepts SSH connections by running a patched OpenSSH v7.5p1 server as a proxy between a victim and their… | 10 | 1740 | maintenance |
| samdenty/Wi-PWN Wi-PWN is ESP8266 firmware for performing WiFi deauthentication attacks with a fast, responsive Material Design web UI. It includes an inte… | 23 | 1739 | maintenance |
| aahmad097/AlternativeShellcodeExec A collection of C++ examples demonstrating alternative Windows callback functions for executing position-independent shellcode, avoiding de… | 32 | 1736 | maintenance |
| lijiejie/ds_store_exp A Python CLI exploit tool that parses exposed .DS_Store files on web servers to enumerate hidden files and directories, then recursively do… | 32 | 1736 | maintenance |
| AnonHackerr/toolss A Python script that automatically installs a collection of hacking and penetration-testing tools on Android devices running Termux. It act… | 32 | 1734 | maintenance |
| m57/dnsteal dnsteal is a fake DNS server written in Python that enables stealthy exfiltration of files from a victim machine via DNS requests. It suppo… | 32 | 1730 | maintenance |
| EASY233/Finger Finger is a Python-based red team tool that performs liveness probing and web system fingerprint detection across large asset lists, identi… | 32 | 1724 | maintenance |
| antirez/hping hping3 is a command-line network tool that sends custom TCP/IP packets and displays target replies, similar to ping but supporting arbitrar… | 32 | 1714 | maintenance |
| sting8k/BurpSuite_403Bypasser A Burp Suite extension written in Python that automatically attempts to bypass 403 Forbidden responses on restricted directories. It hooks … | 32 | 1705 | maintenance |
| Err0r-ICA/TermuxCyberArmy TermuxCyberArmy is a shell/Python-based hacking toolkit script for the Termux terminal environment on Android. It bundles a collection of s… | 43 | 1701 | maintenance |
| The404Hacking/AndroRAT AndroRAT is a Remote Administration Tool (RAT) for Android, consisting of a Java Android client that runs as a background service and a Jav… | 32 | 1694 | maintenance |
| irsdl/IIS-ShortName-Scanner A Java-based scanner that detects and exploits the Microsoft IIS short file name (8.3) disclosure vulnerability using tilde (~) character r… | 32 | 1691 | maintenance |
| swisskyrepo/GraphQLmap GraphQLmap is a Python scripting engine and interactive CLI for interacting with GraphQL endpoints during penetration testing. It supports … | 32 | 1688 | maintenance |
| TryCatchHCF/Cloakify CloakifyFactory is a Python-based text-based steganography toolset that converts any file type into lists of innocuous everyday strings (e.… | 23 | 1683 | maintenance |
| eladshamir/Internal-Monologue A C# post-exploitation tool that retrieves NTLM hashes by inducing NetNTLM challenge-response computations in-process, without touching the… | 32 | 1681 | maintenance |
| Ghr07h/Heimdallr Heimdallr is a fully passive Chrome extension for security professionals that identifies high-risk vulnerability framework fingerprints in … | 23 | 1681 | maintenance |
| rasta-mouse/Watson Watson is a .NET console tool that enumerates missing Windows KB patches and suggests exploits for known privilege escalation vulnerabiliti… | 10 | 1680 | maintenance |
| threatexpress/domainhunter Domain Hunter is a Python CLI tool that finds expired or available domains with prior benign usage history via ExpiredDomains.net, then che… | 32 | 1678 | maintenance |
| krisnova/boopkit boopkit is a Linux rootkit and backdoor written in C that uses eBPF to enable remote command execution over raw TCP. It requires prior priv… | 23 | 1677 | maintenance |
| noob-hackers/kalimux Kalimux is a bash script that automatically installs Kali Linux with a GUI inside Termux on Android, without requiring root. It uses proot … | 32 | 1676 | maintenance |
| noob-hackers/grabcam Grabcam is a bash-based Termux script that generates a fake offer page and an ngrok link to trick a victim into granting camera access, cap… | 32 | 1674 | maintenance |
| SECFORCE/sparta SPARTA is a Python GUI application that simplifies network infrastructure penetration testing by streamlining the scanning and enumeration … | 23 | 1671 | maintenance |
| TheKingOfDuck/burpFakeIP A Burp Suite extension written in Java that forges IP addresses in HTTP request headers (X-Forwarded-For and similar) to test servers with … | 23 | 1668 | maintenance |
| Dheerajmadhukar/4-ZERO-3 4-ZERO-3 is a Bash-based security testing script that automates a wide range of techniques for bypassing HTTP 403/401 access restrictions o… | 32 | 1667 | maintenance |
| opensec-cn/kunpeng Kunpeng is an open-source vulnerability POC (proof-of-concept) detection framework written in Go, bundling POCs for databases, middleware, … | 23 | 1663 | maintenance |
| Dec0ne/KrbRelayUp KrbRelayUp is a C# command-line tool that wraps Rubeus and KrbRelay to automate a Kerberos relay-based local privilege escalation in Window… | 32 | 1657 | maintenance |
| Mr-Un1k0d3r/SCShell SCShell is a fileless lateral movement tool that executes commands on remote Windows systems by modifying a service's binary path via Chang… | 32 | 1655 | maintenance |
| Adminisme/ServerScan ServerScan is a high-concurrency network scanning and service detection tool written in Go, designed for intranet lateral information gathe… | 23 | 1655 | maintenance |
| d3vilbug/HackBar A Burp Suite plugin that adds a HackBar panel for quickly injecting common payloads like SQLi and XSS during manual web application testing… | 23 | 1632 | maintenance |
| veo/vscan vscan is an open-source, lightweight, fast, cross-platform website vulnerability scanner written in Go, built for red team reconnaissance. … | 23 | 1632 | maintenance |
| androidmalware/android_hid A set of shell scripts that turn a rooted Android device into a USB HID keyboard (Rubber Ducky style) to inject keystroke payloads into tar… | 32 | 1631 | maintenance |
| JohnHammond/msdt-follina A Python CLI tool that generates malicious Microsoft Word documents exploiting the MS-MSDT 'Follina' vulnerability (CVE-2022-30190) and sta… | 32 | 1630 | maintenance |
| jivoi/pentest A collection of Python and shell scripts for offensive security and penetration testing tasks, including host discovery, port scanning, and… | 32 | 1627 | maintenance |
| bdamele/icmpsh icmpsh is a simple reverse ICMP shell tool with a Windows slave (client) written in C and a portable master (server) implemented in C, Perl… | 32 | 1625 | maintenance |
| firesunCN/BlueLotus_XSSReceiver BlueLotus_XSSReceiver is a self-hosted XSS data receiving platform written in PHP and JavaScript, designed for CTF practice and security le… | 32 | 1623 | maintenance |
| sweetsoftware/Ares Ares is a Python-based remote access tool (RAT) consisting of a web-based command-and-control server and a lightweight agent that runs on t… | 32 | 1620 | maintenance |