Ross ROSS = Recommend OSS · open-source software intelligence for agents

function: penetration-testing

859 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
Z4nzu/hackingtool
An all-in-one, menu-driven Python toolkit that aggregates 215 curated security testing tools across 21 categories such as recon, OSINT, web…
7779125active
usestrix/strix
Strix is an open-source AI penetration testing tool that deploys autonomous agents to find, validate, and fix application vulnerabilities. …
8458564active
KeygraphHQ/shannon
Shannon is an open-source, autonomous AI pentester for web applications and APIs that runs locally from the command line. It analyzes sourc…
8447226active
Metasploit Framework
Metasploit Framework is the world's most widely used open-source penetration testing framework, providing a large collection of exploit, pa…
7738886active
sqlmapproject/sqlmap
sqlmap is an open-source penetration testing tool that automates the detection and exploitation of SQL injection flaws and the takeover of …
7538275stable
mukul975/Anthropic-Cybersecurity-Skills
A large open-source library of structured cybersecurity skills (Markdown files with YAML frontmatter) for AI coding agents, mapped to frame…
7831259active
zhaoxuya520/reverse-skill
A cybersecurity skill router pack that directs AI coding agents (Claude Code, Cursor, Cline, Kiro) to the right reverse-engineering, penetr…
6929591active
robertdavidgraham/masscan
Masscan is an Internet-scale TCP port scanner written in C that transmits 10 million SYN packets per second, capable of scanning the entire…
5825955active
vxcontrol/pentagi
PentAGI is a self-hosted, fully autonomous multi-agent AI system for performing complex penetration testing tasks, built in Go with a React…
7822033active
gentilkiwi/mimikatz
mimikatz is a well-known Windows security tool written in C that extracts plaintext passwords, hashes, PINs, and Kerberos tickets from memo…
5721799active
MobSF/Mobile-Security-Framework-MobSF
MobSF is an automated all-in-one mobile application security testing framework for Android, iOS, and Windows Mobile apps. It performs stati…
9421650active
peass-ng/PEASS-ng
PEASS-ng is a suite of privilege escalation enumeration scripts (LinPEAS for Linux/Unix/macOS and WinPEAS for Windows) that scan local syst…
9520381active
bettercap/bettercap
bettercap is a Go-based, all-in-one framework for network reconnaissance and man-in-the-middle attacks across WiFi, Bluetooth Low Energy, w…
8819865active
ZPhisher
Zphisher is a beginner-friendly, automated phishing toolkit written in Bash with 30+ ready-made login page templates. It supports multiple …
2316700active
MatrixTM/MHDDoS
MHDDoS is a Python 3 command-line DDoS attack script offering 57 flood methods across Layer 7 (HTTP) and Layer 4 (TCP/UDP), including bypas…
7416595active
ffuf/ffuf
ffuf is a fast web fuzzer written in Go used for discovering directories, virtual hosts, and parameters by brute-forcing HTTP requests. It …
9716593stable
zaproxy/zaproxy
Zed Attack Proxy (ZAP) by Checkmarx is a free, open-source web application security scanner used for finding vulnerabilities in web apps du…
7815686stable
trustedsec/social-engineer-toolkit
The Social-Engineer Toolkit (SET) is an open-source Python-based penetration testing framework for authorized social-engineering assessment…
7015239active
GreyDGL/PentestGPT
PentestGPT is an AI-powered penetration testing agent framework that drives LLMs (Claude Code, Codex, or many providers in legacy mode) to …
7015091active
maurosoria/dirsearch
dirsearch is an advanced web path scanner that brute-forces directories and files on web servers using wordlists. It is a Python CLI tool w…
8714662active
shadow1ng/fscan
Fscan is a comprehensive intranet scanning tool written in Go that automates host discovery, port scanning, service identification, weak-pa…
9514450active
OJ/gobuster
Gobuster is a fast, multi-threaded brute-forcing tool written in Go for enumerating web directories/files, DNS subdomains, virtual hosts, c…
8014038active
juice-shop/juice-shop
OWASP Juice Shop is an intentionally insecure web application written in Node.js, Express, and Angular that covers vulnerabilities from the…
9413726active
digininja/DVWA
Damn Vulnerable Web Application (DVWA) is a PHP/MariaDB web application intentionally riddled with common web vulnerabilities at multiple d…
7013551active
nmap/nmap
Nmap is the industry-standard open-source network scanner for host discovery, port scanning, service/version detection, and OS fingerprinti…
7713465stable
threat9/routersploit
RouterSploit is an open-source exploitation framework dedicated to embedded devices like routers, modeled after Metasploit. It provides mod…
5913223active
jopohl/urh
Universal Radio Hacker (URH) is a complete open-source suite for investigating wireless protocols, with native support for many common Soft…
1012569active
Atomic Red Team
Atomic Red Team is a library of small, portable detection tests mapped to the MITRE ATT&CK framework, letting security teams validate their…
7712457active
vanhauser-thc/thc-hydra
THC-Hydra is a parallelized network login cracker supporting dozens of protocols (SSH, FTP, HTTP forms, SMB, RDP, databases, and more). It …
8012200active
justcallmekoko/ESP32Marauder
ESP32 Marauder is a suite of WiFi and Bluetooth offensive and defensive security tools distributed as firmware for ESP32-based hardware. It…
9912134active
BishopFox/sliver
Sliver is an open-source cross-platform adversary emulation and red team framework written in Go. It generates dynamically compiled implant…
9011729active
chaitin/xray
xray is a security assessment tool from Chaitin that scans web applications for common vulnerabilities like XSS and SQL injection, supporti…
2311720active
0x4m4/hexstrike-ai
HexStrike AI is an MCP server that bridges LLM agents (Claude, GPT, Copilot) with 150+ cybersecurity tools for autonomous penetration testi…
6111381active
1N3/Sn1per
Sn1per is an open-source automated penetration testing and attack surface management platform that chains reconnaissance, scanning, exploit…
6311043active
beefproject/beef
BeEF (Browser Exploitation Framework) is a penetration testing tool focused on the web browser, hooking one or more browsers and using them…
7210983active
sullo/nikto
Nikto is a Perl-based command-line web server scanner that tests servers for dangerous files, outdated software, misconfigurations, and kno…
8910684active
samratashok/nishang
Nishang is a framework and collection of PowerShell scripts and payloads for offensive security, penetration testing, and red teaming. It c…
2310069active
malwaredllc/byob
BYOB is an open-source post-exploitation framework written in Python, featuring a command-and-control server with a web GUI, a cross-platfo…
769498active
sensepost/objection
objection is a runtime mobile exploration toolkit powered by Frida for assessing the security posture of iOS and Android applications witho…
889347active
NVIDIA/garak
garak is a command-line LLM vulnerability scanner that probes large language models for failures like hallucination, data leakage, prompt i…
919033active
frohoff/ysoserial
ysoserial is a proof-of-concept command-line tool that generates serialized Java payloads exploiting unsafe object deserialization using ga…
489033active
HavocFramework/Havoc
Havoc is a modern, malleable post-exploitation command and control (C2) framework with a Go teamserver, a Qt-based cross-platform client, a…
108507active
six2dez/reconftw
reconFTW is an open-source (MIT) automated reconnaissance framework written in Shell that orchestrates 80+ security tools to perform full r…
868025active
v1s1t0r1sh3r3/airgeddon
A multi-use bash script for auditing wireless networks on Linux, wrapping tools like aircrack-ng to automate attacks such as evil twin, WPS…
937952active
PCILeech
PCILeech is DMA attack software that uses PCIe hardware devices (or software memory acquisition methods) to read and write target system me…
657899active
mandiant/commando-vm
Commando VM is a fully customizable Windows-based security distribution for penetration testing and red teaming, packaged as a PowerShell i…
537791active
hfiref0x/UACME
UACMe is a C-based command-line tool that demonstrates dozens of Windows User Account Control (UAC) bypass techniques abusing built-in Auto…
877764active
yaklang/yakit
Yakit is an all-in-one interactive application security testing platform built as a GUI client for the Yaklang security DSL engine over gRP…
957700active
aircrack-ng/aircrack-ng
Aircrack-ng is a complete suite of command-line tools for assessing WiFi network security, covering packet capture, injection, monitor mode…
627541active
apache/caldera
Apache Caldera is a cybersecurity platform for automated adversary emulation built on the MITRE ATT&CK framework. It provides an asynchrono…
797213active
ayoubfaouzi/al-khaser
Al-Khaser is a proof-of-concept Windows application that demonstrates a wide range of malware anti-analysis techniques, including anti-debu…
737108active
guardicore/monkey
Infection Monkey is an open-source adversary emulation platform that simulates malware-like self-propagation across a network to test secur…
317076active
urbanadventurer/WhatWeb
WhatWeb is a command-line web scanner that identifies the technologies powering websites, including CMSs, web servers, JavaScript libraries…
766800stable
ticarpi/jwt_tool
A Python command-line toolkit for validating, forging, scanning, and tampering with JSON Web Tokens (JWTs). It automates checks for known J…
316754active
The-Z-Labs/linux-exploit-suggester
A shell-based auditing tool that assesses a Linux system's exposure to publicly known kernel privilege escalation exploits based on kernel …
656593active
BruceDevices/firmware
Bruce is an open-source (AGPL-3.0) ESP32 firmware packed with offensive-security and Red Team tools such as WiFi attacks, Evil Portal, ward…
906570active
j3ssie/osmedeus
Osmedeus is a security-focused declarative orchestration engine that lets users define reconnaissance and vulnerability-scanning pipelines …
936538active
EnableSecurity/wafw00f
WAFW00F is a Python command-line tool that identifies and fingerprints Web Application Firewall (WAF) products protecting a website. It sen…
796528stable
Mebus/cupp
CUPP is a Python CLI tool that generates targeted password wordlists by profiling personal information about a user, such as birthdays, nic…
746507active
zmap/zmap
ZMap is a fast, stateless single-packet network scanner written in C, designed for Internet-wide network surveys such as scanning the entir…
906366active
infinition/Bjorn
Bjorn is an autonomous network scanning and offensive security tool that runs on a Raspberry Pi with a 2.13-inch e-Paper HAT. It discovers …
636252active
k8gege/K8tools
K8tools is a large curated collection of penetration testing and offensive security tools covering internal network penetration, privilege …
346203active
GhostTroops/scan4all
scan4all is a Go-based automated vulnerability scanning and reconnaissance tool that integrates vscan, nuclei, ksubdomain, and subfinder. I…
236170active
AzeemIdrisi/PhoneSploit-Pro
PhoneSploit Pro is an all-in-one Python CLI tool for remotely exploiting and testing Android devices using ADB and the Metasploit Framework…
886128active
AutoRecon/AutoRecon
AutoRecon is a multi-threaded Python CLI tool that automates network reconnaissance by performing port and service detection scans, then la…
616093active
mishakorzik/AllHackingTools
AllHackingTools is an all-in-one installer and menu system for Termux that automates downloading and installing a large collection of penet…
566083active
Tencent/AI-Infra-Guard
Tencent's full-stack AI red teaming platform that scans AI infrastructure, agents, MCP servers, and skills for vulnerabilities and evaluate…
885984active
FluxionNetwork/fluxion
Fluxion is a security auditing and social-engineering research tool that retrieves WPA/WPA2 keys via phishing attacks using rogue access po…
915907active
RedSiege/EyeWitness
EyeWitness is a Python CLI tool that takes screenshots of websites using headless Chromium, captures server header information, and identif…
505829active
commixproject/commix
Commix (short for command injection exploiter) is an open-source penetration testing tool that automates the detection and exploitation of …
755824active
Pennyw0rth/NetExec
NetExec (nxc) is a community-maintained, open-source network execution tool and successor to CrackMapExec, used for pentesting and red-team…
745815active
elder-plinius/T3MP3ST
T3MP3ST is a multi-agent offensive-security framework that turns existing AI coding agents (Claude Code, Codex, Ollama, etc.) into autonomo…
585684active
trustedsec/ptf
The PenTesters Framework (PTF) is a Python-based modular framework that installs, compiles, and keeps penetration testing tools up to date …
325558active
OWASP/Nettacker
OWASP Nettacker is a Python-based automated penetration testing and information-gathering framework for reconnaissance, vulnerability scann…
885535active
Hackplayers/evil-winrm
Evil-WinRM is a Ruby-based command-line WinRM shell designed for hacking and penetration testing of Windows servers. It supports features l…
795448active
drk1wi/Modlishka
Modlishka is an open-source penetration testing tool written in Go that acts as a transparent man-in-the-middle reverse proxy. It can proxy…
665407active
PurpleAILAB/Decepticon
Decepticon is an autonomous AI red-team hacking agent that uses LLMs (built on LangChain/LangGraph) to plan and execute context-aware offen…
805335active
Ladon
Ladon is a large-scale internal network penetration scanner written in C#, offering port scanning, service identification, network asset di…
295320active
RhinoSecurityLabs/pacu
Pacu is an open-source AWS exploitation framework for offensive security testing of Amazon Web Services environments. It provides a modular…
735312active
hahwul/dalfox
Dalfox is an open-source XSS vulnerability scanner written in Rust that automates discovery, injection, and DOM/AST-level verification of r…
985256active
Ullaakut/cameradar
Cameradar is a Go-based command-line tool that scans targets for open RTSP video surveillance endpoints and uses dictionary attacks to disc…
945173active
techchipnet/CamPhish
CamPhish is a bash-based penetration-testing tool that hosts a fake webpage on a built-in PHP server and exposes it via ngrok or CloudFlare…
405020active
V4bel/dirtyfrag
Dirty Frag is a proof-of-concept Linux kernel local privilege escalation exploit written in C. It chains the xfrm-ESP (CVE-2026-43284) and …
504990active
cdk-team/CDK
CDK is a zero-dependency container penetration toolkit written in Go for security testing of Kubernetes, Docker, and Containerd environment…
704740active
its-a-feature/Mythic
Mythic is a collaborative, multi-platform post-exploitation red teaming framework built with Go, Docker, and a web browser UI. It provides …
784725active
ReversecLabs/drozer
drozer is an open-source security assessment framework for Android that lets testers assume the role of an app and interact with the Androi…
574597active
samsesh/SocialBox-Termux
SocialBox-Termux is a shell-based brute-force attack framework targeting social media and email services like Facebook, Gmail, Instagram, a…
724497active
Awarexone/Agentic-Bug-Hunter
An AI-powered bug bounty hunting toolkit that automates reconnaissance, vulnerability testing, finding validation, and report generation fo…
774464active
BeichenDream/Godzilla
Godzilla is a Java-based webshell management tool supporting dynamic payloads for JSP, ASPX, and PHP targets with multiple AES/XOR encrypto…
234455active
t3l3machus/Villain
Villain is a high-level stage 0/1 command-and-control (C2) framework written in Python that handles multiple reverse TCP and HoaxShell-base…
404439active
zan8in/afrog
afrog is an open-source security tool written in Go for vulnerability scanning using PoC (Proof of Concept) rules. It is designed for bug b…
964372active
microsoft/PyRIT
PyRIT is Microsoft's open-source Python framework for identifying security and safety risks in generative AI systems. It provides automatio…
884361active
TideSec/TscanPlus
TscanPlus is a comprehensive network security detection and operations tool for rapid asset discovery, identification, and vulnerability de…
824257active
jonaslejon/malicious-pdf
A Python CLI tool that generates 67 malicious PDF test files embedding callbacks for SSRF, XSS, XXE, NTLM credential theft, and data exfilt…
864254active
baihengaead/wlan-sec-test-tool
A Python-based GUI tool for wireless network security testing that checks WiFi networks for weak passwords by attempting connections with a…
704183active
guelfoweb/knockpy
KnockPy is a modular Python 3 CLI tool for enumerating subdomains of a target domain using passive reconnaissance sources and DNS bruteforc…
644178active
r0oth3x49/ghauri
Ghauri is a cross-platform Python CLI tool that automates detection and exploitation of SQL injection vulnerabilities in web applications. …
544070active
theori-io/copy-fail-CVE-2026-31431
A proof-of-concept exploit for CVE-2026-31431, a Linux kernel local privilege escalation bug in the authencesn cryptographic template that …
504049active
diego-treitos/linux-smart-enumeration
A POSIX-compliant shell script that enumerates a local Linux system's security posture to help escalate privileges during pentesting and CT…
593962active
trustedsec/unicorn
Magic Unicorn is a Python CLI tool that generates PowerShell downgrade-attack commands to inject shellcode directly into memory. It support…
703938active

page 1 / 9 next →