function: penetration-testing
859 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| Z4nzu/hackingtool An all-in-one, menu-driven Python toolkit that aggregates 215 curated security testing tools across 21 categories such as recon, OSINT, web… | 77 | 79125 | active |
| usestrix/strix Strix is an open-source AI penetration testing tool that deploys autonomous agents to find, validate, and fix application vulnerabilities. … | 84 | 58564 | active |
| KeygraphHQ/shannon Shannon is an open-source, autonomous AI pentester for web applications and APIs that runs locally from the command line. It analyzes sourc… | 84 | 47226 | active |
| Metasploit Framework Metasploit Framework is the world's most widely used open-source penetration testing framework, providing a large collection of exploit, pa… | 77 | 38886 | active |
| sqlmapproject/sqlmap sqlmap is an open-source penetration testing tool that automates the detection and exploitation of SQL injection flaws and the takeover of … | 75 | 38275 | stable |
| mukul975/Anthropic-Cybersecurity-Skills A large open-source library of structured cybersecurity skills (Markdown files with YAML frontmatter) for AI coding agents, mapped to frame… | 78 | 31259 | active |
| zhaoxuya520/reverse-skill A cybersecurity skill router pack that directs AI coding agents (Claude Code, Cursor, Cline, Kiro) to the right reverse-engineering, penetr… | 69 | 29591 | active |
| robertdavidgraham/masscan Masscan is an Internet-scale TCP port scanner written in C that transmits 10 million SYN packets per second, capable of scanning the entire… | 58 | 25955 | active |
| vxcontrol/pentagi PentAGI is a self-hosted, fully autonomous multi-agent AI system for performing complex penetration testing tasks, built in Go with a React… | 78 | 22033 | active |
| gentilkiwi/mimikatz mimikatz is a well-known Windows security tool written in C that extracts plaintext passwords, hashes, PINs, and Kerberos tickets from memo… | 57 | 21799 | active |
| MobSF/Mobile-Security-Framework-MobSF MobSF is an automated all-in-one mobile application security testing framework for Android, iOS, and Windows Mobile apps. It performs stati… | 94 | 21650 | active |
| peass-ng/PEASS-ng PEASS-ng is a suite of privilege escalation enumeration scripts (LinPEAS for Linux/Unix/macOS and WinPEAS for Windows) that scan local syst… | 95 | 20381 | active |
| bettercap/bettercap bettercap is a Go-based, all-in-one framework for network reconnaissance and man-in-the-middle attacks across WiFi, Bluetooth Low Energy, w… | 88 | 19865 | active |
| ZPhisher Zphisher is a beginner-friendly, automated phishing toolkit written in Bash with 30+ ready-made login page templates. It supports multiple … | 23 | 16700 | active |
| MatrixTM/MHDDoS MHDDoS is a Python 3 command-line DDoS attack script offering 57 flood methods across Layer 7 (HTTP) and Layer 4 (TCP/UDP), including bypas… | 74 | 16595 | active |
| ffuf/ffuf ffuf is a fast web fuzzer written in Go used for discovering directories, virtual hosts, and parameters by brute-forcing HTTP requests. It … | 97 | 16593 | stable |
| zaproxy/zaproxy Zed Attack Proxy (ZAP) by Checkmarx is a free, open-source web application security scanner used for finding vulnerabilities in web apps du… | 78 | 15686 | stable |
| trustedsec/social-engineer-toolkit The Social-Engineer Toolkit (SET) is an open-source Python-based penetration testing framework for authorized social-engineering assessment… | 70 | 15239 | active |
| GreyDGL/PentestGPT PentestGPT is an AI-powered penetration testing agent framework that drives LLMs (Claude Code, Codex, or many providers in legacy mode) to … | 70 | 15091 | active |
| maurosoria/dirsearch dirsearch is an advanced web path scanner that brute-forces directories and files on web servers using wordlists. It is a Python CLI tool w… | 87 | 14662 | active |
| shadow1ng/fscan Fscan is a comprehensive intranet scanning tool written in Go that automates host discovery, port scanning, service identification, weak-pa… | 95 | 14450 | active |
| OJ/gobuster Gobuster is a fast, multi-threaded brute-forcing tool written in Go for enumerating web directories/files, DNS subdomains, virtual hosts, c… | 80 | 14038 | active |
| juice-shop/juice-shop OWASP Juice Shop is an intentionally insecure web application written in Node.js, Express, and Angular that covers vulnerabilities from the… | 94 | 13726 | active |
| digininja/DVWA Damn Vulnerable Web Application (DVWA) is a PHP/MariaDB web application intentionally riddled with common web vulnerabilities at multiple d… | 70 | 13551 | active |
| nmap/nmap Nmap is the industry-standard open-source network scanner for host discovery, port scanning, service/version detection, and OS fingerprinti… | 77 | 13465 | stable |
| threat9/routersploit RouterSploit is an open-source exploitation framework dedicated to embedded devices like routers, modeled after Metasploit. It provides mod… | 59 | 13223 | active |
| jopohl/urh Universal Radio Hacker (URH) is a complete open-source suite for investigating wireless protocols, with native support for many common Soft… | 10 | 12569 | active |
| Atomic Red Team Atomic Red Team is a library of small, portable detection tests mapped to the MITRE ATT&CK framework, letting security teams validate their… | 77 | 12457 | active |
| vanhauser-thc/thc-hydra THC-Hydra is a parallelized network login cracker supporting dozens of protocols (SSH, FTP, HTTP forms, SMB, RDP, databases, and more). It … | 80 | 12200 | active |
| justcallmekoko/ESP32Marauder ESP32 Marauder is a suite of WiFi and Bluetooth offensive and defensive security tools distributed as firmware for ESP32-based hardware. It… | 99 | 12134 | active |
| BishopFox/sliver Sliver is an open-source cross-platform adversary emulation and red team framework written in Go. It generates dynamically compiled implant… | 90 | 11729 | active |
| chaitin/xray xray is a security assessment tool from Chaitin that scans web applications for common vulnerabilities like XSS and SQL injection, supporti… | 23 | 11720 | active |
| 0x4m4/hexstrike-ai HexStrike AI is an MCP server that bridges LLM agents (Claude, GPT, Copilot) with 150+ cybersecurity tools for autonomous penetration testi… | 61 | 11381 | active |
| 1N3/Sn1per Sn1per is an open-source automated penetration testing and attack surface management platform that chains reconnaissance, scanning, exploit… | 63 | 11043 | active |
| beefproject/beef BeEF (Browser Exploitation Framework) is a penetration testing tool focused on the web browser, hooking one or more browsers and using them… | 72 | 10983 | active |
| sullo/nikto Nikto is a Perl-based command-line web server scanner that tests servers for dangerous files, outdated software, misconfigurations, and kno… | 89 | 10684 | active |
| samratashok/nishang Nishang is a framework and collection of PowerShell scripts and payloads for offensive security, penetration testing, and red teaming. It c… | 23 | 10069 | active |
| malwaredllc/byob BYOB is an open-source post-exploitation framework written in Python, featuring a command-and-control server with a web GUI, a cross-platfo… | 76 | 9498 | active |
| sensepost/objection objection is a runtime mobile exploration toolkit powered by Frida for assessing the security posture of iOS and Android applications witho… | 88 | 9347 | active |
| NVIDIA/garak garak is a command-line LLM vulnerability scanner that probes large language models for failures like hallucination, data leakage, prompt i… | 91 | 9033 | active |
| frohoff/ysoserial ysoserial is a proof-of-concept command-line tool that generates serialized Java payloads exploiting unsafe object deserialization using ga… | 48 | 9033 | active |
| HavocFramework/Havoc Havoc is a modern, malleable post-exploitation command and control (C2) framework with a Go teamserver, a Qt-based cross-platform client, a… | 10 | 8507 | active |
| six2dez/reconftw reconFTW is an open-source (MIT) automated reconnaissance framework written in Shell that orchestrates 80+ security tools to perform full r… | 86 | 8025 | active |
| v1s1t0r1sh3r3/airgeddon A multi-use bash script for auditing wireless networks on Linux, wrapping tools like aircrack-ng to automate attacks such as evil twin, WPS… | 93 | 7952 | active |
| PCILeech PCILeech is DMA attack software that uses PCIe hardware devices (or software memory acquisition methods) to read and write target system me… | 65 | 7899 | active |
| mandiant/commando-vm Commando VM is a fully customizable Windows-based security distribution for penetration testing and red teaming, packaged as a PowerShell i… | 53 | 7791 | active |
| hfiref0x/UACME UACMe is a C-based command-line tool that demonstrates dozens of Windows User Account Control (UAC) bypass techniques abusing built-in Auto… | 87 | 7764 | active |
| yaklang/yakit Yakit is an all-in-one interactive application security testing platform built as a GUI client for the Yaklang security DSL engine over gRP… | 95 | 7700 | active |
| aircrack-ng/aircrack-ng Aircrack-ng is a complete suite of command-line tools for assessing WiFi network security, covering packet capture, injection, monitor mode… | 62 | 7541 | active |
| apache/caldera Apache Caldera is a cybersecurity platform for automated adversary emulation built on the MITRE ATT&CK framework. It provides an asynchrono… | 79 | 7213 | active |
| ayoubfaouzi/al-khaser Al-Khaser is a proof-of-concept Windows application that demonstrates a wide range of malware anti-analysis techniques, including anti-debu… | 73 | 7108 | active |
| guardicore/monkey Infection Monkey is an open-source adversary emulation platform that simulates malware-like self-propagation across a network to test secur… | 31 | 7076 | active |
| urbanadventurer/WhatWeb WhatWeb is a command-line web scanner that identifies the technologies powering websites, including CMSs, web servers, JavaScript libraries… | 76 | 6800 | stable |
| ticarpi/jwt_tool A Python command-line toolkit for validating, forging, scanning, and tampering with JSON Web Tokens (JWTs). It automates checks for known J… | 31 | 6754 | active |
| The-Z-Labs/linux-exploit-suggester A shell-based auditing tool that assesses a Linux system's exposure to publicly known kernel privilege escalation exploits based on kernel … | 65 | 6593 | active |
| BruceDevices/firmware Bruce is an open-source (AGPL-3.0) ESP32 firmware packed with offensive-security and Red Team tools such as WiFi attacks, Evil Portal, ward… | 90 | 6570 | active |
| j3ssie/osmedeus Osmedeus is a security-focused declarative orchestration engine that lets users define reconnaissance and vulnerability-scanning pipelines … | 93 | 6538 | active |
| EnableSecurity/wafw00f WAFW00F is a Python command-line tool that identifies and fingerprints Web Application Firewall (WAF) products protecting a website. It sen… | 79 | 6528 | stable |
| Mebus/cupp CUPP is a Python CLI tool that generates targeted password wordlists by profiling personal information about a user, such as birthdays, nic… | 74 | 6507 | active |
| zmap/zmap ZMap is a fast, stateless single-packet network scanner written in C, designed for Internet-wide network surveys such as scanning the entir… | 90 | 6366 | active |
| infinition/Bjorn Bjorn is an autonomous network scanning and offensive security tool that runs on a Raspberry Pi with a 2.13-inch e-Paper HAT. It discovers … | 63 | 6252 | active |
| k8gege/K8tools K8tools is a large curated collection of penetration testing and offensive security tools covering internal network penetration, privilege … | 34 | 6203 | active |
| GhostTroops/scan4all scan4all is a Go-based automated vulnerability scanning and reconnaissance tool that integrates vscan, nuclei, ksubdomain, and subfinder. I… | 23 | 6170 | active |
| AzeemIdrisi/PhoneSploit-Pro PhoneSploit Pro is an all-in-one Python CLI tool for remotely exploiting and testing Android devices using ADB and the Metasploit Framework… | 88 | 6128 | active |
| AutoRecon/AutoRecon AutoRecon is a multi-threaded Python CLI tool that automates network reconnaissance by performing port and service detection scans, then la… | 61 | 6093 | active |
| mishakorzik/AllHackingTools AllHackingTools is an all-in-one installer and menu system for Termux that automates downloading and installing a large collection of penet… | 56 | 6083 | active |
| Tencent/AI-Infra-Guard Tencent's full-stack AI red teaming platform that scans AI infrastructure, agents, MCP servers, and skills for vulnerabilities and evaluate… | 88 | 5984 | active |
| FluxionNetwork/fluxion Fluxion is a security auditing and social-engineering research tool that retrieves WPA/WPA2 keys via phishing attacks using rogue access po… | 91 | 5907 | active |
| RedSiege/EyeWitness EyeWitness is a Python CLI tool that takes screenshots of websites using headless Chromium, captures server header information, and identif… | 50 | 5829 | active |
| commixproject/commix Commix (short for command injection exploiter) is an open-source penetration testing tool that automates the detection and exploitation of … | 75 | 5824 | active |
| Pennyw0rth/NetExec NetExec (nxc) is a community-maintained, open-source network execution tool and successor to CrackMapExec, used for pentesting and red-team… | 74 | 5815 | active |
| elder-plinius/T3MP3ST T3MP3ST is a multi-agent offensive-security framework that turns existing AI coding agents (Claude Code, Codex, Ollama, etc.) into autonomo… | 58 | 5684 | active |
| trustedsec/ptf The PenTesters Framework (PTF) is a Python-based modular framework that installs, compiles, and keeps penetration testing tools up to date … | 32 | 5558 | active |
| OWASP/Nettacker OWASP Nettacker is a Python-based automated penetration testing and information-gathering framework for reconnaissance, vulnerability scann… | 88 | 5535 | active |
| Hackplayers/evil-winrm Evil-WinRM is a Ruby-based command-line WinRM shell designed for hacking and penetration testing of Windows servers. It supports features l… | 79 | 5448 | active |
| drk1wi/Modlishka Modlishka is an open-source penetration testing tool written in Go that acts as a transparent man-in-the-middle reverse proxy. It can proxy… | 66 | 5407 | active |
| PurpleAILAB/Decepticon Decepticon is an autonomous AI red-team hacking agent that uses LLMs (built on LangChain/LangGraph) to plan and execute context-aware offen… | 80 | 5335 | active |
| Ladon Ladon is a large-scale internal network penetration scanner written in C#, offering port scanning, service identification, network asset di… | 29 | 5320 | active |
| RhinoSecurityLabs/pacu Pacu is an open-source AWS exploitation framework for offensive security testing of Amazon Web Services environments. It provides a modular… | 73 | 5312 | active |
| hahwul/dalfox Dalfox is an open-source XSS vulnerability scanner written in Rust that automates discovery, injection, and DOM/AST-level verification of r… | 98 | 5256 | active |
| Ullaakut/cameradar Cameradar is a Go-based command-line tool that scans targets for open RTSP video surveillance endpoints and uses dictionary attacks to disc… | 94 | 5173 | active |
| techchipnet/CamPhish CamPhish is a bash-based penetration-testing tool that hosts a fake webpage on a built-in PHP server and exposes it via ngrok or CloudFlare… | 40 | 5020 | active |
| V4bel/dirtyfrag Dirty Frag is a proof-of-concept Linux kernel local privilege escalation exploit written in C. It chains the xfrm-ESP (CVE-2026-43284) and … | 50 | 4990 | active |
| cdk-team/CDK CDK is a zero-dependency container penetration toolkit written in Go for security testing of Kubernetes, Docker, and Containerd environment… | 70 | 4740 | active |
| its-a-feature/Mythic Mythic is a collaborative, multi-platform post-exploitation red teaming framework built with Go, Docker, and a web browser UI. It provides … | 78 | 4725 | active |
| ReversecLabs/drozer drozer is an open-source security assessment framework for Android that lets testers assume the role of an app and interact with the Androi… | 57 | 4597 | active |
| samsesh/SocialBox-Termux SocialBox-Termux is a shell-based brute-force attack framework targeting social media and email services like Facebook, Gmail, Instagram, a… | 72 | 4497 | active |
| Awarexone/Agentic-Bug-Hunter An AI-powered bug bounty hunting toolkit that automates reconnaissance, vulnerability testing, finding validation, and report generation fo… | 77 | 4464 | active |
| BeichenDream/Godzilla Godzilla is a Java-based webshell management tool supporting dynamic payloads for JSP, ASPX, and PHP targets with multiple AES/XOR encrypto… | 23 | 4455 | active |
| t3l3machus/Villain Villain is a high-level stage 0/1 command-and-control (C2) framework written in Python that handles multiple reverse TCP and HoaxShell-base… | 40 | 4439 | active |
| zan8in/afrog afrog is an open-source security tool written in Go for vulnerability scanning using PoC (Proof of Concept) rules. It is designed for bug b… | 96 | 4372 | active |
| microsoft/PyRIT PyRIT is Microsoft's open-source Python framework for identifying security and safety risks in generative AI systems. It provides automatio… | 88 | 4361 | active |
| TideSec/TscanPlus TscanPlus is a comprehensive network security detection and operations tool for rapid asset discovery, identification, and vulnerability de… | 82 | 4257 | active |
| jonaslejon/malicious-pdf A Python CLI tool that generates 67 malicious PDF test files embedding callbacks for SSRF, XSS, XXE, NTLM credential theft, and data exfilt… | 86 | 4254 | active |
| baihengaead/wlan-sec-test-tool A Python-based GUI tool for wireless network security testing that checks WiFi networks for weak passwords by attempting connections with a… | 70 | 4183 | active |
| guelfoweb/knockpy KnockPy is a modular Python 3 CLI tool for enumerating subdomains of a target domain using passive reconnaissance sources and DNS bruteforc… | 64 | 4178 | active |
| r0oth3x49/ghauri Ghauri is a cross-platform Python CLI tool that automates detection and exploitation of SQL injection vulnerabilities in web applications. … | 54 | 4070 | active |
| theori-io/copy-fail-CVE-2026-31431 A proof-of-concept exploit for CVE-2026-31431, a Linux kernel local privilege escalation bug in the authencesn cryptographic template that … | 50 | 4049 | active |
| diego-treitos/linux-smart-enumeration A POSIX-compliant shell script that enumerates a local Linux system's security posture to help escalate privileges during pentesting and CT… | 59 | 3962 | active |
| trustedsec/unicorn Magic Unicorn is a Python CLI tool that generates PowerShell downgrade-attack commands to inject shellcode directly into memory. It support… | 70 | 3938 | active |
page 1 / 9 next →