function: penetration-testing
859 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| itm4n/PrivescCheck A PowerShell enumeration script that identifies common Windows privilege escalation vulnerabilities and misconfigurations. It also collects… | 98 | 3928 | active |
| leebaird/discover A collection of custom Bash and Python scripts that automate penetration testing tasks including reconnaissance, scanning, enumeration, and… | 77 | 3928 | active |
| lanjelot/patator Patator is a multi-purpose, multi-threaded brute-forcing tool written in Python with a modular design supporting dozens of protocols (SSH, … | 42 | 3923 | active |
| cifertech/ESP32-DIV ESP32-DIV is open-source firmware (with open schematics and PCB files) for a custom ESP32-S3 handheld device that bundles Wi-Fi, BLE, 2.4GH… | 89 | 3890 | active |
| ambionics/phpggc PHPGGC is a library of PHP unserialize() payloads (gadget chains) with a command-line tool to generate them, covering frameworks like Larav… | 52 | 3876 | active |
| Pocsuite pocsuite3 is an open-source remote vulnerability testing and proof-of-concept development framework by Knownsec's 404 Team. It provides a P… | 27 | 3872 | active |
| elementalsouls/Claude-BugHunter A Claude Code skill bundle that turns Claude into a bug-hunting and red-team assistant, with 83 skills, 15 slash commands, and 681 disclose… | 77 | 3801 | active |
| pwntester/ysoserial.net ysoserial.net is a proof-of-concept command-line tool that generates deserialization payloads exploiting unsafe .NET object deserialization… | 62 | 3782 | active |
| scipag/vulscan Vulscan is an Nmap NSE script that turns Nmap into a vulnerability scanner by matching version-detected services against offline vulnerabil… | 52 | 3780 | active |
| RhinoSecurityLabs/cloudgoat CloudGoat is Rhino Security Labs' 'Vulnerable by Design' AWS deployment tool that provisions intentionally vulnerable cloud environments fo… | 78 | 3708 | active |
| S3cur3Th1sSh1t/WinPwn WinPwn is a PowerShell-based automation framework for internal Windows penetration testing and Active Directory security assessment. It bun… | 40 | 3693 | active |
| gadievron/raptor RAPTOR is an autonomous offensive/defensive security research framework built on top of Claude Code, chaining static analysis, binary analy… | 66 | 3672 | active |
| ly4k/Certipy Certipy is a Python CLI toolkit for enumerating and abusing Active Directory Certificate Services (AD CS) misconfigurations. It detects and… | 94 | 3643 | active |
| sooryathejas/METATRON METATRON is a CLI-based AI penetration testing assistant that runs a local LLM (via Ollama) entirely offline on Linux, primarily Parrot OS.… | 48 | 3616 | active |
| swisskyrepo/SSRFmap SSRFmap is a Python CLI framework that automatically detects and exploits Server-Side Request Forgery vulnerabilities. It takes a Burp Suit… | 76 | 3608 | active |
| s0md3v/XSStrike XSStrike is a Python command-line Cross Site Scripting (XSS) detection suite that uses hand-written HTML/JavaScript parsers, context analys… | 31 | 15151 | maintenance |
| arch3rPro/Pentest-Windows A pre-built Windows 11 penetration testing virtual machine image bundling 400+ security tools and scripts, distributed for VMware, Parallel… | 47 | 3549 | active |
| epinna/weevely3 Weevely is a weaponized web shell for post-exploitation that generates a small obfuscated PHP agent to upload to a target web server, provi… | 46 | 3533 | active |
| wifiphisher/wifiphisher Wifiphisher is a rogue Access Point framework for Wi-Fi security testing and red team engagements, enabling man-in-the-middle positioning v… | 60 | 14788 | maintenance |
| t3l3machus/hoaxshell Hoaxshell is a Windows reverse shell payload generator and handler that abuses the HTTP(S) protocol to establish a beacon-like reverse shel… | 33 | 3487 | active |
| BlackArch Linux BlackArch Linux is an Arch Linux-based penetration testing distribution bundling over 2,800 security tools for penetration testers and secu… | 77 | 3474 | active |
| ropnop/kerbrute Kerbrute is a Go-based CLI tool for brute-forcing and enumerating valid Active Directory accounts through Kerberos Pre-Authentication. It o… | 23 | 3429 | stable |
| EntySec/Ghost Ghost Framework is a Python-based Android post-exploitation framework that leverages the Android Debug Bridge (ADB) to gain remote access t… | 54 | 3392 | active |
| H4ckForJob/dirmap Dirmap is an advanced web directory and file scanning tool written in Python, designed to be more powerful than DirBuster, Dirsearch, cansi… | 44 | 3374 | stable |
| skelsec/pypykatz pypykatz is a pure Python implementation of parts of Mimikatz, the well-known Windows credential extraction tool. It parses LSASS process m… | 65 | 3352 | active |
| almandin/fuxploider Fuxploider is an open-source penetration testing tool that automates detection and exploitation of file upload form vulnerabilities. It ide… | 32 | 3328 | active |
| dbisu/pico-ducky A project that turns a Raspberry Pi Pico into a USB Rubber Ducky-style HID injection device running CircuitPython. It executes Ducky Script… | 71 | 3307 | active |
| chipsec/chipsec CHIPSEC is a Python framework for analyzing the security of PC platforms, including hardware, system firmware (BIOS/UEFI), and platform com… | 98 | 3295 | active |
| dafthack/MailSniper MailSniper is a PowerShell-based penetration testing tool for searching email in Microsoft Exchange environments for sensitive terms like p… | 77 | 3276 | active |
| rtcatc/Packer-Fuzzer Packer Fuzzer is a Python-based security scanner that targets websites built with JavaScript module bundlers like Webpack. It automatically… | 23 | 3249 | active |
| D3Ext/WEF WEF is a Wi-Fi Exploitation Framework written in Bash that automates a wide range of wireless attacks against WPA/WPA2/WPA3, WPS, and WEP n… | 52 | 3209 | active |
| jaykali/maskphish MaskPhish is a simple Bash script that masks phishing URLs under normal-looking URLs (e.g., google.com or facebook.com) as a proof of conce… | 42 | 3191 | active |
| 21y4d/nmapAutomator nmapAutomator is a POSIX-compatible shell script that automates nmap-based network reconnaissance and enumeration, running scans in the bac… | 32 | 3109 | active |
| cloudflare/security-audit-skill A coding-agent skill from Cloudflare that turns an LLM coding agent into a security auditor via a six-phase pipeline (recon, hunting, valid… | 54 | 3077 | active |
| ThePorgs/Exegol Exegol is a container-based, community-driven hacking environment for offensive security professionals, managed through a Python CLI wrappe… | 97 | 3072 | active |
| Kevin-Robertson/Inveigh Inveigh is a cross-platform .NET IPv4/IPv6 machine-in-the-middle tool for penetration testers, with a primary C# version and a legacy Power… | 53 | 3014 | active |
| GH05TCREW/pentestagent PentestAgent is a Python-based AI agent framework for black-box penetration testing that orchestrates LLM-driven security testing workflows… | 62 | 3010 | active |
| mgeeky/Penetration-Testing-Tools A curated collection of 170+ penetration testing tools, scripts, and cheatsheets developed by the author over years of red teaming and IT s… | 32 | 3001 | active |
| Netw0rkNoob/VulnClaw VulnClaw is an AI-driven penetration testing CLI tool that combines an LLM agent, MCP toolchain, and curated pentest skills to automate the… | 80 | 2997 | active |
| tegal1337/CiLocks CiLocks is a menu-driven Linux CLI toolkit for Android and iOS security testing, bundling lockscreen brute-force/bypass, ADB data extractio… | 23 | 2991 | active |
| Manisso/fsociety Fsociety is a Python-based penetration testing framework that bundles a menu of hacking tools covering information gathering, password atta… | 74 | 12275 | maintenance |
| makoto56/penetration-suite-toolkit A preconfigured Windows 11 penetration testing toolkit distributed as a VM image, bundling a large curated collection of security tools wit… | 34 | 2970 | active |
| TheOfficialFloW/PPPwn PPPwn is a proof-of-concept kernel remote code execution exploit for PlayStation 4 consoles up to firmware 11.00, exploiting CVE-2006-4304 … | 24 | 2960 | active |
| thewhiteh4t/FinalRecon FinalRecon is an all-in-one automatic web reconnaissance tool written in Python that provides a fast overview of a web target. It bundles h… | 70 | 2953 | active |
| calebstewart/pwncat pwncat is a post-exploitation platform and handler for reverse and bind shells, written in Python. It wraps raw shell communication with an… | 10 | 2917 | active |
| palahsu/DDoS-Ripper DDoS-Ripper (DRipper) is a Python command-line tool that floods a target IP with traffic to simulate a distributed denial-of-service attack… | 72 | 2914 | active |
| jayofelony/pwnagotchi Pwnagotchi is a Raspberry Pi-based Wi-Fi penetration-testing gadget that leverages Bettercap to passively sniff or actively attack nearby W… | 93 | 2886 | active |
| i-am-shodan/USBArmyKnife USB Army Knife is firmware for ESP32-based USB devices (like the T-Dongle-S3) that turns them into a close-access penetration testing tool.… | 71 | 2870 | active |
| LimerBoy/Impulse Impulse is a Python-based denial-of-service toolkit that bundles multiple attack methods including SYN, UDP, ICMP, HTTP floods, Slowloris, … | 39 | 2840 | active |
| gkbrk/slowloris A Python rewrite of the Slowloris low-bandwidth HTTP Denial of Service attack tool. It holds many connections open to threaded web servers … | 32 | 2820 | stable |
| screetsec/TheFatRat TheFatRat is a menu-driven exploiting tool that automates MSFvenom and Metasploit to generate backdoors and payloads for Windows, Linux, Ma… | 23 | 11444 | maintenance |
| digininja/CeWL CeWL is a Ruby command-line tool that spiders a target website to a specified depth and collects unique words into a custom wordlist for us… | 63 | 2801 | stable |
| Impact-I/reFlutter reFlutter is a Python CLI framework for reverse engineering Flutter mobile apps by repacking APK/IPA files with a specially patched, precom… | 95 | 2738 | active |
| NetSPI/PowerUpSQL PowerUpSQL is a PowerShell toolkit for attacking and auditing SQL Server instances, supporting discovery, weak configuration auditing, priv… | 32 | 2737 | active |
| ankit0183/Wifi-Hacking A Python-based menu-driven CLI tool that automates Wi-Fi penetration testing by wrapping built-in Kali Linux wireless tools. It supports mo… | 59 | 2667 | active |
| confident-ai/deepteam DeepTeam is an open-source Python framework for red teaming LLM systems, AI agents, RAG pipelines, and chatbots. It simulates adversarial a… | 67 | 2623 | active |
| SummerSec/ShiroAttack2 A Java-based exploitation tool for the Apache Shiro-550 rememberMe deserialization vulnerability, offering both a JavaFX GUI and a CLI. It … | 88 | 2619 | active |
| BishopFox/cloudfox CloudFox is an open-source command line tool by Bishop Fox that automates situational awareness and enumeration in cloud environments, prim… | 90 | 2563 | active |
| caido/caido Caido is a lightweight web security auditing toolkit and HTTP proxy for intercepting, viewing, and modifying traffic between browsers and w… | 99 | 2558 | active |
| s0lst1c3/eaphammer EAPHammer is a toolkit for performing targeted evil twin attacks against WPA2-Enterprise networks, including credential stealing and hostil… | 23 | 2552 | active |
| lgandx/PCredz PCredz is a Python CLI tool that extracts credentials and authentication tokens (NTLM, Kerberos, HTTP Basic, FTP, SMTP, IMAP, POP3, LDAP, S… | 64 | 2548 | active |
| 7h30th3r0n3/Evil-M5Project Evil-M5Project is a C++ firmware/tool for M5Stack devices (Cardputer, AtomS3, Fire, Core2) that scans, monitors, and interacts with WiFi ne… | 70 | 2543 | active |
| x90skysn3k/brutespray Brutespray is a fast, multi-protocol credential brute-forcing tool written in Go. It parses scan output from Nmap, Nessus, Nexpose, JSON, a… | 95 | 2525 | active |
| tobiabocchi/flipperzero-bruteforce A Python script that generates .sub files for brute-forcing fixed OOK code subghz protocols using a Flipper Zero device. It supports multip… | 32 | 2512 | active |
| nil0x42/phpsploit PhpSploit is a full-featured command-and-control (C2) framework that persists on a webserver via a stealthy single-line PHP backdoor. It is… | 23 | 2491 | active |
| TH3xACE/SUDO_KILLER SUDO_KILLER is a Shell-based security tool that audits Linux systems for sudo-related privilege escalation vectors, including misconfigurat… | 64 | 2481 | active |
| sabri-zaki/EasY_HaCk EasY_HaCk is a Termux-based penetration testing menu tool that bundles and installs tools like Metasploit, Nmap, SQLmap, and recon-ng for n… | 43 | 2471 | active |
| Idov31/Nidhogg Nidhogg is an open-source Windows x64 kernel rootkit written in C++ that demonstrates a wide range of rootkit techniques such as process, t… | 83 | 2463 | active |
| Notselwyn/CVE-2024-1086 A proof-of-concept local privilege escalation exploit for CVE-2024-1086, a double-free vulnerability in the Linux kernel's nf_tables subsys… | 16 | 2457 | stable |
| noob-hackers/hacklock Hacklock is a bash-based Termux tool that generates pattern phishing pages to capture an Android victim's unlock pattern via a shared link … | 53 | 2445 | active |
| m0nad/Diamorphine Diamorphine is a loadable kernel module (LKM) rootkit for Linux kernels 2.6.x through 6.x on x86/x86_64 and ARM64. It demonstrates rootkit … | 68 | 2442 | active |
| XSS Hunter XSS Hunter Express is a self-hosted service for tracking and detecting blind cross-site scripting (XSS) vulnerabilities via injected payloa… | 32 | 2440 | active |
| dirkjanm/BloodHound.py BloodHound.py is a Python-based data ingestor for BloodHound that enumerates Active Directory domains, collecting users, groups, computers,… | 54 | 2437 | active |
| ZerBea/hcxtools A set of C command-line tools that convert WiFi packet captures (pcap/pcapng) into hash formats compatible with Hashcat and John the Ripper… | 79 | 2431 | active |
| NetSPI/MicroBurst MicroBurst is a PowerShell toolkit for assessing Microsoft Azure security, including service discovery, weak configuration auditing, and po… | 73 | 2426 | active |
| GiacomoLaw/Keylogger A simple, bare-bones keylogger that records keystrokes and saves them to a local log file, with separate implementations for Windows, Linux… | 39 | 2421 | active |
| oritera/Cairn Cairn is a general-purpose AI state-space search engine built on a blackboard architecture with a fact-intent graph, where LLM agent worker… | 72 | 2395 | active |
| DataDog/stratus-red-team Stratus Red Team is a self-contained Go CLI that emulates granular, actionable cloud attack techniques mapped to MITRE ATT&CK, against AWS,… | 99 | 2379 | active |
| jorhelp/Ingram Ingram is a Python-based vulnerability scanning framework targeting network cameras (IP/CCTV devices). It integrates known exploits for com… | 67 | 2356 | active |
| samugit83/redamon RedAmon is an AI-powered agentic red team framework that automates offensive security operations end-to-end, chaining reconnaissance, explo… | 81 | 2354 | active |
| AabyssZG/SpringBoot-Scan SpringBoot-Scan is an open-source penetration testing framework targeting Spring Boot applications, written in Python. It scans for sensiti… | 53 | 2340 | active |
| BeichenDream/GodPotato GodPotato is a C# Windows privilege escalation tool that abuses a DCOM/RPCSS oxid resolution defect to elevate from a service account with … | 22 | 2334 | stable |
| Ch0pin/medusa MEDUSA is a modular automation framework and script repository for runtime testing and investigating Android and iOS apps, built on FRIDA. … | 84 | 2332 | active |
| googleprojectzero/sandbox-attacksurface-analysis-tools A suite of PowerShell tools and .NET libraries from Google Project Zero for analyzing Windows sandbox attack surfaces. It includes NtCoreLi… | 56 | 2332 | active |
| ssl/ezXSS ezXSS is a self-hosted PHP application that helps penetration testers and bug bounty hunters detect and exploit (blind) cross-site scriptin… | 64 | 2330 | active |
| safebuffer/vulnerable-AD A PowerShell script that configures a Windows Server domain controller into a deliberately vulnerable Active Directory environment for prac… | 32 | 2325 | active |
| p0dalirius/Coercer Coercer is a Python CLI tool that automatically coerces Windows servers to authenticate to an arbitrary machine via multiple RPC methods ov… | 58 | 2310 | active |
| 1N3/BruteX BruteX is a shell-based CLI tool that automatically brute forces all services running on a target, enumerating open ports, usernames, and p… | 23 | 2299 | active |
| n1nj4sec/pupy Pupy is an open-source, cross-platform (Windows, Linux, macOS, Android) command-and-control and post-exploitation framework written in Pyth… | 10 | 8999 | maintenance |
| lz520520/railgun Railgun is a GUI-based penetration testing tool that automates common tasks from manual pentesting experience. It integrates port scanning,… | 35 | 2289 | active |
| API-Security/APIKit APIKit is a BurpSuite extension (Java plugin) that discovers, scans, and audits leaked API documentation such as GraphQL, OpenAPI/Swagger, … | 23 | 2286 | active |
| CravateRouge/bloodyAD bloodyAD is a Python CLI tool for Active Directory privilege escalation that performs specific LDAP calls against domain controllers. It su… | 97 | 2275 | active |
| pen4uin/java-memshell-generator A highly customizable Java in-memory webshell (memshell) generator supporting multiple middleware servers, frameworks, shell types, and out… | 37 | 2230 | active |
| DanOps-1/Gpt-Agreement-Payment A Python toolkit that reverse-engineers and replays the end-to-end ChatGPT Plus/Team/Pro subscription payment flow (Stripe Checkout, PayPal… | 53 | 2225 | active |
| zakirkun/deep-eye Deep Eye is an AI-driven penetration testing CLI that orchestrates multiple LLM providers (OpenAI, Claude, Gemini, OLLAMA, Groq, and others… | 68 | 2219 | active |
| eeeeeeeeee-code/e0e1-wx A Windows GUI tool (PySide6, Python 3.10+) for analyzing and penetration-testing WeChat mini-programs locally. It automates mini-program pa… | 80 | 2214 | active |
| login-securite/lsassy Lsassy is a Python CLI tool that remotely extracts credentials from the LSASS process memory of Windows hosts over the network. It uses imp… | 71 | 2210 | active |
| lefayjey/linWinPwn linWinPwn is a bash script that wraps and streamlines a large set of Active Directory penetration testing tools such as impacket, bloodhoun… | 77 | 2200 | active |
| bytecode77/r77-rootkit r77 is a fileless ring 3 (userland) rootkit for Windows that hides files, processes, registry keys, services, and network connections using… | 75 | 2191 | active |
| ZerBea/hcxdumptool hcxdumptool is a C-based command-line tool that captures packets from WLAN devices and runs layer 2 attacks against the WPA protocol to fin… | 79 | 2184 | active |