function: penetration-testing
859 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| kimci86/bkcrack bkcrack is a command-line tool that cracks legacy ZIP encryption (ZipCrypto/PKWARE) using Biham and Kocher's known plaintext attack. Given … | 73 | 2176 | active |
| Ylarod/Florida Florida is an automatically patched, anti-detection build of frida-server for Android, tracking the upstream FRIDA project. It rebuilds fri… | 89 | 2175 | active |
| dronesploit/dronesploit DroneSploit is a Metasploit-style console framework for pentesting commercial drones, built on sploitkit. It gathers drone-focused hacking … | 23 | 2161 | active |
| vulhub/java-chains Java Chains is a self-hosted web platform for generating Java exploitation payloads, aimed at security researchers. It supports common Java… | 89 | 2152 | active |
| fortra/nanodump NanoDump is a C-based tool that creates minidumps of the Windows LSASS process using a variety of stealthy handle-acquisition and dumping t… | 32 | 2137 | active |
| Wifite Wifite is a Python command-line tool that automates wireless network security auditing by running existing tools like the Aircrack-ng suite… | 66 | 8084 | maintenance |
| defparam/smuggler Smuggler is a Python 3 command-line tool that tests web servers and proxies for HTTP request smuggling and desync vulnerabilities. It fires… | 32 | 2093 | active |
| Sh1Yo/x8 x8 is a hidden parameter discovery suite written in Rust for security testing of web applications. It brute-forces parameter names against … | 23 | 2093 | active |
| rebootuser/LinEnum LinEnum is a shell script that performs scripted local Linux enumeration and privilege escalation checks. It gathers system, user, network,… | 32 | 8012 | maintenance |
| SamueleAmato/sosec sosec is a Python command-line toolkit with a terminal UI for automated credential testing and HTTP request orchestration against social me… | 63 | 2065 | active |
| lukechilds/reverse-shell A hosted service (reverse-shell.sh) that generates reverse shell payloads on demand; piping its URL output into sh on a target spawns a she… | 63 | 2055 | active |
| berdav/CVE-2021-4034 A proof-of-concept exploit and vulnerability checker for CVE-2021-4034 (PwnKit), a polkit pkexec local privilege escalation vulnerability i… | 32 | 2048 | stable |
| ine-labs/AWSGoat AWSGoat is a deliberately vulnerable AWS infrastructure deployed via Terraform, featuring OWASP Top 10 web vulnerabilities and cloud miscon… | 42 | 2044 | active |
| CyberStrikeus/CyberStrike CyberStrike is an open-source AI-powered offensive security harness that runs automated penetration testing from the terminal. It orchestra… | 81 | 2043 | active |
| GhostPack/Certify Certify is a C# command-line tool for enumerating and abusing misconfigurations in Active Directory Certificate Services (AD CS). It was re… | 76 | 2023 | active |
| wyzxxz/jndi_tool A Java-based JNDI exploitation tool that runs malicious RMI/LDAP reference servers to test and exploit JNDI injection vulnerabilities, incl… | 32 | 2021 | active |
| ASHWIN990/ADB-Toolkit ADB-Toolkit is a Bash script wrapping the Android Debug Bridge with 28 options plus a Metasploit section for testing and exploiting Android… | 23 | 2016 | active |
| shivaya-dav/DogeRat DogeRat is a Telegram-controlled Android remote access tool (RAT) consisting of a Node.js/Express/Socket.IO server and a Kotlin Android APK… | 42 | 2005 | active |
| t6x/reaver-wps-fork-t6x Reaver is a C-based command-line tool that performs brute force attacks against Wi-Fi Protected Setup (WPS) registrar PINs to recover WPA/W… | 45 | 1981 | active |
| msoedov/agentic_security Agentic Security is an open-source LLM vulnerability scanner and AI red-teaming toolkit that probes large language models and agent workflo… | 87 | 1977 | active |
| cifertech/nRFBox nRFBox is an open-source ESP32-based handheld tool that scans, analyzes, jams, and spoofs BLE, Wi-Fi, and 2.4GHz signals using an nRF24L01 … | 73 | 1971 | active |
| MichaelGrafnetter/DSInternals DSInternals is a PowerShell module and .NET framework for working with Active Directory internals, including offline NTDS.DIT database pars… | 92 | 1967 | active |
| intruder-io/autoswagger Autoswagger is a Python command-line tool that discovers Swagger/OpenAPI specifications, parses their endpoints, and automatically tests th… | 34 | 1960 | active |
| kkbo8005/mitan Mitan (密探) is an all-in-one penetration testing and security assessment desktop application integrating asset mapping, subdomain brute-forc… | 79 | 1955 | active |
| owtf/owtf OWASP OWTF (Offensive Web Testing Framework) is a penetration testing framework that unites multiple security tools and aligns testing work… | 67 | 1949 | active |
| f0ng/captcha-killer-modified A modified version of the captcha-killer Burp Suite extension that intercepts captcha images from HTTP responses and recognizes them using … | 41 | 1948 | active |
| Ragnt/AngryOxide AngryOxide is an 802.11 WiFi attack tool written in Rust that provides a single-interface survey capability with automated attacks to captu… | 70 | 1945 | active |
| evilsocket/legba Legba is a fast, multiprotocol credentials bruteforcer, password sprayer, and enumerator written in Rust on top of the Tokio async runtime.… | 84 | 1934 | active |
| joaoviictorti/RustRedOps RustRedOps is a collection of red team tools and technique implementations written in Rust, primarily targeting Windows. It provides workin… | 53 | 1900 | active |
| liamg/traitor Traitor is a Go-based CLI tool that automatically exploits common Linux misconfigurations and known vulnerabilities (GTFOBins, pwnkit, dirt… | 23 | 7160 | maintenance |
| federicodotta/Brida Brida is a Burp Suite extension that bridges Burp Suite and Frida, letting testers invoke and manipulate an application's own methods while… | 49 | 1889 | active |
| evildevill/instahack Instahack is a Bash and Python-based brute-force tool for testing Instagram account password strength, routing traffic through Tor for anon… | 62 | 1888 | active |
| pentestfunctions/BlueDucky BlueDucky is a Python tool that exploits CVE-2023-45866, an unauthenticated Bluetooth peering vulnerability, to execute keystroke injection… | 56 | 1888 | active |
| 0xKayala/NucleiFuzzer NucleiFuzzer is a Python-based automation tool that combines URL discovery tools (ParamSpider, Waybackurls, Gauplus, Hakrawler, Katana) wit… | 66 | 1862 | active |
| trustedsec/hate_crack hate_crack is a Python tool by TrustedSec that automates password cracking methodologies on top of Hashcat, orchestrating wordlists, masks,… | 95 | 1854 | active |
| zakirkun/guardian-cli Guardian is a Python CLI tool that automates penetration testing workflows using LLM providers (OpenAI, Claude, Gemini, Ollama, and others)… | 69 | 1853 | active |
| selinuxG/Golin Golin is a Go-based security assessment tool combining asset discovery, port/service scanning, weak password brute-forcing for 40+ services… | 66 | 1847 | active |
| wapiti-scanner/wapiti Wapiti is an open-source black-box web vulnerability scanner written in Python that crawls deployed web applications and fuzzes scripts and… | 98 | 1846 | active |
| pandasec888/taowu-cobalt_strike Taowu is a red team automation plugin (Aggressor script) for the Cobalt Strike platform, bundling a large collection of post-exploitation m… | 56 | 1835 | active |
| bvcyber/CVE-2020-1472 A Python CLI script that tests domain controllers for the ZeroLogon vulnerability (CVE-2020-1472) using the Impacket library. It attempts t… | 45 | 1830 | stable |
| White-hua/Apt_t00ls A Java-based exploitation tool that aggregates proof-of-concept and weaponized exploits for high-severity vulnerabilities in Chinese enterp… | 26 | 1830 | active |
| wagiro/BurpBounty Burp Bounty (Scan Check Builder) is a Burp Suite extension that lets users improve Burp's active and passive web vulnerability scanners wit… | 23 | 1809 | active |
| doyensec/inql InQL is an open-source Burp Suite extension for advanced GraphQL security testing. It provides schema introspection, vulnerability detectio… | 76 | 1801 | active |
| wallarm/gotestwaf GoTestWAF is a Go-based tool that simulates OWASP and API attacks (SQL injection, XSS, etc.) across REST, GraphQL, gRPC, SOAP, and XMLRPC p… | 41 | 1799 | active |
| R4gd0ll/I-Wanna-Get-All A comprehensive Java post-exploitation vulnerability exploitation tool integrating 470 exploit modules for detection and attack of known vu… | 59 | 1787 | active |
| kost/dvcs-ripper dvcs-ripper is a set of Perl command-line tools that download (rip) web-accessible version control repositories such as GIT, SVN, Mercurial… | 32 | 1784 | stable |
| D4Vinci/One-Lin3r One-Lin3r is a lightweight, modular Python framework that provides a searchable database of over 176 one-liner commands for penetration tes… | 57 | 1783 | active |
| GoSecure/pyrdp PyRDP is a Python Remote Desktop Protocol (RDP) Monster-in-the-Middle (MITM) tool and library. It intercepts RDP connections to capture cre… | 60 | 1780 | active |
| ron190/jsql-injection jSQL Injection is a free, open-source Java application for automatic SQL database injection, used to find and extract database information … | 84 | 1776 | active |
| quentinhardy/odat ODAT (Oracle Database Attacking Tool) is an open-source Python penetration testing tool for assessing the security of remote Oracle Databas… | 57 | 1776 | active |
| j3ers3/Hello-Java-Sec A deliberately vulnerable Java Spring Boot application demonstrating common web vulnerabilities (SQLi, XSS, RCE, deserialization, SSTI, SSR… | 27 | 1763 | active |
| xaitax/Chrome-App-Bound-Encryption-Decryption A Windows post-exploitation research tool that bypasses Chromium's App-Bound Encryption using direct syscall-based reflective process hollo… | 63 | 1762 | active |
| qi4L/JYso JYso is a Java-based offensive security tool that combines the capabilities of ysoserial (Java deserialization gadget generation) and JNDIE… | 83 | 1761 | active |
| xmendez/wfuzz Wfuzz is a Python-based command-line web application fuzzer that replaces a FUZZ keyword in HTTP requests with values from configurable pay… | 60 | 6558 | maintenance |
| jm33-m0/emp3r0r emp3r0r is an open-source post-exploitation framework and command-and-control (C2) system written in Go, targeting Linux and Windows hosts.… | 95 | 1741 | active |
| wiire-a/pixiewps Pixiewps is a C command-line utility that brute-forces Wi-Fi Protected Setup (WPS) PINs offline, exploiting low- or non-entropy software im… | 57 | 1740 | active |
| MatheuZSecurity/Singularity Singularity is a stealthy Linux kernel module (LKM) rootkit targeting modern 6.x kernels, using ftrace-based syscall hooking to hide proces… | 56 | 1736 | active |
| cr0hn/dockerscan DockerScan is a comprehensive Docker security scanner written in Go that scans containers, images, and registries using multiple techniques… | 93 | 1710 | active |
| S3cur3Th1sSh1t/PowerSharpPack PowerSharpPack wraps many useful offensive C# security projects (Seatbelt, Rubeus, SharpUp, winPEAS, etc.) into PowerShell scripts for easy… | 39 | 1708 | active |
| dolevf/Damn-Vulnerable-GraphQL-Application Damn Vulnerable GraphQL Application (DVGA) is an intentionally insecure GraphQL service built for learning and practicing GraphQL security … | 33 | 1705 | active |
| dafthack/MFASweep MFASweep is a PowerShell script that attempts to log in to multiple Microsoft services with provided credentials to detect whether MFA is e… | 67 | 1692 | active |
| whwlsfb/JDumpSpider JDumpSpider is a Java CLI tool that extracts sensitive information (datasource credentials, config properties, Redis configs, Shiro keys, u… | 70 | 1680 | active |
| MorDavid/BruteForceAI BruteForceAI is a Python-based penetration testing tool that uses LLMs (via Ollama or Groq) to automatically analyze login page HTML and id… | 60 | 1677 | active |
| rebeyond/Behinder Behinder ('冰蝎') is a cross-platform Java client for managing encrypted webshells on compromised web servers running PHP, Java, or .NET. It … | 23 | 6191 | maintenance |
| dirkjanm/krbrelayx A Python toolkit for abusing Kerberos in Active Directory environments, including Kerberos relaying and unconstrained delegation attacks. I… | 64 | 1657 | active |
| whwlsfb/BurpCrypto BurpCrypto is a Burp Suite extension that encrypts Intruder payloads with algorithms like AES, RSA, and DES, or by executing arbitrary Java… | 23 | 1648 | active |
| cddmp/enum4linux-ng enum4linux-ng is a Python rewrite of the enum4linux.pl Windows/Samba enumeration tool, wrapping Samba utilities like nmblookup, net, rpccli… | 75 | 1644 | active |
| shekyan/slowhttptest SlowHTTPTest is a highly configurable command-line tool that simulates Application Layer Denial of Service attacks by prolonging HTTP conne… | 67 | 1644 | active |
| Pentest AI pentest-ai is an MIT-licensed local CLI and MCP server that turns Claude Code (or any LLM) into an offensive security assistant, pairing 50… | 80 | 1629 | active |
| JesseCHale/HaleHound-CYD HaleHound-CYD is a multi-protocol offensive security toolkit firmware for the ESP32 Cheap Yellow Display, offering 40+ attack modules acros… | 80 | 1623 | active |
| vladko312/SSTImap SSTImap is a Python-based penetration testing tool that automatically detects and exploits Server-Side Template Injection (SSTI) and code i… | 88 | 1621 | active |
| coffinxp/loxs Loxs is a Python-based multi-vulnerability scanner for web applications that detects SQL injection, XSS, LFI, open redirect, and CRLF injec… | 52 | 1612 | active |
| liamg/gitjacker Gitjacker is a Go CLI tool that downloads and reconstructs git repositories from websites where the .git directory has been mistakenly expo… | 48 | 1607 | active |
| repplus/rep-chrome rep+ is a Chrome DevTools extension inspired by Burp Suite's Repeater that captures and replays HTTP requests with modified methods, header… | 54 | 1603 | active |
| Orange-Cyberdefense/ocd-mindmaps A collection of interactive mindmaps from Orange Cyberdefense covering offensive security and penetration testing methodologies, published … | 37 | 1602 | active |
| 4lbH4cker/ALHacking ALHacking is a shell-script-based toolkit bundling a menu of so-called ethical hacking utilities, including social media account attacks, p… | 32 | 1601 | active |
| AlisamTechnology/ATSCAN ATSCAN is a Perl-based command-line scanner for mass dork searching and vulnerability exploitation. It combines search engine dorking with … | 23 | 1583 | active |
| stealthcopter/deepce DEEPCE is a single-file pure-shell script for enumerating Docker environments and attempting privilege escalation and container escapes. It… | 58 | 1567 | active |
| Tsojan/TsojanScan TsojanScan is an integrated BurpSuite plugin for vulnerability detection that bundles multiple common vulnerability POCs into a single exte… | 85 | 1563 | active |
| moom825/xeno-rat Xeno-RAT is an open-source remote access tool (RAT) written in C# for remotely controlling Windows 10/11 machines. It includes features suc… | 18 | 1562 | active |
| OWASP/QRLJacking QRLJacking is an OWASP project documenting and exploiting the Quick Response Code Login Jacking attack vector, which hijacks user sessions … | 48 | 1559 | active |
| newaetech/chipwhisperer ChipWhisperer is an open-source toolchain for hardware security research, providing capture hardware designs, FPGA/USB firmware, and a Pyth… | 79 | 1557 | active |
| BlackSnufkin/LitterBox LitterBox is a self-hosted payload-analysis sandbox for red teams that runs static, dynamic, and EDR-based analysis on samples and produces… | 62 | 1526 | active |
| nemesida-waf/waf-bypass WAF Bypass Tool is an open-source Python CLI tool that tests web application firewalls for false positives and false negatives using predef… | 83 | 1520 | active |
| gobysec/Goby Goby is a network security assessment tool that maps an organization's attack surface and scans for known vulnerabilities and weak password… | 23 | 1517 | active |
| ztgrace/changeme changeme is a Python CLI tool that scans networks for devices and services using default or backdoor credentials. Credential definitions ar… | 36 | 1516 | active |
| webpwnized/mutillidae OWASP Mutillidae II is a deliberately vulnerable PHP web application used as a target for web-security training and practice. It includes o… | 72 | 1513 | active |
| nikitastupin/clairvoyance Clairvoyance is a Python CLI tool that recovers a GraphQL API's schema even when introspection is disabled, by probing field and type names… | 57 | 1506 | active |
| Gowtham-Darkseid/AutoPentestX AutoPentestX is a Python-based automated penetration testing toolkit that scans targets for vulnerabilities and generates security reports.… | 45 | 1504 | active |
| assetnote/nowafpls nowafpls is a Jython-based Burp Suite plugin that bypasses web application firewalls (WAFs) by inserting junk data into HTTP request bodies… | 38 | 1502 | active |
| Meckazin/ChromeKatz ChromeKatz is a set of offensive security tools (CookieKatz, ElevationKatz) written in C that dump cookies and decryption keys directly fro… | 72 | 1495 | active |
| Schira4396/VcenterKiller A Go-based all-in-one exploitation and verification tool targeting VMware vCenter, covering major CVEs such as CVE-2021-21972, CVE-2021-219… | 23 | 1485 | active |
| Fuzion24/JustTrustMe An Xposed module for rooted Android devices that disables SSL certificate pinning in apps, enabling traffic interception during security au… | 23 | 5361 | maintenance |
| inguardians/peirates Peirates is a Go-based, interactive Kubernetes penetration testing tool that automates privilege escalation, lateral movement, and cluster … | 90 | 1477 | active |
| lengjibo/RedTeamTools A collection of red team tools written and modified by the author, primarily in C++ and Python. It includes utilities for AV bypass, privil… | 53 | 1472 | active |
| Greenwolf/ntlm_theft ntlm_theft is a Python3 CLI tool that generates 21 different types of NTLMv2 hash theft files (e.g., .url, .scf, .docx, .pdf, .jnlp) that t… | 52 | 1470 | active |
| t3l3machus/psudohash psudohash is a Python CLI tool that generates millions of keyword-based password mutations for brute-force attacks and hash cracking. It mi… | 34 | 1467 | active |
| ssh-mitm/ssh-mitm SSH-MITM is an open-source man-in-the-middle SSH server for authorized security audits and malware analysis. It proxies SSH client-server c… | 66 | 1464 | active |
| epsylon/xsser XSSer is an automatic penetration testing framework for detecting, exploiting, and reporting cross-site scripting (XSS) vulnerabilities in … | 82 | 1461 | active |
| PortSwigger/param-miner Param Miner is a Burp Suite extension that identifies hidden, unlinked HTTP parameters, headers, and cookies using diffing logic and binary… | 78 | 1460 | active |