Ross ROSS = Recommend OSS · open-source software intelligence for agents

function: penetration-testing

859 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
kimci86/bkcrack
bkcrack is a command-line tool that cracks legacy ZIP encryption (ZipCrypto/PKWARE) using Biham and Kocher's known plaintext attack. Given …
732176active
Ylarod/Florida
Florida is an automatically patched, anti-detection build of frida-server for Android, tracking the upstream FRIDA project. It rebuilds fri…
892175active
dronesploit/dronesploit
DroneSploit is a Metasploit-style console framework for pentesting commercial drones, built on sploitkit. It gathers drone-focused hacking …
232161active
vulhub/java-chains
Java Chains is a self-hosted web platform for generating Java exploitation payloads, aimed at security researchers. It supports common Java…
892152active
fortra/nanodump
NanoDump is a C-based tool that creates minidumps of the Windows LSASS process using a variety of stealthy handle-acquisition and dumping t…
322137active
Wifite
Wifite is a Python command-line tool that automates wireless network security auditing by running existing tools like the Aircrack-ng suite…
668084maintenance
defparam/smuggler
Smuggler is a Python 3 command-line tool that tests web servers and proxies for HTTP request smuggling and desync vulnerabilities. It fires…
322093active
Sh1Yo/x8
x8 is a hidden parameter discovery suite written in Rust for security testing of web applications. It brute-forces parameter names against …
232093active
rebootuser/LinEnum
LinEnum is a shell script that performs scripted local Linux enumeration and privilege escalation checks. It gathers system, user, network,…
328012maintenance
SamueleAmato/sosec
sosec is a Python command-line toolkit with a terminal UI for automated credential testing and HTTP request orchestration against social me…
632065active
lukechilds/reverse-shell
A hosted service (reverse-shell.sh) that generates reverse shell payloads on demand; piping its URL output into sh on a target spawns a she…
632055active
berdav/CVE-2021-4034
A proof-of-concept exploit and vulnerability checker for CVE-2021-4034 (PwnKit), a polkit pkexec local privilege escalation vulnerability i…
322048stable
ine-labs/AWSGoat
AWSGoat is a deliberately vulnerable AWS infrastructure deployed via Terraform, featuring OWASP Top 10 web vulnerabilities and cloud miscon…
422044active
CyberStrikeus/CyberStrike
CyberStrike is an open-source AI-powered offensive security harness that runs automated penetration testing from the terminal. It orchestra…
812043active
GhostPack/Certify
Certify is a C# command-line tool for enumerating and abusing misconfigurations in Active Directory Certificate Services (AD CS). It was re…
762023active
wyzxxz/jndi_tool
A Java-based JNDI exploitation tool that runs malicious RMI/LDAP reference servers to test and exploit JNDI injection vulnerabilities, incl…
322021active
ASHWIN990/ADB-Toolkit
ADB-Toolkit is a Bash script wrapping the Android Debug Bridge with 28 options plus a Metasploit section for testing and exploiting Android…
232016active
shivaya-dav/DogeRat
DogeRat is a Telegram-controlled Android remote access tool (RAT) consisting of a Node.js/Express/Socket.IO server and a Kotlin Android APK…
422005active
t6x/reaver-wps-fork-t6x
Reaver is a C-based command-line tool that performs brute force attacks against Wi-Fi Protected Setup (WPS) registrar PINs to recover WPA/W…
451981active
msoedov/agentic_security
Agentic Security is an open-source LLM vulnerability scanner and AI red-teaming toolkit that probes large language models and agent workflo…
871977active
cifertech/nRFBox
nRFBox is an open-source ESP32-based handheld tool that scans, analyzes, jams, and spoofs BLE, Wi-Fi, and 2.4GHz signals using an nRF24L01 …
731971active
MichaelGrafnetter/DSInternals
DSInternals is a PowerShell module and .NET framework for working with Active Directory internals, including offline NTDS.DIT database pars…
921967active
intruder-io/autoswagger
Autoswagger is a Python command-line tool that discovers Swagger/OpenAPI specifications, parses their endpoints, and automatically tests th…
341960active
kkbo8005/mitan
Mitan (密探) is an all-in-one penetration testing and security assessment desktop application integrating asset mapping, subdomain brute-forc…
791955active
owtf/owtf
OWASP OWTF (Offensive Web Testing Framework) is a penetration testing framework that unites multiple security tools and aligns testing work…
671949active
f0ng/captcha-killer-modified
A modified version of the captcha-killer Burp Suite extension that intercepts captcha images from HTTP responses and recognizes them using …
411948active
Ragnt/AngryOxide
AngryOxide is an 802.11 WiFi attack tool written in Rust that provides a single-interface survey capability with automated attacks to captu…
701945active
evilsocket/legba
Legba is a fast, multiprotocol credentials bruteforcer, password sprayer, and enumerator written in Rust on top of the Tokio async runtime.…
841934active
joaoviictorti/RustRedOps
RustRedOps is a collection of red team tools and technique implementations written in Rust, primarily targeting Windows. It provides workin…
531900active
liamg/traitor
Traitor is a Go-based CLI tool that automatically exploits common Linux misconfigurations and known vulnerabilities (GTFOBins, pwnkit, dirt…
237160maintenance
federicodotta/Brida
Brida is a Burp Suite extension that bridges Burp Suite and Frida, letting testers invoke and manipulate an application's own methods while…
491889active
evildevill/instahack
Instahack is a Bash and Python-based brute-force tool for testing Instagram account password strength, routing traffic through Tor for anon…
621888active
pentestfunctions/BlueDucky
BlueDucky is a Python tool that exploits CVE-2023-45866, an unauthenticated Bluetooth peering vulnerability, to execute keystroke injection…
561888active
0xKayala/NucleiFuzzer
NucleiFuzzer is a Python-based automation tool that combines URL discovery tools (ParamSpider, Waybackurls, Gauplus, Hakrawler, Katana) wit…
661862active
trustedsec/hate_crack
hate_crack is a Python tool by TrustedSec that automates password cracking methodologies on top of Hashcat, orchestrating wordlists, masks,…
951854active
zakirkun/guardian-cli
Guardian is a Python CLI tool that automates penetration testing workflows using LLM providers (OpenAI, Claude, Gemini, Ollama, and others)…
691853active
selinuxG/Golin
Golin is a Go-based security assessment tool combining asset discovery, port/service scanning, weak password brute-forcing for 40+ services…
661847active
wapiti-scanner/wapiti
Wapiti is an open-source black-box web vulnerability scanner written in Python that crawls deployed web applications and fuzzes scripts and…
981846active
pandasec888/taowu-cobalt_strike
Taowu is a red team automation plugin (Aggressor script) for the Cobalt Strike platform, bundling a large collection of post-exploitation m…
561835active
bvcyber/CVE-2020-1472
A Python CLI script that tests domain controllers for the ZeroLogon vulnerability (CVE-2020-1472) using the Impacket library. It attempts t…
451830stable
White-hua/Apt_t00ls
A Java-based exploitation tool that aggregates proof-of-concept and weaponized exploits for high-severity vulnerabilities in Chinese enterp…
261830active
wagiro/BurpBounty
Burp Bounty (Scan Check Builder) is a Burp Suite extension that lets users improve Burp's active and passive web vulnerability scanners wit…
231809active
doyensec/inql
InQL is an open-source Burp Suite extension for advanced GraphQL security testing. It provides schema introspection, vulnerability detectio…
761801active
wallarm/gotestwaf
GoTestWAF is a Go-based tool that simulates OWASP and API attacks (SQL injection, XSS, etc.) across REST, GraphQL, gRPC, SOAP, and XMLRPC p…
411799active
R4gd0ll/I-Wanna-Get-All
A comprehensive Java post-exploitation vulnerability exploitation tool integrating 470 exploit modules for detection and attack of known vu…
591787active
kost/dvcs-ripper
dvcs-ripper is a set of Perl command-line tools that download (rip) web-accessible version control repositories such as GIT, SVN, Mercurial…
321784stable
D4Vinci/One-Lin3r
One-Lin3r is a lightweight, modular Python framework that provides a searchable database of over 176 one-liner commands for penetration tes…
571783active
GoSecure/pyrdp
PyRDP is a Python Remote Desktop Protocol (RDP) Monster-in-the-Middle (MITM) tool and library. It intercepts RDP connections to capture cre…
601780active
ron190/jsql-injection
jSQL Injection is a free, open-source Java application for automatic SQL database injection, used to find and extract database information …
841776active
quentinhardy/odat
ODAT (Oracle Database Attacking Tool) is an open-source Python penetration testing tool for assessing the security of remote Oracle Databas…
571776active
j3ers3/Hello-Java-Sec
A deliberately vulnerable Java Spring Boot application demonstrating common web vulnerabilities (SQLi, XSS, RCE, deserialization, SSTI, SSR…
271763active
xaitax/Chrome-App-Bound-Encryption-Decryption
A Windows post-exploitation research tool that bypasses Chromium's App-Bound Encryption using direct syscall-based reflective process hollo…
631762active
qi4L/JYso
JYso is a Java-based offensive security tool that combines the capabilities of ysoserial (Java deserialization gadget generation) and JNDIE…
831761active
xmendez/wfuzz
Wfuzz is a Python-based command-line web application fuzzer that replaces a FUZZ keyword in HTTP requests with values from configurable pay…
606558maintenance
jm33-m0/emp3r0r
emp3r0r is an open-source post-exploitation framework and command-and-control (C2) system written in Go, targeting Linux and Windows hosts.…
951741active
wiire-a/pixiewps
Pixiewps is a C command-line utility that brute-forces Wi-Fi Protected Setup (WPS) PINs offline, exploiting low- or non-entropy software im…
571740active
MatheuZSecurity/Singularity
Singularity is a stealthy Linux kernel module (LKM) rootkit targeting modern 6.x kernels, using ftrace-based syscall hooking to hide proces…
561736active
cr0hn/dockerscan
DockerScan is a comprehensive Docker security scanner written in Go that scans containers, images, and registries using multiple techniques…
931710active
S3cur3Th1sSh1t/PowerSharpPack
PowerSharpPack wraps many useful offensive C# security projects (Seatbelt, Rubeus, SharpUp, winPEAS, etc.) into PowerShell scripts for easy…
391708active
dolevf/Damn-Vulnerable-GraphQL-Application
Damn Vulnerable GraphQL Application (DVGA) is an intentionally insecure GraphQL service built for learning and practicing GraphQL security …
331705active
dafthack/MFASweep
MFASweep is a PowerShell script that attempts to log in to multiple Microsoft services with provided credentials to detect whether MFA is e…
671692active
whwlsfb/JDumpSpider
JDumpSpider is a Java CLI tool that extracts sensitive information (datasource credentials, config properties, Redis configs, Shiro keys, u…
701680active
MorDavid/BruteForceAI
BruteForceAI is a Python-based penetration testing tool that uses LLMs (via Ollama or Groq) to automatically analyze login page HTML and id…
601677active
rebeyond/Behinder
Behinder ('冰蝎') is a cross-platform Java client for managing encrypted webshells on compromised web servers running PHP, Java, or .NET. It …
236191maintenance
dirkjanm/krbrelayx
A Python toolkit for abusing Kerberos in Active Directory environments, including Kerberos relaying and unconstrained delegation attacks. I…
641657active
whwlsfb/BurpCrypto
BurpCrypto is a Burp Suite extension that encrypts Intruder payloads with algorithms like AES, RSA, and DES, or by executing arbitrary Java…
231648active
cddmp/enum4linux-ng
enum4linux-ng is a Python rewrite of the enum4linux.pl Windows/Samba enumeration tool, wrapping Samba utilities like nmblookup, net, rpccli…
751644active
shekyan/slowhttptest
SlowHTTPTest is a highly configurable command-line tool that simulates Application Layer Denial of Service attacks by prolonging HTTP conne…
671644active
Pentest AI
pentest-ai is an MIT-licensed local CLI and MCP server that turns Claude Code (or any LLM) into an offensive security assistant, pairing 50…
801629active
JesseCHale/HaleHound-CYD
HaleHound-CYD is a multi-protocol offensive security toolkit firmware for the ESP32 Cheap Yellow Display, offering 40+ attack modules acros…
801623active
vladko312/SSTImap
SSTImap is a Python-based penetration testing tool that automatically detects and exploits Server-Side Template Injection (SSTI) and code i…
881621active
coffinxp/loxs
Loxs is a Python-based multi-vulnerability scanner for web applications that detects SQL injection, XSS, LFI, open redirect, and CRLF injec…
521612active
liamg/gitjacker
Gitjacker is a Go CLI tool that downloads and reconstructs git repositories from websites where the .git directory has been mistakenly expo…
481607active
repplus/rep-chrome
rep+ is a Chrome DevTools extension inspired by Burp Suite's Repeater that captures and replays HTTP requests with modified methods, header…
541603active
Orange-Cyberdefense/ocd-mindmaps
A collection of interactive mindmaps from Orange Cyberdefense covering offensive security and penetration testing methodologies, published …
371602active
4lbH4cker/ALHacking
ALHacking is a shell-script-based toolkit bundling a menu of so-called ethical hacking utilities, including social media account attacks, p…
321601active
AlisamTechnology/ATSCAN
ATSCAN is a Perl-based command-line scanner for mass dork searching and vulnerability exploitation. It combines search engine dorking with …
231583active
stealthcopter/deepce
DEEPCE is a single-file pure-shell script for enumerating Docker environments and attempting privilege escalation and container escapes. It…
581567active
Tsojan/TsojanScan
TsojanScan is an integrated BurpSuite plugin for vulnerability detection that bundles multiple common vulnerability POCs into a single exte…
851563active
moom825/xeno-rat
Xeno-RAT is an open-source remote access tool (RAT) written in C# for remotely controlling Windows 10/11 machines. It includes features suc…
181562active
OWASP/QRLJacking
QRLJacking is an OWASP project documenting and exploiting the Quick Response Code Login Jacking attack vector, which hijacks user sessions …
481559active
newaetech/chipwhisperer
ChipWhisperer is an open-source toolchain for hardware security research, providing capture hardware designs, FPGA/USB firmware, and a Pyth…
791557active
BlackSnufkin/LitterBox
LitterBox is a self-hosted payload-analysis sandbox for red teams that runs static, dynamic, and EDR-based analysis on samples and produces…
621526active
nemesida-waf/waf-bypass
WAF Bypass Tool is an open-source Python CLI tool that tests web application firewalls for false positives and false negatives using predef…
831520active
gobysec/Goby
Goby is a network security assessment tool that maps an organization's attack surface and scans for known vulnerabilities and weak password…
231517active
ztgrace/changeme
changeme is a Python CLI tool that scans networks for devices and services using default or backdoor credentials. Credential definitions ar…
361516active
webpwnized/mutillidae
OWASP Mutillidae II is a deliberately vulnerable PHP web application used as a target for web-security training and practice. It includes o…
721513active
nikitastupin/clairvoyance
Clairvoyance is a Python CLI tool that recovers a GraphQL API's schema even when introspection is disabled, by probing field and type names…
571506active
Gowtham-Darkseid/AutoPentestX
AutoPentestX is a Python-based automated penetration testing toolkit that scans targets for vulnerabilities and generates security reports.…
451504active
assetnote/nowafpls
nowafpls is a Jython-based Burp Suite plugin that bypasses web application firewalls (WAFs) by inserting junk data into HTTP request bodies…
381502active
Meckazin/ChromeKatz
ChromeKatz is a set of offensive security tools (CookieKatz, ElevationKatz) written in C that dump cookies and decryption keys directly fro…
721495active
Schira4396/VcenterKiller
A Go-based all-in-one exploitation and verification tool targeting VMware vCenter, covering major CVEs such as CVE-2021-21972, CVE-2021-219…
231485active
Fuzion24/JustTrustMe
An Xposed module for rooted Android devices that disables SSL certificate pinning in apps, enabling traffic interception during security au…
235361maintenance
inguardians/peirates
Peirates is a Go-based, interactive Kubernetes penetration testing tool that automates privilege escalation, lateral movement, and cluster …
901477active
lengjibo/RedTeamTools
A collection of red team tools written and modified by the author, primarily in C++ and Python. It includes utilities for AV bypass, privil…
531472active
Greenwolf/ntlm_theft
ntlm_theft is a Python3 CLI tool that generates 21 different types of NTLMv2 hash theft files (e.g., .url, .scf, .docx, .pdf, .jnlp) that t…
521470active
t3l3machus/psudohash
psudohash is a Python CLI tool that generates millions of keyword-based password mutations for brute-force attacks and hash cracking. It mi…
341467active
ssh-mitm/ssh-mitm
SSH-MITM is an open-source man-in-the-middle SSH server for authorized security audits and malware analysis. It proxies SSH client-server c…
661464active
epsylon/xsser
XSSer is an automatic penetration testing framework for detecting, exploiting, and reporting cross-site scripting (XSS) vulnerabilities in …
821461active
PortSwigger/param-miner
Param Miner is a Burp Suite extension that identifies hidden, unlinked HTTP parameters, headers, and cookies using diffing logic and binary…
781460active

← prev page 3 / 9 next →