function: penetration-testing
859 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| OWASP/wrongsecrets OWASP WrongSecrets is a deliberately vulnerable Java application containing 50+ challenges that demonstrate how secrets are commonly miscon… | 94 | 1459 | active |
| urbanadventurer/username-anarchy Username Anarchy is a Ruby command-line tool that generates lists of likely usernames from people's first and last names for use in penetra… | 23 | 1458 | stable |
| AhMyth/AhMyth-Android-RAT AhMyth is an open-source Android Remote Administration Tool (RAT) consisting of an Electron-based desktop control panel and an Android back… | 10 | 5273 | maintenance |
| OWASP/SecurityShepherd OWASP Security Shepherd is a self-hosted web and mobile application security training platform built in Java. It presents lessons and chall… | 66 | 1456 | active |
| NullArray/AutoSploit AutoSploit is a Python CLI tool that automates mass exploitation of remote hosts by combining target discovery from Shodan, Censys, and Zoo… | 23 | 5253 | maintenance |
| One-Fox-Security-Team/One-Fox-T00ls One-Fox-T00ls is a curated collection of penetration testing and security toolboxes from the One-Fox security team, covering information ga… | 56 | 1443 | active |
| t3l3machus/toxssin toxssin is an open-source penetration testing CLI tool that automates exploitation of Cross-Site Scripting (XSS) vulnerabilities. It pairs … | 33 | 1440 | active |
| login-securite/DonPAPI DonPAPI is a Python CLI tool that remotely dumps DPAPI-protected secrets (browser credentials, certificates, WiFi passwords, and more) from… | 29 | 1417 | active |
| Metarget/metarget Metarget is a Python-based framework that automatically builds vulnerable cloud-native infrastructures, installing vulnerable versions of D… | 65 | 1415 | active |
| outflanknl/C2-Tool-Collection A collection of C-based offensive security tools that integrate with Cobalt Strike and other C2 frameworks via Beacon Object Files (BOF) an… | 32 | 1415 | active |
| RythmStick/AMSITrigger AMSITrigger is a C# command-line tool that identifies the specific strings in PowerShell scripts that trigger Microsoft's Antimalware Scan … | 32 | 1415 | active |
| Bitwise-01/Instagram- A Python CLI tool that performs brute-force password attacks against Instagram accounts using a supplied password list and rotating proxies… | 32 | 5081 | maintenance |
| tihanyin/PSSW100AVB A curated collection of PowerShell scripts demonstrating antivirus evasion techniques, most notably reverse shells that go undetected by AV… | 70 | 1405 | active |
| karma9874/AndroRAT AndroRAT is an Android remote administration tool (RAT) with a Java-based Android client APK and a Python server, communicating over socket… | 32 | 5037 | maintenance |
| Flangvik/TeamFiltration TeamFiltration is a cross-platform penetration testing framework for enumerating, password spraying, exfiltrating data from, and backdoorin… | 55 | 1399 | active |
| Jackalope Jackalope is a customizable, coverage-guided fuzzer for black-box binaries built on the TinyInst instrumentation library by Google Project … | 77 | 1380 | active |
| ChiChou/grapefruit Grapefruit is an open-source mobile security testing suite for iOS and Android that provides a browser-based GUI over Frida for runtime ins… | 91 | 1379 | active |
| blacklanternsecurity/TREVORspray TREVORspray is a modular password spraying tool with threading, SSH/subnet proxy rotation, and loot modules targeting identity providers li… | 70 | 1379 | active |
| 0xacb/recollapse REcollapse is a Python CLI helper tool that generates fuzzing payloads for black-box regex fuzzing against web applications. It helps bypas… | 46 | 1371 | active |
| andresriancho/w3af w3af is an open source web application attack and audit framework that scans web applications for over 200 vulnerability types, including X… | 23 | 4900 | maintenance |
| SpiderLabs/Responder Responder is a Python-based LLMNR, NBT-NS, and mDNS poisoner with built-in rogue authentication servers (SMB, HTTP/S, MSSQL, FTP, LDAP, POP… | 10 | 4890 | maintenance |
| Morsmalleo/AhMyth AhMyth is a cross-platform Android Remote Administration Tool (RAT) used to build APK payloads and remotely control Android devices through… | 66 | 1364 | active |
| 61106960/adPEAS adPEAS is a single-file PowerShell tool that automates Active Directory security assessment, enumerating misconfigurations, vulnerabilities… | 99 | 1361 | active |
| boku7/Loki Loki is a stage-1 command and control (C2) framework written in Node.js that exploits script-jacking vulnerabilities in Electron applicatio… | 50 | 1360 | active |
| zalexdev/strykerapp StrykerOSS is a free, open-source mobile penetration testing suite for rooted Android devices that bundles network, wireless, and web secur… | 98 | 1359 | active |
| roottusk/vapi vAPI is a self-hostable deliberately vulnerable API that mimics the OWASP API Security Top 10 scenarios through hands-on exercises. It ship… | 23 | 1349 | active |
| JoasASantos/NeuroSploit NeuroSploit is an AI-powered penetration testing framework written in Rust that turns a URL, repository, app, or host into an autonomous se… | 85 | 1347 | active |
| projectdiscovery/nuclei-burp-plugin A Burp Suite plugin that helps generate Nuclei vulnerability scanner templates from HTTP requests and responses captured in Burp's Proxy, R… | 44 | 1344 | active |
| WKL-Sec/HiddenDesktop Hidden Desktop is a Cobalt Strike BOF implementation of HVNC (Hidden Virtual Network Computing), letting red team operators interact with a… | 20 | 1343 | active |
| urbanadventurer/Android-PIN-Bruteforce A shell script that turns a rooted Android device running Kali NetHunter into a USB HID keyboard that bruteforces the lockscreen PIN of a l… | 32 | 4782 | maintenance |
| x364e3ab6/DudeSuite DudeSuite is a lightweight, integrated web penetration testing toolkit distributed as a desktop application for Windows and macOS. It bundl… | 85 | 1336 | active |
| F6JO/RouteVulScan RouteVulScan is a Burp Suite extension written in Java that passively and recursively probes each path layer of web traffic for vulnerable … | 82 | 1334 | active |
| bugbasesecurity/pentest-copilot Pentest Copilot is an open-source, AI-driven penetration testing agent that connects to a Kali attack box, autonomously runs security tools… | 64 | 1327 | active |
| wafinfo/DecryptTools A comprehensive encryption/decryption tool for penetration testers, supporting 22+ decryption schemes for Chinese enterprise software (OA s… | 22 | 1327 | active |
| ly4k/PwnKit A self-contained exploit for CVE-2021-4034 (PwnKit), a local privilege escalation vulnerability in polkit's pkexec. It ships as a prebuilt … | 32 | 1326 | stable |
| cseroad/Webshell_Generate A JavaFX desktop tool that generates evasive (antivirus-bypassing) webshells in multiple languages, supporting cmd shells and clients like … | 59 | 1323 | active |
| test502git/awvs14-scan A Python batch-scanning script built on the Acunetix (AWVS) 14/15 API that automates bulk URL scanning with specialized templates for log4j… | 48 | 1318 | active |
| 0x727/BypassPro BypassPro is a Burp Suite extension written in Java that automates bypass attempts against authorization controls (401/403) and WAFs. It co… | 79 | 1317 | active |
| cseroad/Exp-Tools A Java-based integrated exploitation tool that bundles proof-of-concept exploits for high-risk vulnerabilities in Chinese enterprise softwa… | 21 | 1316 | active |
| codingo/VHostScan VHostScan is a Python-based virtual host scanner that discovers hidden vhosts on a web server using wordlists, reverse lookups, and catch-a… | 39 | 1309 | active |
| freelabz/secator secator is a task and workflow runner for security assessments that unifies dozens of well-known security tools (subfinder, httpx, ffuf, nm… | 93 | 1306 | active |
| codingo/Interlace Interlace is a Python CLI tool that wraps single-threaded command-line applications and runs them in parallel across many targets, adding C… | 41 | 1303 | active |
| 0xInfection/XSRFProbe XSRFProbe is a Python-based Cross Site Request Forgery (CSRF/XSRF) audit and exploitation toolkit. It crawls web applications, runs systema… | 82 | 1302 | stable |
| Marven11/Fenjing Fenjing is an automated Jinja2 SSTI (server-side template injection) exploitation tool designed for CTF competitions. It automatically anal… | 87 | 1301 | active |
| sighook/pixload pixload is a set of Perl CLI tools for creating and injecting payloads into image files (BMP, GIF, JPG, PNG, WebP). It is used in offensive… | 23 | 1300 | active |
| RedTeamPentesting/pretender Pretender is a Go-based penetration testing tool that gains machine-in-the-middle positions via spoofed local name resolution (mDNS, LLMNR,… | 92 | 1299 | active |
| XiaoliChan/wmiexec-Pro wmiexec-Pro is a Python CLI tool built on Impacket that provides an enhanced version of wmiexec.py for remote command execution on Windows … | 67 | 1295 | active |
| h4r5h1t/webcopilot WebCopilot is a Bash-based automation script for bug bounty reconnaissance that enumerates subdomains using multiple tools, filters paramet… | 23 | 1295 | active |
| hausec/PowerZure PowerZure is a PowerShell framework for assessing and exploiting resources in Microsoft Azure and Entra ID. It provides both reconnaissance… | 53 | 1293 | active |
| P1-Team/AlliN AlliN is a flexible, dependency-free Python scanner designed to assist penetration testing projects, especially lateral movement and intran… | 40 | 1288 | active |
| RickdeJager/stegseek Stegseek is a lightning-fast command-line cracker for steghide steganography, built as a fork of the original steghide project that can tes… | 23 | 1288 | stable |
| ProbiusOfficial/CTF-OS CTF-OS is a preconfigured virtual machine image purpose-built for Capture The Flag (CTF) competitions, bundling a curated set of security a… | 32 | 1286 | active |
| SafeBreach-Labs/PoolParty PoolParty is a C++ command-line tool implementing eight novel, fully-undetectable process injection techniques that abuse Windows Thread Po… | 20 | 1284 | active |
| bit4woo/Fiora Fiora is a graphical interface for the Nuclei vulnerability PoC framework, enabling quick PoC search and one-click execution of Nuclei scan… | 57 | 1282 | active |
| SanMuzZzZz/LuaN1aoAgent LuaN1aoAgent is an autonomous AI-driven penetration testing agent built in TypeScript on the Pi SDK, using graph-based cognitive reasoning … | 81 | 1276 | active |
| icyguider/Shhhloader Shhhloader is a Python-based builder that compiles C++ shellcode loader stubs designed to bypass AV/EDR on Windows. It supports multiple sh… | 32 | 1276 | active |
| zhuifengshaonianhanlu/pikachu Pikachu is a deliberately vulnerable PHP/MySQL web application designed as a practice range for learning web security and penetration testi… | 71 | 4504 | maintenance |
| W01fh4cker/VcenterKit A comprehensive penetration testing toolkit targeting VMware vCenter, bundling exploitation modules for known CVEs such as CVE-2021-21972, … | 42 | 1270 | active |
| xploitstech/Xteam Xteam is an all-in-one, menu-driven hacking toolkit written in Python and launched via bash scripts, bundling Instagram information gatheri… | 42 | 1268 | active |
| UndeadSec/EvilURL EvilURL is a Python CLI tool that generates Unicode (IDN) domain permutations used in homograph attacks, where look-alike characters trick … | 10 | 1267 | active |
| Athena-OS/athena Athena OS is an Arch/Nix-based Linux distribution focused on cybersecurity and penetration testing, available as ISO, Docker images, and WS… | 83 | 1266 | active |
| 3xpl01tc0d3r/ProcessInjection A C# command-line tool that demonstrates and performs multiple Windows process injection techniques, including DLL injection, process hollo… | 48 | 1259 | active |
| utkusen/promptmap promptmap2 is an automated prompt injection scanner for custom LLM applications, supporting white-box testing of system prompts and black-b… | 53 | 1254 | active |
| wh1t3p1g/ysomap Ysomap is a Java deserialization exploit framework that lets users dynamically configure gadget chain payloads with different execution eff… | 26 | 1247 | active |
| lemono0/FastJsonParty FastJsonParty is a collection of Dockerized vulnerable environments covering multiple FastJson versions (1.2.47, 1.2.68, 1.2.80) for practi… | 28 | 1246 | active |
| antonioCoco/ConPtyShell ConPtyShell is a fully interactive reverse shell for Windows that leverages the Windows Pseudo Console (ConPTY) API to turn a remote PowerS… | 23 | 1246 | stable |
| RoganDawes/P4wnP1 P4wnP1 is a highly customizable USB attack platform built on a Raspberry Pi Zero or Zero W, providing features like a Windows LockPicker an… | 23 | 4383 | maintenance |
| PortSwigger/http-request-smuggler A Burp Suite extension that automatically detects and exploits HTTP Request Smuggling vulnerabilities, including HTTP/1.1 CL.TE/TE.CL desyn… | 76 | 1236 | active |
| arismelachroinos/lscript A shell script for Kali Linux that automates common WiFi penetration testing and hacking procedures through an interactive menu. It bundles… | 10 | 4330 | maintenance |
| RUB-NDS/PRET PRET is a Python command-line toolkit for printer security testing that connects to devices via network (port 9100) or USB and exploits pri… | 32 | 4301 | maintenance |
| ipa-lab/hackingBuddyGPT HackingBuddyGPT is a Python framework that helps ethical hackers and security researchers use LLMs and LLM-based autonomous agents for pene… | 67 | 1223 | active |
| nmap/ncrack Ncrack is a high-speed network authentication cracking tool from the Nmap project, designed to audit hosts and network devices for weak pas… | 23 | 1220 | active |
| jxy-s/herpaderping A proof-of-concept tool and technical write-up demonstrating Process Herpaderping, a Windows technique that maps a process image from a fil… | 32 | 1210 | active |
| Veil-Framework/Veil Veil is a Python-based command-line tool that generates Metasploit payloads designed to bypass common antivirus solutions. It supports mult… | 10 | 4226 | maintenance |
| qi4L/qscan Qscan is an extremely fast internal network scanner written in Go, offering port scanning, protocol detection, service fingerprinting, brut… | 72 | 1206 | active |
| mbrg/power-pwn Power Pwn is an offensive and defensive security toolset for Microsoft 365 Power Platform and AI services, including Copilot Studio, custom… | 63 | 1201 | active |
| epinna/tplmap Tplmap is a Python command-line tool that automatically detects and exploits Server-Side Template Injection (SSTI) and code injection vulne… | 23 | 4197 | maintenance |
| Hackmanit/Web-Cache-Vulnerability-Scanner A fast, Go-based CLI scanner for detecting web cache poisoning and web cache deception vulnerabilities. It supports many attack techniques,… | 60 | 1200 | active |
| ozguralp/gmapsapiscanner A Python CLI tool that tests whether a leaked or discovered Google Maps API key is vulnerable to unauthorized usage across many Google Maps… | 70 | 1198 | active |
| The-Viper-One/PsMapExec PsMapExec is a PowerShell-based post-exploitation framework inspired by CrackMapExec/NetExec for assessing Active Directory environments. I… | 61 | 1198 | active |
| internetwache/GitTools GitTools is a collection of three shell/Python scripts for finding and exploiting websites that publicly expose their .git directory. It in… | 64 | 4178 | maintenance |
| vanhauser-thc/thc-ipv6 A comprehensive IPv6 attack toolkit written in C, providing dozens of tools for spoofing, man-in-the-middle, denial-of-service, scanning, a… | 58 | 1196 | active |
| huntergregal/mimipenguin MimiPenguin is a post-exploitation tool that dumps the current Linux desktop user's cleartext login password from process memory, inspired … | 41 | 4157 | maintenance |
| jayus0821/swagger-hack A Python CLI tool that automatically crawls all endpoints exposed by leaked Swagger/OpenAPI documentation and sends configured test request… | 57 | 1189 | active |
| yazgx97/frida-ios-hook A Python/JavaScript CLI tool that wraps Frida to make it easy to trace classes and functions, hook methods, and modify return values on iOS… | 69 | 1183 | active |
| runZeroInc/sshamble SSHamble is a Go-based research and scanning tool for probing SSH server implementations. It enumerates SSH capabilities and tests for auth… | 68 | 1180 | active |
| JoelGMSec/EvilnoVNC EvilnoVNC is a ready-to-run phishing platform that gives victims a real Chromium browser session over a noVNC connection inside Docker, whi… | 41 | 1176 | active |
| S3cur3Th1sSh1t/Creds A collection of PowerShell scripts and executables useful for penetration testing and forensics, mostly Windows and Active Directory domain… | 76 | 1174 | active |
| NH-RED-TEAM/RustHound RustHound is a cross-platform Active Directory data collector for BloodHound Legacy 4.x, written in Rust. It enumerates users, groups, comp… | 23 | 1171 | active |
| Quitten/Autorize Autorize is a Burp Suite extension, written in Jython, that automatically detects authorization and authentication enforcement flaws in web… | 56 | 1169 | active |
| jasonxtn/Kraken Kraken is a Python-based menu-driven toolkit that centralizes brute-force attacks across network protocols (SSH, FTP, LDAP, Telnet, WiFi), … | 23 | 1169 | active |
| v4lkyr0/Buildware-Tools Buildware-Tools is a Python-based terminal multitool combining OSINT reconnaissance, network diagnostics, Discord automation, cryptography … | 78 | 1167 | active |
| 0xthirteen/SharpRDP SharpRDP is a C# console application that executes authenticated commands on remote Windows hosts via the Remote Desktop Protocol, using th… | 75 | 1162 | active |
| arthepsy/CVE-2021-4034 A proof-of-concept exploit for CVE-2021-4034 (PwnKit), a local privilege escalation vulnerability in polkit's pkexec utility. It is a small… | 32 | 1160 | stable |
| pureqh/Hyacinth Hyacinth is a Java-based GUI tool that bundles detection and exploitation modules for common Java vulnerabilities such as Struts2, Fast, We… | 55 | 1144 | active |
| the-useless-one/pywerview PywerView is a partial Python rewrite of PowerSploit's PowerView for Active Directory enumeration, built on impacket. It lets pentesters ru… | 76 | 1133 | active |
| Arinerron/CVE-2022-0847-DirtyPipe-Exploit A C-based root privilege escalation exploit for CVE-2022-0847 (Dirty Pipe), a Linux kernel vulnerability. It modifies Max Kellermann's proo… | 32 | 1133 | stable |
| RuoJi6/CACM CACM is a Linux post-exploitation and privilege persistence tool that bundles port scanning, sensitive information gathering, EDR/AV identi… | 85 | 1121 | active |
| spyboy-productions/CamXploit CamXploit is a Python-based security reconnaissance tool that checks whether an IP address hosts a potentially exposed IP camera or CCTV se… | 48 | 1118 | active |
| outlaws-bai/Galaxy Galaxy is a Burp Suite extension that automatically decrypts and re-encrypts HTTP traffic whose payloads are encrypted, letting testers wor… | 88 | 1109 | active |