function: penetration-testing
859 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| fuzzland/ityfuzz ItyFuzz is a blazing-fast bytecode-level hybrid fuzzer for EVM and MoveVM smart contracts that combines symbolic (concolic) execution with … | 55 | 1108 | active |
| PortSwigger/mcp-server A Burp Suite extension by PortSwigger that exposes Burp's capabilities to AI clients via the Model Context Protocol (MCP). It includes an S… | 70 | 1107 | active |
| CuriousLearnerDev/Online_tools A security tool marketplace application that lets users download, update, and automatically install a large catalog of penetration testing … | 96 | 1106 | active |
| dafthack/MSOLSpray MSOLSpray is a PowerShell-based password spraying tool for Microsoft Online (Azure AD/O365) accounts. It leverages Azure AD OAuth2 error co… | 32 | 1100 | stable |
| EnableSecurity/sipvicious SIPVicious OSS is a Python-based toolset for auditing SIP-based VoIP systems, including tools to scan for SIP servers (svmap), enumerate ex… | 89 | 1098 | active |
| mbechler/marshalsec marshalsec is a Java tool and research project that generates exploitation payloads for insecure unmarshalling across many Java marshalling… | 32 | 3708 | maintenance |
| Gameye98/Lazymux Lazymux is a Python-based menu-driven installer for Termux that lets users install and run many penetration testing and hacking tools (e.g.… | 32 | 3700 | maintenance |
| m-sec-org/EZ EZ is a cross-platform vulnerability scanner that combines information gathering, port scanning, service brute-forcing, URL crawling, finge… | 24 | 1078 | active |
| hahwul/jwt-hack jwt-hack is a fast, single-binary Rust CLI toolkit for testing, analyzing, and attacking JSON Web Tokens (JWT) and JWE tokens. It supports … | 91 | 1075 | active |
| trailofbits/anamorpher Anamorpher is a tool for crafting and visualizing image scaling attacks that hide multi-modal prompt injections in images, revealed only wh… | 55 | 1075 | active |
| xiaogang000/XG_NTAI A Java-based GUI tool for generating obfuscated webshell payloads (ASP, PHP, JSP, JSPX) that evade WAF and antivirus detection, compatible … | 37 | 1075 | active |
| thehackingsage/hackdroid HackDroid is a curated collection of 364+ pentesting and security-related Android apps organized into categories like MITM, forensics, snif… | 32 | 1072 | active |
| nathanlopez/Stitch Stitch is a cross-platform Python Remote Administration Tool (RAT) framework for building custom payloads for Windows, macOS, and Linux. It… | 32 | 3660 | maintenance |
| clr2of8/DPAT DPAT is a Python-based Domain Password Audit Tool for penetration testers that analyzes NTDS password dumps combined with cracking results … | 58 | 1065 | active |
| synacktiv/php_filter_chain_generator A Python CLI tool by Synacktiv that generates PHP filter chains (php://filter gadget chains) to achieve remote code execution when an attac… | 32 | 1065 | stable |
| Lazarus-AI/clearwing Clearwing is a dual-mode autonomous offensive-security tool that combines a network-pentest ReAct agent with an LLM-driven source-code vuln… | 63 | 1063 | active |
| itsreyi/BlockSuite Block-Suite is a modular JavaFX desktop application for authorized Minecraft server security assessments. It deploys a transparent MITM pro… | 67 | 1060 | active |
| ElevenPaths/FOCA FOCA is a Windows desktop application that finds metadata and hidden information in documents discovered via search engines (Google, Bing, … | 23 | 3622 | maintenance |
| lachlan2k/React2Shell-CVE-2025-55182-original-poc A collection of original proof-of-concept exploits for CVE-2025-55182 (React2Shell), a remote code execution vulnerability in React Server … | 41 | 1059 | active |
| NetSPI/PowerHuntShares PowerHuntShares is a PowerShell audit tool that inventories, analyzes, and reports excessive privileges on SMB share ACLs across Active Dir… | 53 | 1052 | active |
| 0xZDH/o365spray o365spray is a Python CLI tool for username enumeration and password spraying against Microsoft Office 365 domains. It implements multiple … | 32 | 1050 | active |
| smxiazi/NEW_xp_CAPTCHA xp_CAPTCHA is a Burp Suite extension (Java plugin) that automatically recognizes CAPTCHAs during brute-force attacks, using a companion Pyt… | 23 | 1050 | active |
| bountyyfi/lonkero Lonkero is a professional-grade web application security scanner written in Rust, built for real penetration testing with 125+ scan modules… | 73 | 1047 | active |
| xm1k3/cent Cent is a Go CLI tool that aggregates and organizes community-contributed Nuclei vulnerability scanning templates into a single local folde… | 81 | 1046 | active |
| amlweems/xzbot A research toolkit for the xz backdoor (CVE-2024-3094) containing an OpenSSH honeypot patch to detect exploit attempts, a patch script to r… | 25 | 3554 | maintenance |
| bszapp/android-wifi-pojie An Android WiFi toolbox app written in Kotlin that brute-forces WiFi passwords using password dictionaries, supporting multiple run modes (… | 73 | 1036 | active |
| vanhoefm/krackattacks-scripts Scripts by Mathy Vanhoef to test whether Wi-Fi clients or access points are vulnerable to the KRACK attack against WPA2. They include a mod… | 23 | 3524 | maintenance |
| zhzyker/vulmap Vulmap is a Python 3 command-line tool that scans web applications for known CVE vulnerabilities and can immediately verify or exploit them… | 23 | 3521 | maintenance |
| carlospolop/legion Legion is a Python-based automatic enumeration tool that orchestrates well-known open-source pentesting tools (nmap, hydra, metasploit) to … | 74 | 1032 | active |
| AsjadOooO/Zero-attacker Zero-attacker is a multipurpose Python-based hacking toolkit bundling 15+ tools for ethical hacking and Discord operations, including DDoS,… | 45 | 1021 | active |
| chAng-L19/codex-redteam-mode An opt-in red-team mode plugin for OpenAI Codex App and Codex CLI that compiles offensive-security objectives into GoalContracts and execut… | 80 | 1016 | active |
| AKCodez/hackingtool-plugin A Claude Code plugin that wraps 183+ pentesting and OSINT tools from Z4nzu/hackingtool, letting Claude automatically select and run securit… | 50 | 1016 | active |
| Spade-sec/First A WeChat mini-program security debugging tool (fork/extension of WMPFDebugger) that uses Frida injection and Chrome DevTools Protocol bridg… | 74 | 1015 | active |
| redcode-labs/neurax Neurax is a Go framework for constructing self-spreading binaries (worms) that propagate across LAN/WAN networks without external servers. … | 32 | 1015 | active |
| secretsquirrel/the-backdoor-factory The Backdoor Factory (BDF) is a Python command-line tool that patches Windows PE, Linux ELF, and macOS Mach-O executables with user-supplie… | 32 | 3439 | maintenance |
| fullhunt/log4j-scan A Python-based automated scanner for detecting the Log4j RCE vulnerability (CVE-2021-44228, Log4Shell) and related CVEs across lists of URL… | 23 | 3422 | maintenance |
| indetectables-net/toolkit A curated Windows toolkit bundling 101 applications for reverse engineering, malware analysis, and cracking, installed via an automated Inn… | 89 | 1009 | active |
| tarunkant/Gopherus Gopherus is a Python CLI tool that generates Gopher protocol payloads for exploiting SSRF vulnerabilities to achieve remote code execution.… | 32 | 3411 | maintenance |
| dedsec1121fk/DedSec DedSec Project is an educational cybersecurity and Termux toolkit for Android that bundles scripts, utilities, local web interfaces, and pr… | 88 | 1005 | active |
| controlplaneio/simulator A distributed systems and infrastructure security training platform that provisions a Kubernetes cluster in your AWS account and runs scena… | 23 | 1000 | active |
| linkedin/qark QARK (Quick Android Review Kit) is a Python command-line tool from LinkedIn that scans Android applications, either as Java source code or … | 23 | 3382 | maintenance |
| codingo/NoSQLMap NoSQLMap is an open-source Python command-line tool that audits, automates injection attacks against, and exploits default configuration we… | 65 | 3345 | maintenance |
| gwen001/pentest-tools A collection of small custom security scripts in Bash, Python, and PHP for penetration testing and bug bounty quick tasks, covering DNS enu… | 23 | 3323 | maintenance |
| nabla-c0d3/ssl-kill-switch2 SSL Kill Switch 2 is a blackbox Cydia Substrate tweak that disables SSL/TLS certificate validation, including certificate pinning, in iOS a… | 23 | 3311 | maintenance |
| Ignitetch/AdvPhishing A command-line phishing toolkit that hosts fake login pages for popular services (Facebook, Google, Paytm, Zomato, etc.) and performs real-… | 50 | 3268 | maintenance |
| risinek/esp32-wifi-penetration-tool An extensible Wi-Fi penetration testing framework for the ESP32 microcontroller, implementing attacks such as PMKID capture, WPA/WPA2 hands… | 23 | 3050 | maintenance |
| NYAN-x-CAT/AsyncRAT-C-Sharp AsyncRAT is an open-source Remote Access Tool (RAT) written in C# that lets an operator remotely monitor and control Windows client machine… | 23 | 3008 | maintenance |
| christophetd/CloudFlair CloudFlair is a Python CLI tool that finds the origin servers of websites protected by Cloudflare or CloudFront by searching Censys interne… | 41 | 2972 | maintenance |
| google/nogotofail Nogotofail is an on-path (man-in-the-middle) blackbox network traffic security testing tool built in Python. It detects weak TLS/SSL connec… | 10 | 2951 | maintenance |
| Ekultek/WhatWaf WhatWaf is a Python command-line tool that detects web application firewalls (WAFs) protecting a target web application and attempts to fin… | 23 | 2924 | maintenance |
| mrd0x/BITB A collection of HTML/JavaScript templates implementing the Browser In The Browser (BITB) phishing technique, which renders fake browser win… | 32 | 2897 | maintenance |
| pentestmonkey/php-reverse-shell A PHP script that opens an interactive reverse shell connection back to an attacker-controlled listener. It is a well-known utility for pen… | 32 | 2853 | maintenance |
| AntSwordProject/AntSword-Loader AntSword Loader is the official Electron-based launcher for AntSword, a cross-platform webshell management and post-exploitation tool used … | 23 | 2835 | maintenance |
| tiagorlampert/CHAOS CHAOS is a free and open-source Remote Administration Tool written in Go that generates cross-platform binaries (Windows and Linux) for con… | 23 | 2830 | maintenance |
| welk1n/JNDI-Injection-Exploit A Java-based penetration testing tool that generates workable JNDI links and starts RMI, LDAP, and HTTP servers to exploit JNDI injection v… | 23 | 2823 | maintenance |
| ohpe/juicy-potato Juicy Potato is a C++ Windows local privilege escalation tool that abuses COM/DCOM activation and impersonation privileges (SeImpersonate/S… | 23 | 2820 | maintenance |
| esc0rtd3w/wifi-hacker A shell script that automates attacking wireless connections using the built-in tools of Kali Linux. It supports WEP, WPS, WPA, and WPA2 se… | 23 | 2799 | maintenance |
| Ettercap/ettercap Ettercap is a comprehensive open-source suite for man-in-the-middle attacks on local networks. It supports live connection sniffing, on-the… | 81 | 2784 | maintenance |
| NextronSystems/APTSimulator APT Simulator is a Windows Batch script toolset that makes a system look as if it was the victim of an APT attack, using tools and output f… | 42 | 2764 | maintenance |
| rootm0s/WinPwnage WinPwnage is a Python tool and library that implements UAC bypass, privilege elevation, and persistence techniques for Windows. It can scan… | 32 | 2753 | maintenance |
| shack2/SNETCracker A Windows GUI tool for auditing weak passwords across many network services such as SSH, RDP, SMB, MySQL, Redis, and FTP. It supports batch… | 23 | 2740 | maintenance |
| m0rtem/CloudFail CloudFail is a Python 3 command-line reconnaissance tool that attempts to discover the real IP address of servers hidden behind Cloudflare.… | 32 | 2683 | maintenance |
| flipkart-incubator/Astra Astra is an automated REST API security testing tool from Flipkart that detects vulnerabilities like SQL injection, XSS, broken authenticat… | 32 | 2658 | maintenance |
| ParrotSec/mimikatz mimikatz is a well-known Windows security tool that extracts plaintext passwords, hashes, PINs, and Kerberos tickets from memory, and suppo… | 32 | 2630 | maintenance |
| matterpreter/DefenderCheck A C# command-line tool that takes a binary as input and splits it iteratively to pinpoint the exact bytes that Microsoft Defender flags on.… | 59 | 2623 | maintenance |
| AlessandroZ/BeRoot BeRoot is a post-exploitation tool that checks common misconfigurations on Windows, Linux, and macOS hosts to identify potential privilege … | 23 | 2621 | maintenance |
| Tuhinshubhra/CMSeeK CMSeeK is a Python 3 command-line suite that detects the content management system (CMS) powering a website, supporting over 180 CMSs inclu… | 65 | 2571 | maintenance |
| brendan-rius/c-jwt-cracker A multi-threaded JWT brute-force secret key cracker written in C using OpenSSL. It attempts to recover the HMAC signing key of a JWT token … | 32 | 2559 | maintenance |
| chrisk44/Hijacker Hijacker is an Android GUI wrapper for wireless penetration testing tools including Aircrack-ng, Airodump-ng, MDK3, and Reaver. It lets use… | 10 | 2544 | maintenance |
| joaomatosf/jexboss JexBoss is a Python command-line tool for testing and exploiting JBoss Application Server and Java deserialization vulnerabilities. It supp… | 32 | 2518 | maintenance |
| Chora10/Cknife Cknife (China Chopper Knife) is a Java-based cross-platform webshell management tool, an open-source client compatible with the China Chopp… | 32 | 2422 | maintenance |
| secretsquirrel/SigThief SigThief is a Python CLI tool that rips the Authenticode signature off a signed PE file and appends it to another binary, patching the cert… | 32 | 2416 | maintenance |
| tr0uble-mAker/POC-bomber POC-bomber is a Python-based offensive security tool that bundles a large arsenal of high-impact POCs and EXPs (RCE, deserialization, file … | 23 | 2369 | maintenance |
| dana-at-cp/backdoor-apk A shell script that automates injecting a Metasploit backdoor payload into any Android APK by decompiling, hooking smali code, and re-signi… | 32 | 2367 | maintenance |
| bugcrowd/HUNT HUNT Suite is a collection of Burp Suite and OWASP ZAP proxy extensions that identify common parameters vulnerable to vulnerability classes… | 67 | 2331 | maintenance |
| sensepost/ruler Ruler is a Go-based command-line tool for interacting with and abusing Microsoft Exchange servers via MAPI/HTTP or RPC/HTTP. It enables off… | 23 | 2313 | maintenance |
| itm4n/PrintSpoofer PrintSpoofer is a Windows privilege escalation tool that abuses SeImpersonatePrivilege via the Print Spooler 'Printer Bug' to escalate from… | 10 | 2268 | maintenance |
| topotam/PetitPotam PetitPotam is a proof-of-concept tool that coerces Windows hosts to authenticate to attacker-controlled machines via the MS-EFSRPC protocol… | 32 | 2267 | maintenance |
| rabbitmask/WeblogicScan A one-click Python vulnerability scanner for Oracle WebLogic servers, covering nearly all historical WebLogic CVEs (SSRF, Java deserializat… | 32 | 2261 | maintenance |
| worawit/MS17-010 A collection of Python exploit scripts and proof-of-concepts for the MS17-010 Windows SMB vulnerabilities, including Eternalblue, Eternalch… | 32 | 2260 | maintenance |
| ldpreload/BlackLotus An open-source UEFI bootkit targeting Windows that implements a Secure Boot bypass, kernel-level persistence, and an HTTP-based C2 loader w… | 29 | 2240 | maintenance |
| shmilylty/netspy netspy is a fast, cross-platform Go CLI tool for discovering reachable intranet network segments from a compromised host. It supports ICMP,… | 23 | 2238 | maintenance |
| Ascotbe/Medusa Medusa is a self-hosted red team arsenal platform written in Python that bundles tools such as an XSS platform, collaborative platform, CVE… | 23 | 2235 | maintenance |
| evilcos/xssor2 XSS'OR is a self-hostable web application for penetration testers that provides XSS/CSRF payload generation, encoding/decoding utilities, a… | 32 | 2224 | maintenance |
| HatBoy/Struts2-Scan A Python CLI tool that scans and exploits known Apache Struts2 vulnerabilities (S2-001 through S2-057) using publicly disclosed exploits. I… | 32 | 2220 | maintenance |
| LionSec/xerosploit Xerosploit is a Ruby-based penetration testing toolkit that wraps bettercap and nmap to perform man-in-the-middle attacks, port scanning, a… | 23 | 2199 | maintenance |
| thehackingsage/hacktronian Hacktronian is a Python-based, menu-driven collection of penetration testing tools that bundles popular utilities for information gathering… | 32 | 2196 | maintenance |
| codingo/Reconnoitre Reconnoitre is a Python CLI tool for multithreaded information gathering and service enumeration of target hosts and ranges, built original… | 23 | 2196 | maintenance |
| iamj0ker/bypass-403 A shell script that attempts to bypass HTTP 403 Forbidden responses using 24 known bypass techniques via curl. It also compares responses u… | 32 | 2189 | maintenance |
| hexway/apple_bleee A collection of experimental Python PoC scripts for sniffing and injecting Apple Bluetooth Low Energy (BLE) and AWDL (AirDrop) traffic. It … | 23 | 2184 | maintenance |
| IAmBlackHacker/Facebook-BruteForce A Python script that performs brute-force password attacks against Facebook accounts using wordlists, intended for educational purposes. It… | 23 | 2182 | maintenance |
| CedArctic/DigiSpark-Scripts A collection of hand-written Arduino IDE sketches for the DigiSpark ATtiny85 board that turn it into a USB HID keyboard for executing autom… | 32 | 2170 | maintenance |
| noob-hackers/ighack A bash-based Termux script that attempts to brute-force Instagram account passwords using wordlists, routing traffic through Tor for anonym… | 50 | 2141 | maintenance |
| initstring/cloud_enum A Python command-line OSINT tool that enumerates publicly exposed resources across AWS, Azure, and Google Cloud using keyword mutations and… | 79 | 2132 | maintenance |
| skavngr/rapidscan RapidScan is a Python CLI tool that automates web vulnerability scanning by orchestrating multiple security tools (nmap, nikto, wafw00f, ss… | 23 | 2128 | maintenance |
| dafthack/DomainPasswordSpray DomainPasswordSpray is a PowerShell tool that performs password spray attacks against domain user accounts, automatically generating a user… | 32 | 2082 | maintenance |
| iSafeBlue/TrackRay TrackRay (溯光) is an open-source penetration testing framework written in Java on SpringBoot that implements its own vulnerability scanning … | 23 | 2078 | maintenance |
| 0xn0ne/weblogicScanner A Python CLI vulnerability scanner for Oracle WebLogic servers that detects a wide range of known CVEs (2014-2020), including deserializati… | 32 | 2073 | maintenance |
| yzddmr6/WebCrack WebCrack is a Python CLI tool for batch detection of weak passwords and universal-password (SQL injection bypass) vulnerabilities on web ad… | 32 | 2051 | maintenance |
| wszf/androrat AndroRAT is a remote administration tool (RAT) for Android built as a client/server pair: an Android client that runs as a boot-started bac… | 32 | 2040 | maintenance |