function: penetration-testing
859 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| Cyb0r9/SocialBox SocialBox is a shell-based brute-force attack framework targeting Facebook, Gmail, Instagram, and Twitter login forms. It is a penetration-… | 32 | 2034 | maintenance |
| fin3ss3g0d/evilgophish evilgophish is a Go-based framework combining evilginx3 and GoPhish for running authorized phishing and smishing campaigns with real-time c… | 32 | 2022 | maintenance |
| Nekmo/dirhunt Dirhunt is a Python CLI web crawler optimized for finding and analyzing web directories without brute-forcing paths. It detects 'index of' … | 23 | 2007 | maintenance |
| cube0x0/CVE-2021-1675 A proof-of-concept exploit tool implementing the PrintNightmare vulnerabilities (CVE-2021-1675/CVE-2021-34527) in both C# and Python (Impac… | 32 | 1999 | maintenance |
| 411Hall/JAWS JAWS is a PowerShell enumeration script that helps penetration testers and CTF players quickly identify potential Windows privilege escalat… | 32 | 1993 | maintenance |
| mdsecactivebreach/SharpShooter SharpShooter is a payload creation framework for retrieving and executing arbitrary CSharp source code, generating payloads in formats like… | 32 | 1988 | maintenance |
| samyk/slipstream NAT Slipstreaming is a security research tool by Samy Kamkar that demonstrates remotely opening arbitrary firewall pinholes through a victi… | 32 | 1984 | maintenance |
| h3xduck/TripleCross TripleCross is a Linux eBPF rootkit demonstrating offensive capabilities of eBPF technology, including library injection, execution hijacki… | 23 | 1977 | maintenance |
| jondonas/linux-exploit-suggester-2 A Perl script that suggests Linux kernel privilege escalation exploits based on the running kernel version. It matches the kernel release a… | 32 | 1973 | maintenance |
| D35m0nd142/LFISuite LFISuite is a fully automatic Python tool that scans for and exploits Local File Inclusion (LFI) vulnerabilities using eight different atta… | 23 | 1961 | maintenance |
| w-digital-scanner/w13scan W13Scan is an open-source Python3 web vulnerability scanner supporting both passive (proxy-based) and active scanning modes. It ships with … | 32 | 1946 | maintenance |
| Xyntax/POC-T POC-T is a Python 2.7 plugin-based concurrent framework for penetration testing tasks such as crawling, bruteforcing, and batch PoC/EXP ver… | 23 | 1936 | maintenance |
| dirkjanm/mitm6 mitm6 is a Python pentesting tool that exploits Windows' default IPv6 configuration by answering DHCPv6 requests, assigning victims a link-… | 23 | 1918 | maintenance |
| SummerSec/SpringBootExploit A Java GUI tool for quickly exploiting Spring Boot actuator/env page vulnerabilities, built from the LandGrey SpringBootVulExploit checklis… | 10 | 1897 | maintenance |
| inbug-team/InScan InScan is a Go-based automated intranet penetration testing tool designed for use after breaching a network boundary. It provides port scan… | 32 | 1888 | maintenance |
| lobuhi/byp4xx byp4xx is a command-line tool written in Go that attempts to bypass HTTP 40X (access denied) responses using techniques like verb tampering… | 32 | 1888 | maintenance |
| corelan/mona mona.py is a Python plugin for debuggers (Immunity Debugger, x64dbg) that assists with exploit development tasks such as finding ROP gadget… | 10 | 1888 | maintenance |
| google/security-research-pocs A collection of proof-of-concept exploit code produced during security research by the Google Security Team. It serves as a reference repos… | 10 | 1880 | maintenance |
| 0xInfection/TIDoS-Framework TIDoS is a Python-based offensive web application penetration testing framework with a Metasploit-like console interface and an optional Qt… | 23 | 1868 | maintenance |
| orlyjamie/mimikittenz mimikittenz is a post-exploitation PowerShell tool that uses the Windows ReadProcessMemory() function to extract plain-text passwords and o… | 32 | 1867 | maintenance |
| jaykali/hackerpro HackerPro is an all-in-one penetration testing tool collection for Linux and Android (Termux) that bundles popular security tools like Nmap… | 32 | 1852 | maintenance |
| kozmer/log4j-shell-poc A proof-of-concept exploit tool for the Log4Shell vulnerability (CVE-2021-44228) in the Java log4j logging library. It automates setting up… | 10 | 1848 | maintenance |
| wavestone-cdt/EDRSandblast EDRSandBlast is a C-based offensive security tool that weaponizes vulnerable signed drivers to bypass EDR detections on Windows, including … | 32 | 1844 | maintenance |
| CCob/SweetPotato SweetPotato is a C# command-line tool that collects multiple native Windows privilege escalation techniques (RottenPotato, PrintSpoofer, Ef… | 32 | 1839 | maintenance |
| cyweb/hammer A Python 3 command-line script for performing DDoS (denial-of-service) flood attacks against target servers. It is a simple offensive secur… | 48 | 1832 | maintenance |
| sleventyeleven/linuxprivchecker A single-file Python script that enumerates a local Linux system and searches for common privilege escalation vectors such as world-writabl… | 32 | 1832 | maintenance |
| neex/phuip-fpizdam A Go-based exploit tool for CVE-2019-11043, a remote code execution vulnerability in php-fpm when used behind certain nginx configurations.… | 32 | 1831 | maintenance |
| mm0r1/exploits A collection of PHP 'pwn' exploits that bypass the disable_functions restriction in PHP using known interpreter bugs (e.g., bug #81705, #72… | 32 | 1825 | maintenance |
| Matrix07ksa/Brute_Force A Python CLI tool that performs brute-force password attacks against Gmail, Hotmail, Twitter, Facebook, and Netflix accounts, with optional… | 32 | 1820 | maintenance |
| fsociety-team/fsociety fsociety is a modular penetration testing framework written in Python that wraps and organizes popular security tools (nmap, sqlmap, Sherlo… | 67 | 1819 | maintenance |
| klezVirus/inceptor Inceptor is a template-driven PE packer and AV/EDR evasion framework for Windows, aimed at penetration testers and red teamers. It automate… | 32 | 1817 | maintenance |
| InteliSecureLabs/Linux_Exploit_Suggester A Perl script that suggests possible Linux kernel exploits based on the operating system release number (uname -r). It matches the kernel v… | 32 | 1812 | maintenance |
| hlldz/Phant0m Phant0m is a Windows Event Log Killer that identifies the process hosting the Windows Event Log service and terminates only its threads, so… | 10 | 1812 | maintenance |
| pmiaowu/BurpShiroPassiveScan A passive BurpSuite extension written in Java that automatically detects Apache Shiro framework usage and tests for known Shiro encryption … | 23 | 1806 | maintenance |
| KimJun1010/WeblogicTool A GUI-based vulnerability exploitation toolkit targeting Oracle WebLogic servers, supporting detection and exploitation of numerous CVEs vi… | 20 | 1804 | maintenance |
| Kevin-Robertson/Invoke-TheHash A collection of PowerShell functions for performing pass-the-hash attacks over WMI and SMB using NTLM hash authentication. It implements ra… | 32 | 1803 | maintenance |
| lockedbyte/CVE-2021-40444 A proof-of-concept exploit generator for CVE-2021-40444, a Microsoft Office Word remote code execution vulnerability. It generates maliciou… | 32 | 1800 | maintenance |
| enjoiz/XXEinjector XXEinjector is a Ruby command-line tool that automates exploitation of XML External Entity (XXE) vulnerabilities using direct and out-of-ba… | 32 | 1795 | maintenance |
| acecilia/OpenWRTInvasion A Python/Docker-based exploit script that gains a root shell on several Xiaomi routers (4A Gigabit, 4A 100M, 4, 4C, 3Gv2, 4Q, miWifi 3C) vi… | 23 | 1791 | maintenance |
| iceyhexman/onlinetools A self-hosted web-based penetration testing toolbox written in Python that bundles common recon and scanning tasks behind a browser UI. It … | 10 | 1788 | maintenance |
| lucasjacks0n/EggShell EggShell is a Python-based post-exploitation surveillance and remote administration tool that provides a command-line session with a target… | 32 | 1768 | maintenance |
| tanweai/wooyun-legacy A Claude Code plugin that injects real-world case citations, statistics, and data-driven prioritization into AI-generated security reports,… | 57 | 1759 | maintenance |
| Moham3dRiahi/XAttacker XAttacker is a Perl-based command-line tool that scans websites for vulnerabilities and automatically exploits them. It detects the target'… | 32 | 1757 | maintenance |
| al0ne/Vxscan Vxscan is a Python3-based comprehensive security scanning tool for authorized penetration testing. It combines host liveness checks, port s… | 32 | 1755 | maintenance |
| DanMcInerney/xsscrapy A Python-based spider built on Scrapy that crawls a website and tests every link it finds for cross-site scripting (XSS) and basic SQL inje… | 32 | 1747 | maintenance |
| knownsec/shellcodeloader A Windows shellcode loader generator written in C++ that packages raw shellcode into encrypted executables with multiple loading techniques… | 23 | 1747 | maintenance |
| chenjj/espoofer espoofer is a Python-based testing tool that crafts spoofed emails to bypass SPF, DKIM, and DMARC authentication, including forged DKIM sig… | 32 | 1745 | maintenance |
| jtesta/ssh-mitm A penetration testing tool that intercepts SSH connections by running a patched OpenSSH v7.5p1 server as a proxy between a victim and their… | 10 | 1740 | maintenance |
| AnonHackerr/toolss A Python script that automatically installs a collection of hacking and penetration-testing tools on Android devices running Termux. It act… | 32 | 1734 | maintenance |
| sting8k/BurpSuite_403Bypasser A Burp Suite extension written in Python that automatically attempts to bypass 403 Forbidden responses on restricted directories. It hooks … | 32 | 1705 | maintenance |
| The404Hacking/AndroRAT AndroRAT is a Remote Administration Tool (RAT) for Android, consisting of a Java Android client that runs as a background service and a Jav… | 32 | 1694 | maintenance |
| irsdl/IIS-ShortName-Scanner A Java-based scanner that detects and exploits the Microsoft IIS short file name (8.3) disclosure vulnerability using tilde (~) character r… | 32 | 1691 | maintenance |
| swisskyrepo/GraphQLmap GraphQLmap is a Python scripting engine and interactive CLI for interacting with GraphQL endpoints during penetration testing. It supports … | 32 | 1688 | maintenance |
| zhengjim/camille Camille is a Frida-based auxiliary tool for detecting Android app privacy compliance. It hooks sensitive Android APIs to reveal whether the… | 32 | 1682 | maintenance |
| eladshamir/Internal-Monologue A C# post-exploitation tool that retrieves NTLM hashes by inducing NetNTLM challenge-response computations in-process, without touching the… | 32 | 1681 | maintenance |
| rasta-mouse/Watson Watson is a .NET console tool that enumerates missing Windows KB patches and suggests exploits for known privilege escalation vulnerabiliti… | 10 | 1680 | maintenance |
| noob-hackers/grabcam Grabcam is a bash-based Termux script that generates a fake offer page and an ngrok link to trick a victim into granting camera access, cap… | 32 | 1674 | maintenance |
| SECFORCE/sparta SPARTA is a Python GUI application that simplifies network infrastructure penetration testing by streamlining the scanning and enumeration … | 23 | 1671 | maintenance |
| TheKingOfDuck/burpFakeIP A Burp Suite extension written in Java that forges IP addresses in HTTP request headers (X-Forwarded-For and similar) to test servers with … | 23 | 1668 | maintenance |
| Dheerajmadhukar/4-ZERO-3 4-ZERO-3 is a Bash-based security testing script that automates a wide range of techniques for bypassing HTTP 403/401 access restrictions o… | 32 | 1667 | maintenance |
| taviso/ctftool An interactive command-line tool for exploring the CTF (Clipboard/Text Services Framework) protocol used by Windows Text Services. It suppo… | 23 | 1667 | maintenance |
| opensec-cn/kunpeng Kunpeng is an open-source vulnerability POC (proof-of-concept) detection framework written in Go, bundling POCs for databases, middleware, … | 23 | 1663 | maintenance |
| Dec0ne/KrbRelayUp KrbRelayUp is a C# command-line tool that wraps Rubeus and KrbRelay to automate a Kerberos relay-based local privilege escalation in Window… | 32 | 1657 | maintenance |
| Mr-Un1k0d3r/SCShell SCShell is a fileless lateral movement tool that executes commands on remote Windows systems by modifying a service's binary path via Chang… | 32 | 1655 | maintenance |
| d3vilbug/HackBar A Burp Suite plugin that adds a HackBar panel for quickly injecting common payloads like SQLi and XSS during manual web application testing… | 23 | 1632 | maintenance |
| veo/vscan vscan is an open-source, lightweight, fast, cross-platform website vulnerability scanner written in Go, built for red team reconnaissance. … | 23 | 1632 | maintenance |
| androidmalware/android_hid A set of shell scripts that turn a rooted Android device into a USB HID keyboard (Rubber Ducky style) to inject keystroke payloads into tar… | 32 | 1631 | maintenance |
| JohnHammond/msdt-follina A Python CLI tool that generates malicious Microsoft Word documents exploiting the MS-MSDT 'Follina' vulnerability (CVE-2022-30190) and sta… | 32 | 1630 | maintenance |
| dpnishant/appmon AppMon is an automated framework for monitoring and tampering with system API calls of native macOS, iOS, and Android apps, built on Frida.… | 10 | 1630 | maintenance |
| jivoi/pentest A collection of Python and shell scripts for offensive security and penetration testing tasks, including host discovery, port scanning, and… | 32 | 1627 | maintenance |
| sweetsoftware/Ares Ares is a Python-based remote access tool (RAT) consisting of a web-based command-and-control server and a lightweight agent that runs on t… | 32 | 1620 | maintenance |
| byt3bl33d3r/DeathStar DeathStar is a Python CLI tool that automates gaining Domain and Enterprise Admin privileges in Active Directory environments by chaining c… | 32 | 1618 | maintenance |
| nccgroup/Winpayloads Winpayloads is a Python 2.7 tool for generating undetectable Windows payloads with extras like UAC bypass, persistence, and PowerShell stag… | 32 | 1616 | maintenance |
| stark0de/nginxpwner Nginxpwner is a Python command-line tool that scans Nginx servers for common misconfigurations and known vulnerabilities, such as CRLF inje… | 10 | 1599 | maintenance |
| tokyoneon/Chimera Chimera is a PowerShell obfuscation script that transforms malicious PS1 payloads using string substitution and variable concatenation to b… | 32 | 1597 | maintenance |
| outflanknl/Dumpert Dumpert is a proof-of-concept LSASS memory dumper written in C and assembly that uses direct system calls and API unhooking to evade AV/EDR… | 32 | 1595 | maintenance |
| Lotus6/ThinkphpGUI A Java-based GUI vulnerability exploitation tool targeting the ThinkPHP framework, supporting detection of vulnerabilities across ThinkPHP … | 23 | 1595 | maintenance |
| wyzxxz/shiro_rce_tool A Java-based command-line tool that assists in detecting and exploiting Apache Shiro rememberMe deserialization vulnerabilities. It brute-f… | 32 | 1594 | maintenance |
| sairson/Yasso Yasso is a Go-based intranet penetration testing toolkit that combines service brute-forcing (RDP, SSH, Redis, PostgreSQL, MongoDB, MSSQL, … | 23 | 1594 | maintenance |
| savio-code/fern-wifi-cracker Fern Wifi Cracker is a Python/Qt GUI application for wireless security auditing that can crack and recover WEP, WPA/WPA2, and WPS keys. It … | 70 | 1592 | maintenance |
| 0xHJK/dumpall dumpall is a Python command-line tool for exploiting information disclosure vulnerabilities on web servers. It reconstructs source code fro… | 23 | 1579 | maintenance |
| XiphosResearch/exploits A collection of miscellaneous proof-of-concept exploit scripts written by Xiphos Research for security testing purposes, covering CVEs acro… | 32 | 1575 | maintenance |
| v3n0m-Scanner/V3n0M-Scanner V3n0M is an offensive security framework and vulnerability scanner written in Python 3.6+ using asyncio. It scans for SQLi, XSS, LFI/RFI vu… | 23 | 1573 | maintenance |
| DeEpinGh0st/Erebus Erebus is a post-exploitation plugin for Cobalt Strike written in PowerShell and Sleep (Aggressor Script). It bundles information gathering… | 23 | 1568 | maintenance |
| Viralmaniar/BigBountyRecon BigBountyRecon is a C# Windows GUI tool that automates initial reconnaissance on a target organisation using 58 techniques, including Googl… | 23 | 1564 | maintenance |
| Mr-Un1k0d3r/PowerLessShell PowerLessShell is a Python CLI tool that generates MSBuild project files capable of executing PowerShell scripts or raw shellcode without s… | 66 | 1559 | maintenance |
| Cn33liz/p0wnedShell p0wnedShell is a C# offensive PowerShell host application that runs PowerShell commands and modules within a runspace environment without r… | 32 | 1550 | maintenance |
| GhostPack/SharpUp SharpUp is a C# port of common Windows privilege escalation checks from the PowerUp PowerShell script. It audits a system for misconfigurat… | 32 | 1531 | maintenance |
| galkan/crowbar Crowbar is a Python-based brute forcing tool for penetration testing that supports protocols often missing from other brute force tools, su… | 23 | 1531 | maintenance |
| harleyQu1nn/AggressorScripts A curated collection of Aggressor scripts (.cna) for Cobalt Strike 3.0+, aggregated from multiple community sources. The scripts automate r… | 32 | 1530 | maintenance |
| Ha3MrX/InstaBrute InstaBrute is a shell script that performs brute-force password attacks against Instagram accounts, exploiting password-guessing vectors co… | 71 | 1527 | maintenance |
| Yaxser/Backstab Backstab is a Windows command-line tool that kills antimalware/EDR-protected processes by abusing the Microsoft-signed Sysinternals Process… | 23 | 1527 | maintenance |
| chaitin/rad Rad (Radium) is a browser-based web crawler built for security scanning, driving a real Chrome browser to discover URLs and requests across… | 23 | 1514 | maintenance |
| WooyunDota/DroidSSLUnpinning A collection of Frida hook scripts (ObjectionUnpinningPlus) that bypass Android certificate pinning so HTTPS traffic can be intercepted wit… | 32 | 1509 | maintenance |
| hatRiot/zarp Zarp is a Python-based network attack tool focused on exploiting local networks by abusing networking protocols rather than systems. It pro… | 23 | 1504 | maintenance |
| pentestmonkey/windows-privesc-check A standalone Windows executable (built from Python with PyInstaller) that audits systems for privilege escalation vectors such as weak serv… | 32 | 1500 | maintenance |
| Kevin-Robertson/Powermad Powermad is a set of PowerShell functions for exploiting Active Directory's default MachineAccountQuota and Active Directory-Integrated DNS… | 32 | 1500 | maintenance |
| 0x00-0x00/ShellPop ShellPop is a Python CLI tool that generates ready-to-use reverse and bind shell commands for penetration testing, with obfuscation, encode… | 23 | 1485 | maintenance |
| optiv/Freeze Freeze is a Go-based payload creation toolkit that generates Windows shellcode loaders designed to bypass EDR security controls. It uses su… | 10 | 1476 | maintenance |
| jordanpotti/AWSBucketDump AWSBucketDump is a Python CLI security tool that enumerates AWS S3 buckets using wordlists, similar to a subdomain bruteforcer but for S3. … | 32 | 1473 | maintenance |