function: penetration-testing
859 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| matterpreter/OffensiveCSharp A collection of standalone C# tools and proof-of-concept programs for offensive security operations, each compiled individually in Visual S… | 32 | 1473 | maintenance |
| antonioCoco/RemotePotato0 RemotePotato0 is a Windows privilege escalation exploit that abuses the DCOM activation service to trigger NTLM authentication from privile… | 23 | 1469 | maintenance |
| rootclay/WMIHACKER WMIHACKER is a VBScript-based command-line tool for lateral movement on Windows hosts via WMI (port 135), avoiding the commonly detected 44… | 33 | 1465 | maintenance |
| nccgroup/house House is a runtime mobile application analysis toolkit with a web GUI, powered by Frida and written in Python. It simplifies dynamic functi… | 32 | 1463 | maintenance |
| woodpecker-framework/woodpecker-framework-release Woodpecker-framework is a Java-based vulnerability detection and deep exploitation framework focused on precisely targeting high-risk vulne… | 23 | 1463 | maintenance |
| ptswarm/reFlutter A Python-based framework that repacks Flutter Android and iOS apps with a patched Flutter engine library to enable dynamic analysis. It red… | 10 | 1463 | maintenance |
| SySS-Research/Seth Seth is a Python and Bash proof-of-concept tool that performs a man-in-the-middle attack on RDP connections via ARP spoofing, downgrading t… | 56 | 1454 | maintenance |
| oddcod3/Phantom-Evasion Phantom-Evasion is a Python-based antivirus evasion tool that generates obfuscated executables and payloads designed to bypass antivirus de… | 10 | 1449 | maintenance |
| SamJoan/droopescan Droopescan is a plugin-based command-line scanner that helps security researchers identify the CMS, version, plugins, themes, and interesti… | 32 | 1445 | maintenance |
| jweny/pocassist Pocassist is an open-source vulnerability PoC testing framework written in Go that lets users edit, run, and batch-test PoCs through a web … | 10 | 1436 | maintenance |
| FunnyWolf/pystinger Pystinger is a Python tool that establishes a SOCKS4a proxy and port mapping through a webshell (PHP, JSP, or ASPX) on a compromised server… | 23 | 1427 | maintenance |
| ptoomey3/Keychain-Dumper A command-line tool for jailbroken iOS devices that dumps Keychain items (passwords, certificates, identities) accessible to an attacker. I… | 23 | 1419 | maintenance |
| Mr-Un1k0d3r/DKMC DKMC (Don't Kill My Cat) is a Python CLI tool that embeds obfuscated shellcode inside valid BMP images, producing polyglot files that are b… | 10 | 1418 | maintenance |
| cube0x0/noPac A C# tool that scans for and exploits the CVE-2021-42287/CVE-2021-42278 Active Directory vulnerability chain, allowing a standard domain us… | 32 | 1412 | maintenance |
| m4ll0k/Atlas Atlas is a Python CLI tool that suggests SQLMap tamper scripts to bypass WAF/IDS/IPS protections during SQL injection testing. It works by … | 32 | 1411 | maintenance |
| CiscoCXSecurity/enum4linux enum4Linux is a Perl-based CLI tool that enumerates information from Windows and Samba hosts, serving as a Linux alternative to enum.exe. I… | 71 | 1407 | maintenance |
| c0ny1/FastjsonExploit A Java CLI framework for quickly exploiting Fast deserialization vulnerabilities. It generates exploit payloads with one command and bundle… | 32 | 1406 | maintenance |
| hakluke/weaponised-XSS-payloads A collection of weaponised XSS payloads - JavaScript files that perform sensitive actions (like creating admin users) on popular CMS platfo… | 32 | 1404 | maintenance |
| maK-/parameth parameth is a Python command-line tool that brute-forces GET and POST parameter names on web endpoints by comparing response differences. I… | 10 | 1396 | maintenance |
| 649/Memcrashed-DDoS-Exploit A Python CLI exploit tool that finds exposed Memcached servers via the Shodan API and sends forged UDP packets to them to amplify DDoS atta… | 32 | 1394 | maintenance |
| BastilleResearch/mousejack A collection of device discovery and research tools for the MouseJack vulnerabilities affecting wireless mice and keyboards using nRF24LU1+… | 32 | 1386 | maintenance |
| importCTF/Instagram-Hacker A Python command-line script that performs brute-force password attacks against Instagram accounts, using mechanize and requests with optio… | 32 | 1384 | maintenance |
| 3ndG4me/AutoBlue-MS17-010 A semi-automated, standalone Python exploit for the MS17-010 (EternalBlue) SMB vulnerability that generates kernel shellcode and handles li… | 32 | 1382 | maintenance |
| lijiejie/swagger-exp A Python-based Swagger REST API information disclosure exploitation tool. It enumerates API endpoints, auto-fills parameters, tests for una… | 32 | 1381 | maintenance |
| screetsec/Dracnmap Dracnmap is a shell-based menu tool that wraps nmap to simplify network scanning and information gathering. It exposes nmap's advanced scri… | 23 | 1380 | maintenance |
| bitsadmin/fakelogonscreen FakeLogonScreen is a red-team utility that displays a fake Windows logon screen to capture a user's password, validating it against Active … | 23 | 1378 | maintenance |
| Katana Katana is a Python CLI tool by John Hammond that automates common low-hanging-fruit checks for CTF challenges, paired with ctf-katana, a cu… | 32 | 1363 | maintenance |
| danigargu/CVE-2020-0796 A proof-of-concept exploit for CVE-2020-0796 (SMBGhost), a local privilege escalation vulnerability in Windows 10's SMBv3 client driver. Wr… | 23 | 1359 | maintenance |
| ReversecLabs/SharpGPOAbuse SharpGPOAbuse is a C# .NET command-line tool that abuses a user's edit rights on a Group Policy Object to compromise objects controlled by … | 32 | 1353 | maintenance |
| jeffzh3ng/fuxi Fuxi is a self-hosted penetration testing platform written in Python that provides a web interface for organizing and running security asse… | 32 | 1346 | maintenance |
| LittleBear4/OA-EXPTOOL A Python-based exploitation framework targeting Chinese OA (Office Automation) systems, bundling nearly 20 batch vulnerability scanners for… | 23 | 1345 | maintenance |
| OmerYa/Invisi-Shell Invisi-Shell is a proof-of-concept tool that bypasses PowerShell security features (ScriptBlock logging, Module logging, Transcription, AMS… | 32 | 1339 | maintenance |
| pwnesia/ssb SSB (Secure Shell Bruteforcer) is a fast, concurrent SSH password brute-forcing tool written in Go. It attempts to authenticate against an … | 23 | 1335 | maintenance |
| Arvanaghi/SessionGopher SessionGopher is a PowerShell tool that extracts and decrypts saved session information for remote access tools like WinSCP, PuTTY, SuperPu… | 32 | 1334 | maintenance |
| GhostPack/SafetyKatz SafetyKatz is a C# tool that combines a modified Mimikatz with a .NET PE loader to dump LSASS memory and extract credentials. It minidumps … | 32 | 1332 | maintenance |
| infobyte/evilgrade Evilgrade is a modular penetration testing framework that exploits poor software update implementations by injecting fake updates via DNS m… | 23 | 1326 | maintenance |
| stampery/mongoaudit mongoaudit is a Python CLI tool that audits MongoDB servers for poor security configurations, known vulnerabilities, and misconfigurations.… | 23 | 1324 | maintenance |
| dirkjanm/CVE-2020-1472 A proof-of-concept exploit for CVE-2020-1472 (Zerologon), a critical Netlogon privilege escalation vulnerability in Windows domain controll… | 32 | 1320 | maintenance |
| TermuxHackz/wifi-hacker A shell script that automates attacking wireless connections using built-in Kali Linux tools, supporting WEP, WPS, WPA, and WPA2 securities… | 32 | 1319 | maintenance |
| redhuntlabs/RedHunt-OS RedHunt OS is a pre-configured Linux virtual machine (OVA) bundling adversary emulation and threat hunting tools such as Caldera, Atomic Re… | 33 | 1318 | maintenance |
| vanhoefm/fragattacks A security testing tool that tests Wi-Fi clients and access points for the FragAttacks fragmentation and aggregation vulnerabilities affect… | 41 | 1311 | maintenance |
| k8gege/K8CScan K8CScan is a high-concurrency, plugin-based scanner designed for large internal network penetration testing. It bundles information gatheri… | 32 | 1303 | maintenance |
| Viralmaniar/Passhunt Passhunt is a Python-based command-line tool for searching default credentials across 523 vendors and 2084 default passwords for network de… | 23 | 1303 | maintenance |
| Vu1nT0tal/IoT-vulhub A collection of Docker-based environments for reproducing IoT firmware vulnerabilities, inspired by the Vulhub project. It uses binwalk for… | 23 | 1294 | maintenance |
| kinghacker0/WishFish WishFish is a bash-based security testing tool that generates phishing-style links (wishing or custom pages) which, when opened by a target… | 32 | 1290 | maintenance |
| med0x2e/SigFlip SigFlip is a red-team tool for patching Authenticode-signed PE files (exe, dll, sys) without invalidating their existing signatures, by emb… | 32 | 1290 | maintenance |
| smxiazi/xia_sql A Burp Suite extension (written in Java) that appends single and double quotes to every request parameter to detect possible SQL injection,… | 23 | 1286 | maintenance |
| entropy1337/infernal-twin Infernal-Wireless is an automated wireless hacking framework written in Python that aids penetration testers in assessing Wi-Fi security. I… | 23 | 1285 | maintenance |
| hangetzzu/saycheese SayCheese is a shell-based social engineering tool that generates a malicious HTTPS page to capture webcam photos from a target who clicks … | 32 | 1284 | maintenance |
| c0ny1/upload-fuzz-dic-builder A Python CLI script that generates fuzzing dictionaries for testing file upload vulnerabilities. It tailors wordlists based on target detai… | 32 | 1279 | maintenance |
| yzddmr6/webshell-venom A tool that generates unlimited polymorphic (AV-evading) webshells for penetration testing. It mutates webshell code to bypass antivirus an… | 10 | 1278 | maintenance |
| netxfly/x-crack x-crack is a command-line weak password (credential brute-force) scanner written in Go that tests common username/password combinations aga… | 23 | 1276 | maintenance |
| screetsec/Brutal Brutal is a Linux toolkit for generating HID attack payloads for Teensy boards, similar to a Rubber Ducky but with different syntax. It cre… | 32 | 1270 | maintenance |
| UzJu/Cloud-Bucket-Leak-Detection-Tools A Python CLI tool that detects misconfigured and leaked cloud storage buckets across six major cloud providers including Aliyun, Tencent Cl… | 29 | 1266 | maintenance |
| lintstar/LSTAR LSTAR is a comprehensive Cobalt Strike post-exploitation Aggressor plugin written in PowerShell and CNA. It consolidates host information g… | 23 | 1266 | maintenance |
| shack2/SuperSQLInjectionV1 SuperSQLInjection (SSQLInjection) is a C#-based GUI SQL injection tool that builds raw HTTP requests over TCP sessions, supporting injectio… | 23 | 1266 | maintenance |
| Cybellum/DoubleAgent DoubleAgent is a research tool and proof-of-concept demonstrating a zero-day code injection and persistence technique on Windows, exploitin… | 32 | 1262 | maintenance |
| pmiaowu/BurpFastJsonScan A passive BurpSuite extension written in Java that detects FastJson deserialization vulnerabilities in JSON-bearing HTTP requests. It autom… | 23 | 1251 | maintenance |
| W01fh4cker/Serein Serein is a graphical Python tool for batch-collecting URLs via the FOFA search engine API and running batch detection/exploitation of know… | 10 | 1250 | maintenance |
| m4n3dw0lf/pythem pythem is a multi-purpose penetration testing framework written in Python 2.7, providing an interactive CLI for security researchers. It bu… | 32 | 1248 | maintenance |
| AbirHasan2005/ShellPhish A modified (modded) version of the ShellPhish phishing simulation tool that generates fake login pages for popular websites like Facebook, … | 32 | 1241 | maintenance |
| Tylous/SniffAir SniffAir is an open-source wireless security framework for parsing passively collected wireless traffic and launching wireless attacks. It … | 23 | 1240 | maintenance |
| Zerx0r/Kage Kage is an Electron-based graphical user interface for the Metasploit Framework's RPC server, allowing users to manage meterpreter sessions… | 10 | 1235 | maintenance |
| mrknow001/aliyun-accesskey-Tools A Python tool for exploiting leaked Alibaba Cloud (Aliyun) AccessKeys: it enumerates ECS hosts associated with a key and enables remote com… | 23 | 1232 | maintenance |
| dark-player/instabrute.github.io IG-HACK is a bash-based brute-force script that attempts to crack Instagram account passwords using wordlist attacks, designed to run in Te… | 38 | 1227 | maintenance |
| dagrz/aws_pwn A collection of Python scripts for penetration testing AWS environments, covering reconnaissance, exploitation, stealth, exploration, and p… | 32 | 1223 | maintenance |
| hacktoolspack/hack-tools A curated collection of free hacking and cybersecurity tools covering DoS, information gathering, malware/ransomware generation, and remote… | 23 | 1218 | maintenance |
| nccgroup/redsnarf RedSnarf is a pen-testing/red-teaming tool for retrieving hashes and credentials from Windows workstations, servers, and domain controllers… | 32 | 1216 | maintenance |
| elkokc/reflector Reflector is a Burp Suite extension written in Java that detects reflected XSS vulnerabilities in real time while browsing a target web app… | 23 | 1214 | maintenance |
| Viralmaniar/Powershell-RAT A Python-based remote access trojan (RAT) for red team engagements that backdoors Windows machines via scheduled tasks and exfiltrates scre… | 23 | 1207 | maintenance |
| LiNuX-Mallu/CAM-DUMPER CAM-DUMPER is a shell-based security testing tool that generates a malicious HTTPS page served via Serveo or Ngrok port forwarding to captu… | 32 | 1203 | maintenance |
| fofapro/Hosts_scan A small Python tool that brute-force matches IP addresses against domain names by binding Hosts headers, to discover weak or internal syste… | 32 | 1197 | maintenance |
| l3m0n/Bypass_Disable_functions_Shell A PHP webshell that collects various techniques for bypassing PHP's disable_functions restriction to achieve command execution, including L… | 32 | 1193 | maintenance |
| OWASP/joomscan OWASP JoomScan is an open-source Perl-based vulnerability scanner for Joomla CMS deployments. It enumerates versions, components, and known… | 23 | 1192 | maintenance |
| AlexisAhmed/BugBountyToolkit A multi-platform bug bounty toolkit that bundles popular security and reconnaissance tools (Nmap, Amass, sqlmap, ffuf, etc.) into a pre-con… | 32 | 1189 | maintenance |
| DanMcInerney/icebreaker A PowerShell-based penetration testing tool that automates five internal network attacks against Active Directory to obtain plaintext crede… | 32 | 1185 | maintenance |
| Ekultek/BlueKeep A Python proof-of-concept exploit for CVE-2019-0708 (BlueKeep), a pre-authentication remote code execution vulnerability in Microsoft RDP a… | 65 | 1183 | maintenance |
| timwhitez/crawlergo_x_XRAY A Python glue script that combines the crawlergo dynamic crawler with the XRAY passive vulnerability scanner, replaying crawled URLs throug… | 32 | 1182 | maintenance |
| BuffaloWill/oxml_xxe A Ruby/Sinatra web tool for embedding XXE/XML exploits into document file formats like DOCX, XLSX, ODT, SVG, and XML. It is used to test XX… | 32 | 1178 | maintenance |
| antonioCoco/RoguePotato RoguePotato is a Windows local privilege escalation tool written in C that elevates from a service account to SYSTEM by abusing the DCOM/NT… | 23 | 1177 | maintenance |
| mttaggart/OffensiveNotion OffensiveNotion is a command-and-control (C2) platform that abuses the Notion notetaking app as its communication channel. It ships a cross… | 10 | 1177 | maintenance |
| dionach/CMSmap CMSmap is a Python open-source CLI scanner that automates detection of security flaws in popular CMSs, integrating common vulnerabilities f… | 32 | 1176 | maintenance |
| CCob/SharpBlock SharpBlock is a C# command-line tool that blocks EDR (Endpoint Detection and Response) protection DLLs from executing their entry points in… | 32 | 1171 | maintenance |
| yangyangwithgnu/bypass_disablefunc_via_LD_PRELOAD A small PHP exploit script plus compiled shared object that bypasses PHP's disable_functions restriction to execute OS commands via LD_PREL… | 32 | 1171 | maintenance |
| DarkCoderSc/win-brute-logon A Windows command-line proof-of-concept tool that brute-forces local user account passwords without requiring any privileges, exploiting th… | 32 | 1170 | maintenance |
| n0b0dyCN/redis-rogue-server A Python-driven exploit tool that achieves remote code execution on unpatched Redis servers (<=5.0.5) by loading a malicious Redis module f… | 32 | 1170 | maintenance |
| 4w4k3/BeeLogger BeeLogger is a Python-based penetration testing tool that generates Windows keylogger executables which exfiltrate captured keystrokes via … | 32 | 1169 | maintenance |
| sh4hin/Androl4b AndroL4b is an Ubuntu MATE-based virtual machine preloaded with Android security, reverse engineering, and malware analysis tools such as R… | 32 | 1166 | maintenance |
| Ch0pin/AVIator AV|Ator is a GUI backdoor generator that encrypts shellcode with AES and produces Windows executables that decrypt and inject the payload u… | 10 | 1161 | maintenance |
| Lucifer1993/TPscan TPscan is a one-click vulnerability detection tool for ThinkPHP applications, written in Python 3. It scans ThinkPHP-based web services for… | 32 | 1159 | maintenance |
| d3ckx1/Fvuln Fvuln (Find-Vulnerability) is an automated security scanning tool for penetration testers and red teams. It combines live IP detection, por… | 23 | 1157 | maintenance |
| deepzec/Bad-Pdf Bad-PDF is a Python tool that generates malicious PDF files exploiting CVE-2018-4993 to steal NTLMv1/NTLMv2 hashes from Windows machines vi… | 44 | 1151 | maintenance |
| Telefonica/Eternalblue-Doublepulsar-Metasploit A Metasploit module that exploits the EternalBlue/DoublePulsar SMB vulnerability in Windows systems. It integrates the leaked NSA exploit i… | 32 | 1151 | maintenance |
| threatexpress/red-team-scripts A collection of red team focused tools, PowerShell scripts, and notes for offensive security engagements, including host and domain enumera… | 32 | 1146 | maintenance |
| ChrisTheCoolHut/Zeratool Zeratool is an Automatic Exploit Generation (AEG) tool that uses angr to concolically analyze binaries for buffer overflow and format strin… | 23 | 1144 | maintenance |
| christophetd/log4shell-vulnerable-app A deliberately vulnerable Spring Boot web application demonstrating the Log4Shell vulnerability (CVE-2021-44228) using Log4j 2.14.1. It shi… | 32 | 1140 | maintenance |
| chvancooten/follina.py A proof-of-concept Python script that replicates the 'Follina' MS-MSDT Microsoft Office remote code execution vulnerability for local testi… | 32 | 1139 | maintenance |
| nccgroup/featherduster FeatherDuster is an automated, modular cryptanalysis tool from NCC Group that identifies and exploits weak cryptosystems from supplied ciph… | 23 | 1137 | maintenance |
| Bhaviktutorials/shark Shark is a shell-based phishing toolkit that automates hosting fake login pages with port forwarding via ngrok and Cloudflare tunnels. It i… | 23 | 1137 | maintenance |
| stephenbradshaw/vulnserver Vulnserver is a deliberately vulnerable multithreaded Windows TCP server containing multiple subtly different buffer overflow bugs. It is d… | 32 | 1133 | maintenance |