Ross ROSS = Recommend OSS · open-source software intelligence for agents

function: penetration-testing

859 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
matterpreter/OffensiveCSharp
A collection of standalone C# tools and proof-of-concept programs for offensive security operations, each compiled individually in Visual S…
321473maintenance
antonioCoco/RemotePotato0
RemotePotato0 is a Windows privilege escalation exploit that abuses the DCOM activation service to trigger NTLM authentication from privile…
231469maintenance
rootclay/WMIHACKER
WMIHACKER is a VBScript-based command-line tool for lateral movement on Windows hosts via WMI (port 135), avoiding the commonly detected 44…
331465maintenance
nccgroup/house
House is a runtime mobile application analysis toolkit with a web GUI, powered by Frida and written in Python. It simplifies dynamic functi…
321463maintenance
woodpecker-framework/woodpecker-framework-release
Woodpecker-framework is a Java-based vulnerability detection and deep exploitation framework focused on precisely targeting high-risk vulne…
231463maintenance
ptswarm/reFlutter
A Python-based framework that repacks Flutter Android and iOS apps with a patched Flutter engine library to enable dynamic analysis. It red…
101463maintenance
SySS-Research/Seth
Seth is a Python and Bash proof-of-concept tool that performs a man-in-the-middle attack on RDP connections via ARP spoofing, downgrading t…
561454maintenance
oddcod3/Phantom-Evasion
Phantom-Evasion is a Python-based antivirus evasion tool that generates obfuscated executables and payloads designed to bypass antivirus de…
101449maintenance
SamJoan/droopescan
Droopescan is a plugin-based command-line scanner that helps security researchers identify the CMS, version, plugins, themes, and interesti…
321445maintenance
jweny/pocassist
Pocassist is an open-source vulnerability PoC testing framework written in Go that lets users edit, run, and batch-test PoCs through a web …
101436maintenance
FunnyWolf/pystinger
Pystinger is a Python tool that establishes a SOCKS4a proxy and port mapping through a webshell (PHP, JSP, or ASPX) on a compromised server…
231427maintenance
ptoomey3/Keychain-Dumper
A command-line tool for jailbroken iOS devices that dumps Keychain items (passwords, certificates, identities) accessible to an attacker. I…
231419maintenance
Mr-Un1k0d3r/DKMC
DKMC (Don't Kill My Cat) is a Python CLI tool that embeds obfuscated shellcode inside valid BMP images, producing polyglot files that are b…
101418maintenance
cube0x0/noPac
A C# tool that scans for and exploits the CVE-2021-42287/CVE-2021-42278 Active Directory vulnerability chain, allowing a standard domain us…
321412maintenance
m4ll0k/Atlas
Atlas is a Python CLI tool that suggests SQLMap tamper scripts to bypass WAF/IDS/IPS protections during SQL injection testing. It works by …
321411maintenance
CiscoCXSecurity/enum4linux
enum4Linux is a Perl-based CLI tool that enumerates information from Windows and Samba hosts, serving as a Linux alternative to enum.exe. I…
711407maintenance
c0ny1/FastjsonExploit
A Java CLI framework for quickly exploiting Fast deserialization vulnerabilities. It generates exploit payloads with one command and bundle…
321406maintenance
hakluke/weaponised-XSS-payloads
A collection of weaponised XSS payloads - JavaScript files that perform sensitive actions (like creating admin users) on popular CMS platfo…
321404maintenance
maK-/parameth
parameth is a Python command-line tool that brute-forces GET and POST parameter names on web endpoints by comparing response differences. I…
101396maintenance
649/Memcrashed-DDoS-Exploit
A Python CLI exploit tool that finds exposed Memcached servers via the Shodan API and sends forged UDP packets to them to amplify DDoS atta…
321394maintenance
BastilleResearch/mousejack
A collection of device discovery and research tools for the MouseJack vulnerabilities affecting wireless mice and keyboards using nRF24LU1+…
321386maintenance
importCTF/Instagram-Hacker
A Python command-line script that performs brute-force password attacks against Instagram accounts, using mechanize and requests with optio…
321384maintenance
3ndG4me/AutoBlue-MS17-010
A semi-automated, standalone Python exploit for the MS17-010 (EternalBlue) SMB vulnerability that generates kernel shellcode and handles li…
321382maintenance
lijiejie/swagger-exp
A Python-based Swagger REST API information disclosure exploitation tool. It enumerates API endpoints, auto-fills parameters, tests for una…
321381maintenance
screetsec/Dracnmap
Dracnmap is a shell-based menu tool that wraps nmap to simplify network scanning and information gathering. It exposes nmap's advanced scri…
231380maintenance
bitsadmin/fakelogonscreen
FakeLogonScreen is a red-team utility that displays a fake Windows logon screen to capture a user's password, validating it against Active …
231378maintenance
Katana
Katana is a Python CLI tool by John Hammond that automates common low-hanging-fruit checks for CTF challenges, paired with ctf-katana, a cu…
321363maintenance
danigargu/CVE-2020-0796
A proof-of-concept exploit for CVE-2020-0796 (SMBGhost), a local privilege escalation vulnerability in Windows 10's SMBv3 client driver. Wr…
231359maintenance
ReversecLabs/SharpGPOAbuse
SharpGPOAbuse is a C# .NET command-line tool that abuses a user's edit rights on a Group Policy Object to compromise objects controlled by …
321353maintenance
jeffzh3ng/fuxi
Fuxi is a self-hosted penetration testing platform written in Python that provides a web interface for organizing and running security asse…
321346maintenance
LittleBear4/OA-EXPTOOL
A Python-based exploitation framework targeting Chinese OA (Office Automation) systems, bundling nearly 20 batch vulnerability scanners for…
231345maintenance
OmerYa/Invisi-Shell
Invisi-Shell is a proof-of-concept tool that bypasses PowerShell security features (ScriptBlock logging, Module logging, Transcription, AMS…
321339maintenance
pwnesia/ssb
SSB (Secure Shell Bruteforcer) is a fast, concurrent SSH password brute-forcing tool written in Go. It attempts to authenticate against an …
231335maintenance
Arvanaghi/SessionGopher
SessionGopher is a PowerShell tool that extracts and decrypts saved session information for remote access tools like WinSCP, PuTTY, SuperPu…
321334maintenance
GhostPack/SafetyKatz
SafetyKatz is a C# tool that combines a modified Mimikatz with a .NET PE loader to dump LSASS memory and extract credentials. It minidumps …
321332maintenance
infobyte/evilgrade
Evilgrade is a modular penetration testing framework that exploits poor software update implementations by injecting fake updates via DNS m…
231326maintenance
stampery/mongoaudit
mongoaudit is a Python CLI tool that audits MongoDB servers for poor security configurations, known vulnerabilities, and misconfigurations.…
231324maintenance
dirkjanm/CVE-2020-1472
A proof-of-concept exploit for CVE-2020-1472 (Zerologon), a critical Netlogon privilege escalation vulnerability in Windows domain controll…
321320maintenance
TermuxHackz/wifi-hacker
A shell script that automates attacking wireless connections using built-in Kali Linux tools, supporting WEP, WPS, WPA, and WPA2 securities…
321319maintenance
redhuntlabs/RedHunt-OS
RedHunt OS is a pre-configured Linux virtual machine (OVA) bundling adversary emulation and threat hunting tools such as Caldera, Atomic Re…
331318maintenance
vanhoefm/fragattacks
A security testing tool that tests Wi-Fi clients and access points for the FragAttacks fragmentation and aggregation vulnerabilities affect…
411311maintenance
k8gege/K8CScan
K8CScan is a high-concurrency, plugin-based scanner designed for large internal network penetration testing. It bundles information gatheri…
321303maintenance
Viralmaniar/Passhunt
Passhunt is a Python-based command-line tool for searching default credentials across 523 vendors and 2084 default passwords for network de…
231303maintenance
Vu1nT0tal/IoT-vulhub
A collection of Docker-based environments for reproducing IoT firmware vulnerabilities, inspired by the Vulhub project. It uses binwalk for…
231294maintenance
kinghacker0/WishFish
WishFish is a bash-based security testing tool that generates phishing-style links (wishing or custom pages) which, when opened by a target…
321290maintenance
med0x2e/SigFlip
SigFlip is a red-team tool for patching Authenticode-signed PE files (exe, dll, sys) without invalidating their existing signatures, by emb…
321290maintenance
smxiazi/xia_sql
A Burp Suite extension (written in Java) that appends single and double quotes to every request parameter to detect possible SQL injection,…
231286maintenance
entropy1337/infernal-twin
Infernal-Wireless is an automated wireless hacking framework written in Python that aids penetration testers in assessing Wi-Fi security. I…
231285maintenance
hangetzzu/saycheese
SayCheese is a shell-based social engineering tool that generates a malicious HTTPS page to capture webcam photos from a target who clicks …
321284maintenance
c0ny1/upload-fuzz-dic-builder
A Python CLI script that generates fuzzing dictionaries for testing file upload vulnerabilities. It tailors wordlists based on target detai…
321279maintenance
yzddmr6/webshell-venom
A tool that generates unlimited polymorphic (AV-evading) webshells for penetration testing. It mutates webshell code to bypass antivirus an…
101278maintenance
netxfly/x-crack
x-crack is a command-line weak password (credential brute-force) scanner written in Go that tests common username/password combinations aga…
231276maintenance
screetsec/Brutal
Brutal is a Linux toolkit for generating HID attack payloads for Teensy boards, similar to a Rubber Ducky but with different syntax. It cre…
321270maintenance
UzJu/Cloud-Bucket-Leak-Detection-Tools
A Python CLI tool that detects misconfigured and leaked cloud storage buckets across six major cloud providers including Aliyun, Tencent Cl…
291266maintenance
lintstar/LSTAR
LSTAR is a comprehensive Cobalt Strike post-exploitation Aggressor plugin written in PowerShell and CNA. It consolidates host information g…
231266maintenance
shack2/SuperSQLInjectionV1
SuperSQLInjection (SSQLInjection) is a C#-based GUI SQL injection tool that builds raw HTTP requests over TCP sessions, supporting injectio…
231266maintenance
Cybellum/DoubleAgent
DoubleAgent is a research tool and proof-of-concept demonstrating a zero-day code injection and persistence technique on Windows, exploitin…
321262maintenance
pmiaowu/BurpFastJsonScan
A passive BurpSuite extension written in Java that detects FastJson deserialization vulnerabilities in JSON-bearing HTTP requests. It autom…
231251maintenance
W01fh4cker/Serein
Serein is a graphical Python tool for batch-collecting URLs via the FOFA search engine API and running batch detection/exploitation of know…
101250maintenance
m4n3dw0lf/pythem
pythem is a multi-purpose penetration testing framework written in Python 2.7, providing an interactive CLI for security researchers. It bu…
321248maintenance
AbirHasan2005/ShellPhish
A modified (modded) version of the ShellPhish phishing simulation tool that generates fake login pages for popular websites like Facebook, …
321241maintenance
Tylous/SniffAir
SniffAir is an open-source wireless security framework for parsing passively collected wireless traffic and launching wireless attacks. It …
231240maintenance
Zerx0r/Kage
Kage is an Electron-based graphical user interface for the Metasploit Framework's RPC server, allowing users to manage meterpreter sessions…
101235maintenance
mrknow001/aliyun-accesskey-Tools
A Python tool for exploiting leaked Alibaba Cloud (Aliyun) AccessKeys: it enumerates ECS hosts associated with a key and enables remote com…
231232maintenance
dark-player/instabrute.github.io
IG-HACK is a bash-based brute-force script that attempts to crack Instagram account passwords using wordlist attacks, designed to run in Te…
381227maintenance
dagrz/aws_pwn
A collection of Python scripts for penetration testing AWS environments, covering reconnaissance, exploitation, stealth, exploration, and p…
321223maintenance
hacktoolspack/hack-tools
A curated collection of free hacking and cybersecurity tools covering DoS, information gathering, malware/ransomware generation, and remote…
231218maintenance
nccgroup/redsnarf
RedSnarf is a pen-testing/red-teaming tool for retrieving hashes and credentials from Windows workstations, servers, and domain controllers…
321216maintenance
elkokc/reflector
Reflector is a Burp Suite extension written in Java that detects reflected XSS vulnerabilities in real time while browsing a target web app…
231214maintenance
Viralmaniar/Powershell-RAT
A Python-based remote access trojan (RAT) for red team engagements that backdoors Windows machines via scheduled tasks and exfiltrates scre…
231207maintenance
LiNuX-Mallu/CAM-DUMPER
CAM-DUMPER is a shell-based security testing tool that generates a malicious HTTPS page served via Serveo or Ngrok port forwarding to captu…
321203maintenance
fofapro/Hosts_scan
A small Python tool that brute-force matches IP addresses against domain names by binding Hosts headers, to discover weak or internal syste…
321197maintenance
l3m0n/Bypass_Disable_functions_Shell
A PHP webshell that collects various techniques for bypassing PHP's disable_functions restriction to achieve command execution, including L…
321193maintenance
OWASP/joomscan
OWASP JoomScan is an open-source Perl-based vulnerability scanner for Joomla CMS deployments. It enumerates versions, components, and known…
231192maintenance
AlexisAhmed/BugBountyToolkit
A multi-platform bug bounty toolkit that bundles popular security and reconnaissance tools (Nmap, Amass, sqlmap, ffuf, etc.) into a pre-con…
321189maintenance
DanMcInerney/icebreaker
A PowerShell-based penetration testing tool that automates five internal network attacks against Active Directory to obtain plaintext crede…
321185maintenance
Ekultek/BlueKeep
A Python proof-of-concept exploit for CVE-2019-0708 (BlueKeep), a pre-authentication remote code execution vulnerability in Microsoft RDP a…
651183maintenance
timwhitez/crawlergo_x_XRAY
A Python glue script that combines the crawlergo dynamic crawler with the XRAY passive vulnerability scanner, replaying crawled URLs throug…
321182maintenance
BuffaloWill/oxml_xxe
A Ruby/Sinatra web tool for embedding XXE/XML exploits into document file formats like DOCX, XLSX, ODT, SVG, and XML. It is used to test XX…
321178maintenance
antonioCoco/RoguePotato
RoguePotato is a Windows local privilege escalation tool written in C that elevates from a service account to SYSTEM by abusing the DCOM/NT…
231177maintenance
mttaggart/OffensiveNotion
OffensiveNotion is a command-and-control (C2) platform that abuses the Notion notetaking app as its communication channel. It ships a cross…
101177maintenance
dionach/CMSmap
CMSmap is a Python open-source CLI scanner that automates detection of security flaws in popular CMSs, integrating common vulnerabilities f…
321176maintenance
CCob/SharpBlock
SharpBlock is a C# command-line tool that blocks EDR (Endpoint Detection and Response) protection DLLs from executing their entry points in…
321171maintenance
yangyangwithgnu/bypass_disablefunc_via_LD_PRELOAD
A small PHP exploit script plus compiled shared object that bypasses PHP's disable_functions restriction to execute OS commands via LD_PREL…
321171maintenance
DarkCoderSc/win-brute-logon
A Windows command-line proof-of-concept tool that brute-forces local user account passwords without requiring any privileges, exploiting th…
321170maintenance
n0b0dyCN/redis-rogue-server
A Python-driven exploit tool that achieves remote code execution on unpatched Redis servers (<=5.0.5) by loading a malicious Redis module f…
321170maintenance
4w4k3/BeeLogger
BeeLogger is a Python-based penetration testing tool that generates Windows keylogger executables which exfiltrate captured keystrokes via …
321169maintenance
sh4hin/Androl4b
AndroL4b is an Ubuntu MATE-based virtual machine preloaded with Android security, reverse engineering, and malware analysis tools such as R…
321166maintenance
Ch0pin/AVIator
AV|Ator is a GUI backdoor generator that encrypts shellcode with AES and produces Windows executables that decrypt and inject the payload u…
101161maintenance
Lucifer1993/TPscan
TPscan is a one-click vulnerability detection tool for ThinkPHP applications, written in Python 3. It scans ThinkPHP-based web services for…
321159maintenance
d3ckx1/Fvuln
Fvuln (Find-Vulnerability) is an automated security scanning tool for penetration testers and red teams. It combines live IP detection, por…
231157maintenance
deepzec/Bad-Pdf
Bad-PDF is a Python tool that generates malicious PDF files exploiting CVE-2018-4993 to steal NTLMv1/NTLMv2 hashes from Windows machines vi…
441151maintenance
Telefonica/Eternalblue-Doublepulsar-Metasploit
A Metasploit module that exploits the EternalBlue/DoublePulsar SMB vulnerability in Windows systems. It integrates the leaked NSA exploit i…
321151maintenance
threatexpress/red-team-scripts
A collection of red team focused tools, PowerShell scripts, and notes for offensive security engagements, including host and domain enumera…
321146maintenance
ChrisTheCoolHut/Zeratool
Zeratool is an Automatic Exploit Generation (AEG) tool that uses angr to concolically analyze binaries for buffer overflow and format strin…
231144maintenance
christophetd/log4shell-vulnerable-app
A deliberately vulnerable Spring Boot web application demonstrating the Log4Shell vulnerability (CVE-2021-44228) using Log4j 2.14.1. It shi…
321140maintenance
chvancooten/follina.py
A proof-of-concept Python script that replicates the 'Follina' MS-MSDT Microsoft Office remote code execution vulnerability for local testi…
321139maintenance
nccgroup/featherduster
FeatherDuster is an automated, modular cryptanalysis tool from NCC Group that identifies and exploits weak cryptosystems from supplied ciph…
231137maintenance
Bhaviktutorials/shark
Shark is a shell-based phishing toolkit that automates hosting fake login pages with port forwarding via ngrok and Cloudflare tunnels. It i…
231137maintenance
stephenbradshaw/vulnserver
Vulnserver is a deliberately vulnerable multithreaded Windows TCP server containing multiple subtly different buffer overflow bugs. It is d…
321133maintenance

← prev page 7 / 9 next →