function: penetration-testing
859 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| shr3ddersec/Shr3dKit Shr3dKit is a shell script that installs a large curated collection of red team and offensive security tools onto a Kali Linux system (hard… | 32 | 1131 | maintenance |
| hausec/ADAPE-Script A PowerShell script that automates Active Directory assessment and privilege escalation checks by bundling multiple well-known pentest modu… | 32 | 1125 | maintenance |
| GreatSCT/GreatSCT GreatSCT is a Python-based framework that generates metasploit payloads designed to bypass antivirus and application whitelisting solutions… | 10 | 1123 | maintenance |
| 1n7erface/Template Template is a heuristic intranet scanning CLI tool built for red team operations, combining host discovery, port scanning, web fingerprinti… | 23 | 1121 | maintenance |
| JoelGMSec/AutoRDPwn AutoRDPwn is a PowerShell post-exploitation framework that automates the RDP Shadow attack on Windows, letting an attacker view or control … | 32 | 1118 | maintenance |
| hash3liZer/WiFiBroot WiFiBroot is a Python 2 command-line tool for wireless (WPA/WPA2) penetration testing that captures and cracks 4-way handshakes and PMKID k… | 23 | 1114 | maintenance |
| wireghoul/dotdotpwn DotDotPwn is a flexible directory traversal fuzzer written in Perl that discovers path traversal vulnerabilities in HTTP, FTP, and TFTP ser… | 23 | 1114 | maintenance |
| awake1t/PortBrute A compact cross-platform brute-force tool written in Go that attempts password attacks against FTP, SSH, SMB, MSSQL, MySQL, PostgreSQL, and… | 32 | 1111 | maintenance |
| prateek147/DVIA-v2 Damn Vulnerable iOS App (DVIA-v2) is a deliberately vulnerable iOS application written in Swift for practicing iOS penetration testing. It … | 23 | 1111 | maintenance |
| calebstewart/CVE-2021-1675 A pure PowerShell proof-of-concept exploit for CVE-2021-1675 (PrintNightmare), a Windows Print Spooler local privilege escalation vulnerabi… | 32 | 1109 | maintenance |
| tevora-threat/SharpView SharpView is a C#/.NET port of the PowerView PowerShell script for Active Directory domain enumeration and reconnaissance. It exposes Power… | 32 | 1108 | maintenance |
| curi0usJack/luckystrike LuckyStrike is a PowerShell-based utility for generating malicious Microsoft Office macro documents, intended for penetration testing and e… | 10 | 1108 | maintenance |
| dark-lbp/isf ISF (Industrial Exploitation Framework) is a Python-based exploitation framework modeled after Metasploit, focused on industrial control sy… | 10 | 1105 | maintenance |
| endgameinc/RTA Red Team Automation (RTA) is a Python framework of scripts that emulate malicious tradecraft modeled after the MITRE ATT&CK matrix, letting… | 32 | 1095 | maintenance |
| M4sc3r4n0/Evil-Droid Evil-Droid is a shell-based framework that creates, generates, and embeds APK payloads for penetrating Android platforms, built on top of t… | 23 | 1094 | maintenance |
| JackOfMostTrades/gadgetinspector A Java bytecode analyzer that automatically discovers deserialization gadget chains in Java libraries and application classpaths. It produc… | 32 | 1090 | maintenance |
| Accenture/Spartacus Spartacus is a Windows toolkit that automates discovery and exploitation of DLL and COM hijacking vulnerabilities by parsing Process Monito… | 10 | 1085 | maintenance |
| pentestmonkey/unix-privesc-check A single shell script that audits Unix systems for misconfigurations allowing local privilege escalation. It can be uploaded and run direct… | 32 | 1082 | maintenance |
| dirkjanm/PrivExchange PrivExchange is a set of Python proof-of-concept tools that abuse Exchange Web Services push notifications to relay authentication and esca… | 32 | 1077 | maintenance |
| wireghoul/htshells A collection of self-contained .htaccess files that turn Apache servers into web shells or launch various attacks when uploaded. It include… | 32 | 1076 | maintenance |
| admintony/Prepare-for-AWD A collection of Python and PHP scripts for AWD (Attack with Defense) CTF competitions, including batch attack scripts for planting and trig… | 32 | 1075 | maintenance |
| antonioCoco/SharPyShell SharPyShell is a Python tool that generates a tiny, obfuscated ASP.NET webshell for C# web applications on .NET Framework and provides an i… | 23 | 1072 | maintenance |
| c0ny1/jsEncrypter A Burp Suite extension that uses PhantomJS to invoke front-end JavaScript encryption functions on payloads, enabling fuzzing and brute-forc… | 23 | 1069 | maintenance |
| ZHacker13/ReverseTCPShell A PowerShell-based ReverseTCP shell framework that provides a command-and-control (C2) server with modules for remote host information gath… | 32 | 1067 | maintenance |
| safebuffer/sam-the-admin A Python CLI exploit tool that chains CVE-2021-42278 and CVE-2021-42287 to impersonate a Domain Admin from a standard Active Directory doma… | 32 | 1067 | maintenance |
| 0xbadjuju/Tokenvator Tokenvator is a C# command-line tool for manipulating Windows tokens to elevate privileges, such as stealing a SYSTEM token from a running … | 23 | 1067 | maintenance |
| raddyfiy/caidao-official-version An archive of the official versions of 'China Chopper' (中国菜刀), a well-known webshell management client, with archived download snapshots an… | 23 | 1063 | maintenance |
| AHXR/ghost Ghost is a lightweight Remote Access Trojan (RAT) written in C++ that gives an attacker silent remote command-line access to Windows machin… | 23 | 1058 | maintenance |
| Abacus-Group-RTO/legion Legion is an open-source, semi-automated network penetration testing framework with a graphical interface, forked from Sparta. It orchestra… | 10 | 1057 | maintenance |
| rastating/wordpress-exploit-framework A Ruby framework for penetration testing WordPress installations, providing a console with loadable exploit and payload modules. It is dist… | 10 | 1046 | maintenance |
| OffensivePython/Saddam Saddam is a Python command-line tool that performs DDoS amplification attacks using DNS, NTP, SNMP, and SSDP reflection vectors. It can als… | 32 | 1045 | maintenance |
| thomasxm/BOAZ_beta BOAZ is a multilayered AV/EDR evasion framework written in C++/C with Python linking, designed to generate polymorphic payloads that bypass… | 57 | 1042 | maintenance |
| TryCatchHCF/DumpsterFire DumpsterFire is a modular, menu-driven, cross-platform Python toolset for building repeatable, time-delayed, distributed security events. I… | 23 | 1039 | maintenance |
| adi0x90/attifyos Attify OS is a Linux distribution based on Ubuntu 18.04 pre-configured with tools for security assessment and penetration testing of IoT de… | 32 | 1037 | maintenance |
| averagesecurityguy/scripts A collection of Python scripts written for use during penetration testing engagements, organized into categories like brute forcing, enumer… | 32 | 1033 | maintenance |
| blasty/CVE-2021-3156 A proof-of-concept exploit for CVE-2021-3156 (Baron Samedit), a heap-based buffer overflow in sudo. It is a C command-line tool that escala… | 32 | 1022 | maintenance |
| Ridter/noPac A Python CLI exploit tool that chains CVE-2021-42278 and CVE-2021-42287 to escalate from a standard Active Directory domain user to Domain … | 32 | 1021 | maintenance |
| b4rtik/SharpKatz SharpKatz is a C# port of mimikatz's credential extraction commands, including sekurlsa::logonpasswords, sekurlsa::ekeys, and lsadump::dcsy… | 32 | 1021 | maintenance |
| mdsecactivebreach/CACTUSTORCH CACTUSTORCH is a payload generation tool that produces JavaScript, VBScript, and VBA shellcode launchers for adversary simulations. It spaw… | 32 | 1017 | maintenance |
| quentinhardy/msdat MSDAT is an open-source Python penetration testing tool for remotely testing the security of Microsoft SQL Server databases. It supports cr… | 32 | 1016 | maintenance |
| secretsquirrel/BDFProxy BDFProxy is a man-in-the-middle proxy that patches downloaded binaries on the fly by embedding payloads, combining the Backdoor Factory wit… | 32 | 1015 | maintenance |
| b3-v3r/Hunner Hunner is a Python-based hacking framework for penetration testing that combines vulnerability scanning (SQL injection, XSS), denial-of-sit… | 32 | 1012 | maintenance |
| feihong-cs/Java-Rce-Echo A collection of Java test code for achieving command output echo after remote code execution (RCE) across common application servers and pl… | 32 | 1008 | maintenance |
| hackerxphantom/HACK-CAMERA A Bash-based penetration-testing tool that hosts a phishing page which requests camera access and captures webcam shots from targets who op… | 23 | 1008 | maintenance |
| stormshadow07/HackTheWorld A Python CLI script that generates Windows payloads designed to evade antivirus detection, integrating with Metasploit and mingw-w64 for co… | 32 | 1005 | maintenance |
| maaaaz/thc-hydra-windows A Windows-compiled distribution of THC-HYDRA, the popular network login brute-forcing tool, bundled with Cygwin DLLs and optional SSH, MySQ… | 23 | 1004 | maintenance |
| Armur-Ai/Pentest-Swarm-AI An open-source autonomous penetration testing application that orchestrates a swarm of AI agents (recon, classification, exploitation, repo… | 75 | 2381 | experimental |
| m4ll0k/BBTz A collection of bug bounty tools and example scripts written in Python by security researcher m4ll0k. It serves as a set of ideas and refer… | 32 | 1909 | experimental |
| MSNightmare/RoguePlanet RoguePlanet is a proof-of-concept exploit for a Windows Defender vulnerability written in C++. It uses a race condition (triggered via ISO … | 52 | 1618 | experimental |
| TarlogicSecurity/BlueSpy BlueSpy is a Python proof-of-concept tool that records and replays audio from vulnerable Bluetooth devices by exploiting pairing without us… | 61 | 1612 | experimental |
| faizann24/wifi-bruteforcer-fsecurify An Android application that attempts to brute force WiFi passwords without requiring a rooted device. It is written in Java and distributed… | 32 | 1486 | experimental |
| achuna33/MYExploit MYExploit is a Java-based one-click scanning and exploitation tool targeting OA (office automation) enterprise products, built as an extens… | 23 | 1485 | experimental |
| chompie1337/SMBGhost_RCE_PoC A Python proof-of-concept exploit for CVE-2020-0796 (SMBGhost), achieving pre-authentication remote code execution against vulnerable Windo… | 32 | 1395 | experimental |
| blackhillsinfosec/WifiForge WifiForge is a Python-based training framework from Black Hills InfoSec that simulates Wi-Fi networks using mininet-wifi so pentesters can … | 70 | 1184 | experimental |
| berylliumsec/nebula Nebula is an AI-powered penetration testing desktop application that combines a terminal, browser, notes, findings, and reporting into one … | 92 | 1097 | experimental |
| koutto/jok3r Jok3r is a Python3 CLI framework that automates network and web black-box penetration testing by chaining 50+ open-source security tools. I… | 32 | 1087 | experimental |
| ZeroMemoryEx/Terminator Terminator is a C++ proof-of-concept tool that terminates EDR/XDR/antivirus processes on Windows by abusing the vulnerable, signed zam64.sy… | 20 | 1061 | experimental |
| hackerxphantom/Facebook_hack A Python command-line tool that performs brute-force password attacks against Facebook accounts using an email or profile ID as the target,… | 10 | 1038 | experimental |
| fikrado/fikrado.py A Python 2.7 command-line script that attempts to gain access to Facebook accounts via the Facebook API using brute-force techniques. It ta… | 23 | 1035 | experimental |
| PowerShellMafia/PowerSploit PowerSploit is a collection of PowerShell modules for post-exploitation tasks during penetration tests, covering code execution, persistenc… | 10 | 13085 | abandoned |
| aliasrobotics/cai Cybersecurity AI (CAI) is an open-source Python framework of specialized AI agents for offensive security tasks such as penetration testing… | 10 | 9810 | abandoned |
| byt3bl33d3r/CrackMapExec CrackMapExec is a Python-based command-line swiss army knife for pentesting Windows and Active Directory networks, supporting protocols lik… | 10 | 9159 | abandoned |
| EmpireProject/Empire Empire is a post-exploitation framework with a pure PowerShell Windows agent and a pure Python Linux/OS X agent, offering encrypted communi… | 10 | 7863 | abandoned |
| aquasecurity/kube-hunter kube-hunter is a Python-based tool that hunts for security weaknesses and vulnerabilities in Kubernetes clusters, running remotely, on a ma… | 23 | 5078 | abandoned |
| unCaptcha unCaptcha2 is a Python-based security research tool that defeats Google's ReCaptcha v2 audio challenges by submitting the audio to free spe… | 32 | 4917 | abandoned |
| zhzyker/exphub Exphub is a collection of standalone Python, Java, PHP, and shell exploit scripts for known CVE vulnerabilities in products like Weblogic, … | 32 | 4291 | abandoned |
| Arachni/arachni Arachni is a modular, high-performance Ruby framework for scanning web applications for security vulnerabilities, including XSS and SQL inj… | 10 | 4039 | abandoned |
| offensive-security/kali-nethunter Kali NetHunter is an Android ROM overlay providing a mobile penetration testing platform, combining a custom kernel, a Kali Linux chroot, a… | 10 | 3806 | abandoned |
| cSploit/android cSploit is an open-source Android network analysis and penetration testing suite for rooted devices, integrating Metasploit RPC, MITM attac… | 23 | 3648 | abandoned |
| NewEraCracker/LOIC LOIC (Low Orbit Ion Cannon) is an open-source network stress testing tool written in C#, based on Praetox's original LOIC. It supports TCP/… | 10 | 2967 | abandoned |
| optiv/ScareCrow ScareCrow is a Go-based payload creation framework designed to bypass EDR (Endpoint Detection and Response) and application whitelisting co… | 10 | 2890 | abandoned |
| DanMcInerney/LANs.py A Python-based penetration testing tool that scans WiFi networks for active clients, performs targeted ARP spoofing, and intercepts or inje… | 32 | 2630 | abandoned |
| evilsocket/bettercap bettercap is a network attack and reconnaissance framework, described as a Swiss Army knife for WiFi, BLE, HID hijacking, CAN-bus, and IPv4… | 10 | 2490 | abandoned |
| Marten4n6/EvilOSX EvilOSX is a Remote Administration Tool (RAT) for macOS/OS X written in pure Python, with a server providing both GUI and CLI interfaces an… | 32 | 2415 | abandoned |
| codebutler/firesheep Firesheep is a Firefox extension that demonstrates HTTP session hijacking attacks by sniffing unencrypted Wi-Fi traffic and capturing sessi… | 32 | 2352 | abandoned |
| sevagas/macro_pack macro_pack is a Python CLI tool that automates obfuscation and generation of MS Office documents, VBA/VBS scripts, shortcuts, and other for… | 10 | 2307 | abandoned |
| secgroundzero/warberry WarBerryPi is a tactical exploitation toolkit built to run on a Raspberry Pi, acting as a drop-box/implant for red-team engagements to scan… | 32 | 2220 | abandoned |
| PowerShellEmpire/PowerTools PowerTools is a collection of PowerShell projects focused on offensive security operations, including tools like PowerView, PowerUp, PowerP… | 23 | 2204 | abandoned |
| AdrMXR/KitHack KitHack is a Python-based framework that automates downloading and installing a curated pack of penetration testing tools, organized into c… | 26 | 2085 | abandoned |
| yahoo/gryffin Gryffin is a large-scale web security scanning platform written in Go, built on a publisher-subscriber architecture for horizontal scaling.… | 10 | 2052 | abandoned |
| rasta-mouse/Sherlock Sherlock is a PowerShell script that identifies missing software patches for known Windows local privilege escalation vulnerabilities. It i… | 10 | 2020 | abandoned |
| Fadi002/unshackle Unshackle is a bootable Linux-based ISO that resets or bypasses Windows and Linux user login passwords from a USB drive. It works offline b… | 10 | 1981 | abandoned |
| feihong-cs/ShiroExploit-Deprecated A Java-based one-click exploitation tool for Apache Shiro vulnerabilities Shiro550 (hardcoded key) and Shiro721 (Padding Oracle), supportin… | 23 | 1956 | abandoned |
| Veil-Framework/Veil-Evasion Veil-Evasion is a Python tool that generates Metasploit payloads designed to bypass common antivirus solutions, optionally compiling them i… | 10 | 1840 | abandoned |
| samyk/skyjack SkyJack is a drone hacking tool that autonomously seeks out, disconnects the owner of, and takes wireless control of nearby Parrot AR.Drone… | 32 | 1831 | abandoned |
| govolution/avet AVET (AntiVirus Evasion Tool) is a shell-based toolbox for pentesters to build Windows executables that evade antivirus detection, using te… | 40 | 1755 | abandoned |
| DesignativeDave/androrat Androrat is a client/server Remote Administration Tool for Android devices, with the client written in Java Android and the server in Java/… | 32 | 1634 | abandoned |
| asLody/legend Legend is a Java method hooking framework for Android that works without root access, supporting both Dalvik and ART runtimes. It lets deve… | 32 | 1605 | abandoned |
| carmaa/inception Inception is a Python-based physical memory manipulation tool that exploits PCI-based DMA (over FireWire, Thunderbolt, ExpressCard, PC Card… | 34 | 1602 | abandoned |
| chinoogawa/fbht A Python 2 command-line tool for interacting with and scraping Facebook accounts, including graph-based analysis of social connections. It … | 23 | 1591 | abandoned |
| byt3bl33d3r/SprayingToolkit A set of Python 3 scripts for performing fast password spraying attacks against Lync/Skype for Business, OWA, IMAP, and Office 365, built o… | 10 | 1576 | abandoned |
| SofianeHamlaoui/Lockdoor-Framework Lockdoor Framework is a Python-based penetration testing framework that bundles a curated selection of security tools (information gatherin… | 34 | 1549 | abandoned |
| D4Vinci/Dr0p1t-Framework Dr0p1t-Framework is a Python-based penetration testing framework that generates stealthy Windows dropper executables designed to bypass ant… | 10 | 1473 | abandoned |
| Lucifer1993/AngelSword AngelSword is a simple CMS vulnerability detection framework written in Python3, designed to help security engineers quickly discover known… | 32 | 1441 | abandoned |
| ReversecLabs/needle Needle is an open-source, modular Python framework for streamlining security assessments of iOS applications, covering areas like data stor… | 10 | 1401 | abandoned |
| byt3bl33d3r/gcat Gcat is a proof-of-concept Python backdoor that uses a Gmail account as its command-and-control channel, with an implant deployed on target… | 10 | 1351 | abandoned |
| WWILLV/GodOfHacker GodOfHacker is a satirical C# 'hacker all-in-one tool' whose feature list is intentionally absurd (one-click 0day attacks, stealing QQ acco… | 23 | 1340 | abandoned |
| hackappcom/ibrute A Python proof-of-concept tool that brute-forces AppleID passwords via the Find My iPhone service API, which lacked bruteforce protection. … | 32 | 1322 | abandoned |
| elvanderb/TCP-32764 A collection of Python proof-of-concept code and research notes documenting a hidden backdoor listening on TCP port 32764 in Linksys, Netge… | 32 | 1291 | abandoned |
| clymb3r/PowerShell A collection of useful PowerShell scripts, most notably security and penetration testing tools that were contributed to PowerSploit. The re… | 32 | 1284 | abandoned |