Ross ROSS = Recommend OSS · open-source software intelligence for agents

function: penetration-testing

859 products, primary matches first, then adoption-weighted; health v2 shown.

ProductHealth v2StarsMaturity
cisagov/log4j-scanner
A CISA-derived scanner for detecting web services vulnerable to the Log4Shell remote code execution vulnerabilities (CVE-2021-44228 and CVE…
101278abandoned
samyk/usbdriveby
USBdriveby is an Arduino/Teensy microcontroller project that emulates a USB HID keyboard and mouse to covertly install a backdoor, evade fi…
321263abandoned
LOoLzeC/ASU
ASU is a Python-based Facebook hacking toolkit offering account checking and spamming features, distributed via a Termux/Linux install scri…
321251abandoned
vaycore/OneScan
OneScan is a BurpSuite extension written in Java for recursive directory scanning, helping discover hidden vulnerabilities in deeper direct…
101251abandoned
Ha3MrX/Gemail-Hack
A Python command-line script that performs brute-force password attacks against Gmail accounts. It is a simple educational/offensive-securi…
661231abandoned
the-robot/sqliv
SQLiv is a Python command-line tool that scans websites for SQL injection vulnerabilities. It supports dork-based scanning via search engin…
101229abandoned
NYAN-x-CAT/Lime-RAT
LimeRAT is a remote administration tool (RAT) for Windows written in Visual Basic .NET, providing remote desktop, file management, keyloggi…
101134abandoned
sensepost/mana
MANA is a toolkit for rogue access point (evilAP) attacks, implementing improved KARMA attacks via a modified hostapd plus MitM configurati…
231110abandoned
evilsocket/bleah
A deprecated command-line tool for scanning and enumerating Bluetooth Low Energy (BLE) devices. It has been ported into bettercap's BLE mod…
101094abandoned
arnaucube/coffeeMiner
CoffeeMiner is a Python tool that performs a man-in-the-middle attack on a WiFi/LAN network, injecting a JavaScript cryptocurrency miner in…
321077abandoned
ekkoo-z/Z-Godzilla_ekp
A modified (second-development) fork of the Godzilla webshell management tool, customized to evade network traffic detection devices and an…
421075abandoned
1n7erface/PocList
A Java-based collection of proof-of-concept (PoC) tools for verifying and exploiting known vulnerabilities in products like Nacos, WebLogic…
321075abandoned
WyAtu/Perun
Perun is a Python-based network asset vulnerability scanner and scanning framework designed for penetration testers and red teams, primaril…
321051abandoned
M4cs/BabySploit
BabySploit is a beginner-friendly penetration testing toolkit and framework written in Python, designed to ease newcomers into using more c…
231042abandoned
utkusen/leviathan
Leviathan is a Python-based mass audit toolkit that combines masscan, ncrack, and DSSS to discover services, brute-force credentials, detec…
101041abandoned
ba0gu0/520apkhook
A Java-based tool that attaches an Android remote-access APK payload to a legitimate app, producing a trojanized APK where the original app…
321015abandoned
timwr/CVE-2016-5195
A proof-of-concept exploit for CVE-2016-5195 (Dirty Cow) targeting Android devices, built with the Android NDK and deployed over ADB. It de…
321010abandoned
mitmproxy/mitmproxy
mitmproxy is an interactive, SSL/TLS-capable intercepting proxy for HTTP/1, HTTP/2, HTTP/3, and WebSockets, offered as a console tool (mitm…
8944820stable
promptfoo/promptfoo
Promptfoo is an open-source CLI and library for evaluating and red-teaming LLM applications, prompts, agents, and RAG pipelines. It support…
9224603active
dstotijn/hetty
Hetty is an open source HTTP toolkit for security research, serving as an alternative to Burp Suite Pro. It provides a MITM HTTP proxy with…
6512007active
evilsocket/pwnagotchi
Pwnagotchi is an A2C deep reinforcement learning agent built on bettercap that learns from its surrounding WiFi environment to maximize cap…
679189active
androguard/androguard
Androguard is a full Python tool and library for reverse engineering and analyzing Android files, including DEX/ODEX bytecode disassembly a…
836209active
Trusted-AI/adversarial-robustness-toolbox
Adversarial Robustness Toolbox (ART) is a Python library for machine learning security covering evasion, poisoning, extraction, and inferen…
556204stable
Ed1s0nZ/CyberStrikeAI
CyberStrikeAI is a Go-based AI-native cybersecurity platform that combines LLM-powered agents, MCP-native tools, RAG knowledge bases, and v…
795991active
aidlearning/AidLearning-FrameWork
AidLux (originally AidLearning) is an AIoT development platform that runs a native Ubuntu Linux environment with GUI, deep learning tooling…
705797active
sensity-ai/dot
dot (Deepfake Offensive Toolkit) is a Python tool that generates real-time, controllable deepfakes from a webcam feed and injects them into…
234586active
GerbenJavado/LinkFinder
LinkFinder is a Python CLI script that discovers endpoints and their parameters in JavaScript files using jsbeautifier and regular expressi…
324439stable
ConsenSysDiligence/mythril
Mythril is a symbolic-execution-based security analysis tool for EVM bytecode that detects vulnerabilities in Ethereum and other EVM-compat…
584265active
google/tamperchrome
Tamper Dev is a browser extension that intercepts and edits HTTP/HTTPS requests and responses in real time without requiring a proxy or aux…
544218active
gtworek/PSBits
A collection of relatively simple C and PowerShell snippets for digging deeper into Windows internals, security, and forensics. Each folder…
763519active
epsylon/ufonet
UFONet is a free, P2P and cryptographic 'disruptive toolkit' written in Python for performing DoS and DDoS attacks at Layer 7 (HTTP) via Op…
762509active
OpenBullet
OpenBullet 2 is a cross-platform automation suite built on .NET for performing HTTP requests against target web applications and processing…
852389active
learnhouse/learnhouse
LearnHouse is a next-generation open-source learning management system (LMS) for creating, sharing, and selling educational content. It com…
992203active
anthropics/defending-code-reference-harness
A reference implementation from Anthropic for autonomous vulnerability discovery and remediation using Claude, including Claude Code skills…
577368maintenance
microsoft/CyberBattleSim
CyberBattleSim is a Python-based experimentation and research platform from Microsoft that simulates abstract enterprise network environmen…
771784active
mandatoryprogrammer/CursedChrome
CursedChrome is a Chrome extension implant that converts a victim's Chrome browser into a fully-functional HTTP proxy, letting an operator …
321728active
cyberark/FuzzyAI
FuzzyAI is an automated LLM fuzzing tool from CyberArk that tests LLM APIs for jailbreak vulnerabilities. It ships as a Python CLI with a w…
511568active
akto-api-security/akto
Akto is an open-source API and AI security platform that discovers and inventories APIs, AI agents, MCP servers, and LLM usage, then contin…
941505active
llm-attacks/llm-attacks
Official research code for 'Universal and Transferable Adversarial Attacks on Aligned Language Models', implementing the GCG algorithm for …
284769maintenance
nccgroup/singularity
Singularity of Origin is a DNS rebinding attack framework that includes a DNS server, a web server, a management UI, and sample attack payl…
741315active
erev0s/VAmPI
VAmPI is a deliberately vulnerable REST API built with Flask that implements the OWASP Top 10 vulnerabilities for APIs. It is designed for …
661311active
PentesterFlow/agent
PentesterFlow is a terminal-based agentic AI CLI assistant for penetration testers and bug bounty hunters. It orchestrates LLM-driven recon…
711308active
larlarua/AutoCVE
AutoCVE is a self-hosted multi-agent platform that automates CVE discovery: it filters target projects, imports repositories, audits source…
771280active
0x727/ShuiZe_0x727
ShuiZe_0x727 is a Python-based automated information gathering (reconnaissance) tool for red team operators. Given a root domain, C-segment…
234019maintenance
laluka/bypass-url-parser
A Python CLI tool (usable as a library) that generates and tests many URL bypass payloads to access 40X-protected pages, using curl as its …
741138active
martin-olivier/airgorah
Airgorah is a WiFi security auditing application built in Rust with a GTK4 graphical interface, wrapping the aircrack-ng tools suite. It ca…
901096active
rogue-security/rogue
Rogue is an open-source AI agent evaluator and red teaming platform that stress-tests agents against business policies and simulated advers…
781058active
techchipnet/hound
Hound is a lightweight PHP-based information gathering tool that captures a target device's exact GPS coordinates along with system and ISP…
301016active
moxie0/sslstrip
sslstrip is a Python command-line tool that implements Moxie Marlinspike's SSL stripping man-in-the-middle attack, downgrading HTTPS links …
322073maintenance
droe/sslsplit
SSLsplit is a transparent SSL/TLS interception proxy for man-in-the-middle attacks against encrypted network connections. It terminates TLS…
541876maintenance
Err0r-ICA/TermuxCyberArmy
TermuxCyberArmy is a shell/Python-based hacking toolkit script for the Termux terminal environment on Android. It bundles a collection of s…
431701maintenance
ViRb3/TrustMeAlready
An Xposed module for rooted Android devices that disables SSL certificate verification and pinning system-wide. It hooks Java trust-check m…
101508maintenance
veo/wsMemShell
A Java-based WebSocket memory webshell (memshell) tool that injects WebSocket endpoints into running application servers like Tomcat, Sprin…
321490maintenance
4ra1n/super-xray
Super Xray is a Java-based GUI launcher for the xray web vulnerability scanner, wrapping its command-line interface and config.yaml setup i…
101325maintenance
vincentcox/bypass-firewalls-by-DNS-history
A shell script that attempts to bypass web application firewalls (like Cloudflare, Incapsula, SUCURI) by finding the origin server IP throu…
321306maintenance
khast3x/Redcloud
Redcloud is a Python-based toolbox that automates deployment of red team attack infrastructure using Docker, deployable locally or remotely…
231276maintenance
lmammino/jwt-cracker
jwt-cracker is a Node.js command-line tool that brute-forces the signing secrets of HS256, HS384, and HS512 JWT tokens. It supports custom …
231179maintenance
TideSec/FuzzScanner
FuzzScanner is a Ruby/Python-based reconnaissance toolset that batch-collects information about target websites, including subdomains, open…
321008maintenance
hahwul/XSpear
XSpear is a Ruby-based XSS (cross-site scripting) scanner and parameter analysis tool distributed as a gem, usable both as a CLI and as a R…
101364abandoned

← prev page 9 / 9