function: penetration-testing
859 products, primary matches first, then adoption-weighted; health v2 shown.
| Product | Health v2 | Stars | Maturity |
|---|---|---|---|
| cisagov/log4j-scanner A CISA-derived scanner for detecting web services vulnerable to the Log4Shell remote code execution vulnerabilities (CVE-2021-44228 and CVE… | 10 | 1278 | abandoned |
| samyk/usbdriveby USBdriveby is an Arduino/Teensy microcontroller project that emulates a USB HID keyboard and mouse to covertly install a backdoor, evade fi… | 32 | 1263 | abandoned |
| LOoLzeC/ASU ASU is a Python-based Facebook hacking toolkit offering account checking and spamming features, distributed via a Termux/Linux install scri… | 32 | 1251 | abandoned |
| vaycore/OneScan OneScan is a BurpSuite extension written in Java for recursive directory scanning, helping discover hidden vulnerabilities in deeper direct… | 10 | 1251 | abandoned |
| Ha3MrX/Gemail-Hack A Python command-line script that performs brute-force password attacks against Gmail accounts. It is a simple educational/offensive-securi… | 66 | 1231 | abandoned |
| the-robot/sqliv SQLiv is a Python command-line tool that scans websites for SQL injection vulnerabilities. It supports dork-based scanning via search engin… | 10 | 1229 | abandoned |
| NYAN-x-CAT/Lime-RAT LimeRAT is a remote administration tool (RAT) for Windows written in Visual Basic .NET, providing remote desktop, file management, keyloggi… | 10 | 1134 | abandoned |
| sensepost/mana MANA is a toolkit for rogue access point (evilAP) attacks, implementing improved KARMA attacks via a modified hostapd plus MitM configurati… | 23 | 1110 | abandoned |
| evilsocket/bleah A deprecated command-line tool for scanning and enumerating Bluetooth Low Energy (BLE) devices. It has been ported into bettercap's BLE mod… | 10 | 1094 | abandoned |
| arnaucube/coffeeMiner CoffeeMiner is a Python tool that performs a man-in-the-middle attack on a WiFi/LAN network, injecting a JavaScript cryptocurrency miner in… | 32 | 1077 | abandoned |
| ekkoo-z/Z-Godzilla_ekp A modified (second-development) fork of the Godzilla webshell management tool, customized to evade network traffic detection devices and an… | 42 | 1075 | abandoned |
| 1n7erface/PocList A Java-based collection of proof-of-concept (PoC) tools for verifying and exploiting known vulnerabilities in products like Nacos, WebLogic… | 32 | 1075 | abandoned |
| WyAtu/Perun Perun is a Python-based network asset vulnerability scanner and scanning framework designed for penetration testers and red teams, primaril… | 32 | 1051 | abandoned |
| M4cs/BabySploit BabySploit is a beginner-friendly penetration testing toolkit and framework written in Python, designed to ease newcomers into using more c… | 23 | 1042 | abandoned |
| utkusen/leviathan Leviathan is a Python-based mass audit toolkit that combines masscan, ncrack, and DSSS to discover services, brute-force credentials, detec… | 10 | 1041 | abandoned |
| ba0gu0/520apkhook A Java-based tool that attaches an Android remote-access APK payload to a legitimate app, producing a trojanized APK where the original app… | 32 | 1015 | abandoned |
| timwr/CVE-2016-5195 A proof-of-concept exploit for CVE-2016-5195 (Dirty Cow) targeting Android devices, built with the Android NDK and deployed over ADB. It de… | 32 | 1010 | abandoned |
| mitmproxy/mitmproxy mitmproxy is an interactive, SSL/TLS-capable intercepting proxy for HTTP/1, HTTP/2, HTTP/3, and WebSockets, offered as a console tool (mitm… | 89 | 44820 | stable |
| promptfoo/promptfoo Promptfoo is an open-source CLI and library for evaluating and red-teaming LLM applications, prompts, agents, and RAG pipelines. It support… | 92 | 24603 | active |
| dstotijn/hetty Hetty is an open source HTTP toolkit for security research, serving as an alternative to Burp Suite Pro. It provides a MITM HTTP proxy with… | 65 | 12007 | active |
| evilsocket/pwnagotchi Pwnagotchi is an A2C deep reinforcement learning agent built on bettercap that learns from its surrounding WiFi environment to maximize cap… | 67 | 9189 | active |
| androguard/androguard Androguard is a full Python tool and library for reverse engineering and analyzing Android files, including DEX/ODEX bytecode disassembly a… | 83 | 6209 | active |
| Trusted-AI/adversarial-robustness-toolbox Adversarial Robustness Toolbox (ART) is a Python library for machine learning security covering evasion, poisoning, extraction, and inferen… | 55 | 6204 | stable |
| Ed1s0nZ/CyberStrikeAI CyberStrikeAI is a Go-based AI-native cybersecurity platform that combines LLM-powered agents, MCP-native tools, RAG knowledge bases, and v… | 79 | 5991 | active |
| aidlearning/AidLearning-FrameWork AidLux (originally AidLearning) is an AIoT development platform that runs a native Ubuntu Linux environment with GUI, deep learning tooling… | 70 | 5797 | active |
| sensity-ai/dot dot (Deepfake Offensive Toolkit) is a Python tool that generates real-time, controllable deepfakes from a webcam feed and injects them into… | 23 | 4586 | active |
| GerbenJavado/LinkFinder LinkFinder is a Python CLI script that discovers endpoints and their parameters in JavaScript files using jsbeautifier and regular expressi… | 32 | 4439 | stable |
| ConsenSysDiligence/mythril Mythril is a symbolic-execution-based security analysis tool for EVM bytecode that detects vulnerabilities in Ethereum and other EVM-compat… | 58 | 4265 | active |
| google/tamperchrome Tamper Dev is a browser extension that intercepts and edits HTTP/HTTPS requests and responses in real time without requiring a proxy or aux… | 54 | 4218 | active |
| gtworek/PSBits A collection of relatively simple C and PowerShell snippets for digging deeper into Windows internals, security, and forensics. Each folder… | 76 | 3519 | active |
| epsylon/ufonet UFONet is a free, P2P and cryptographic 'disruptive toolkit' written in Python for performing DoS and DDoS attacks at Layer 7 (HTTP) via Op… | 76 | 2509 | active |
| OpenBullet OpenBullet 2 is a cross-platform automation suite built on .NET for performing HTTP requests against target web applications and processing… | 85 | 2389 | active |
| learnhouse/learnhouse LearnHouse is a next-generation open-source learning management system (LMS) for creating, sharing, and selling educational content. It com… | 99 | 2203 | active |
| anthropics/defending-code-reference-harness A reference implementation from Anthropic for autonomous vulnerability discovery and remediation using Claude, including Claude Code skills… | 57 | 7368 | maintenance |
| microsoft/CyberBattleSim CyberBattleSim is a Python-based experimentation and research platform from Microsoft that simulates abstract enterprise network environmen… | 77 | 1784 | active |
| mandatoryprogrammer/CursedChrome CursedChrome is a Chrome extension implant that converts a victim's Chrome browser into a fully-functional HTTP proxy, letting an operator … | 32 | 1728 | active |
| cyberark/FuzzyAI FuzzyAI is an automated LLM fuzzing tool from CyberArk that tests LLM APIs for jailbreak vulnerabilities. It ships as a Python CLI with a w… | 51 | 1568 | active |
| akto-api-security/akto Akto is an open-source API and AI security platform that discovers and inventories APIs, AI agents, MCP servers, and LLM usage, then contin… | 94 | 1505 | active |
| llm-attacks/llm-attacks Official research code for 'Universal and Transferable Adversarial Attacks on Aligned Language Models', implementing the GCG algorithm for … | 28 | 4769 | maintenance |
| nccgroup/singularity Singularity of Origin is a DNS rebinding attack framework that includes a DNS server, a web server, a management UI, and sample attack payl… | 74 | 1315 | active |
| erev0s/VAmPI VAmPI is a deliberately vulnerable REST API built with Flask that implements the OWASP Top 10 vulnerabilities for APIs. It is designed for … | 66 | 1311 | active |
| PentesterFlow/agent PentesterFlow is a terminal-based agentic AI CLI assistant for penetration testers and bug bounty hunters. It orchestrates LLM-driven recon… | 71 | 1308 | active |
| larlarua/AutoCVE AutoCVE is a self-hosted multi-agent platform that automates CVE discovery: it filters target projects, imports repositories, audits source… | 77 | 1280 | active |
| 0x727/ShuiZe_0x727 ShuiZe_0x727 is a Python-based automated information gathering (reconnaissance) tool for red team operators. Given a root domain, C-segment… | 23 | 4019 | maintenance |
| laluka/bypass-url-parser A Python CLI tool (usable as a library) that generates and tests many URL bypass payloads to access 40X-protected pages, using curl as its … | 74 | 1138 | active |
| martin-olivier/airgorah Airgorah is a WiFi security auditing application built in Rust with a GTK4 graphical interface, wrapping the aircrack-ng tools suite. It ca… | 90 | 1096 | active |
| rogue-security/rogue Rogue is an open-source AI agent evaluator and red teaming platform that stress-tests agents against business policies and simulated advers… | 78 | 1058 | active |
| techchipnet/hound Hound is a lightweight PHP-based information gathering tool that captures a target device's exact GPS coordinates along with system and ISP… | 30 | 1016 | active |
| moxie0/sslstrip sslstrip is a Python command-line tool that implements Moxie Marlinspike's SSL stripping man-in-the-middle attack, downgrading HTTPS links … | 32 | 2073 | maintenance |
| droe/sslsplit SSLsplit is a transparent SSL/TLS interception proxy for man-in-the-middle attacks against encrypted network connections. It terminates TLS… | 54 | 1876 | maintenance |
| Err0r-ICA/TermuxCyberArmy TermuxCyberArmy is a shell/Python-based hacking toolkit script for the Termux terminal environment on Android. It bundles a collection of s… | 43 | 1701 | maintenance |
| ViRb3/TrustMeAlready An Xposed module for rooted Android devices that disables SSL certificate verification and pinning system-wide. It hooks Java trust-check m… | 10 | 1508 | maintenance |
| veo/wsMemShell A Java-based WebSocket memory webshell (memshell) tool that injects WebSocket endpoints into running application servers like Tomcat, Sprin… | 32 | 1490 | maintenance |
| 4ra1n/super-xray Super Xray is a Java-based GUI launcher for the xray web vulnerability scanner, wrapping its command-line interface and config.yaml setup i… | 10 | 1325 | maintenance |
| vincentcox/bypass-firewalls-by-DNS-history A shell script that attempts to bypass web application firewalls (like Cloudflare, Incapsula, SUCURI) by finding the origin server IP throu… | 32 | 1306 | maintenance |
| khast3x/Redcloud Redcloud is a Python-based toolbox that automates deployment of red team attack infrastructure using Docker, deployable locally or remotely… | 23 | 1276 | maintenance |
| lmammino/jwt-cracker jwt-cracker is a Node.js command-line tool that brute-forces the signing secrets of HS256, HS384, and HS512 JWT tokens. It supports custom … | 23 | 1179 | maintenance |
| TideSec/FuzzScanner FuzzScanner is a Ruby/Python-based reconnaissance toolset that batch-collects information about target websites, including subdomains, open… | 32 | 1008 | maintenance |
| hahwul/XSpear XSpear is a Ruby-based XSS (cross-site scripting) scanner and parameter analysis tool distributed as a gem, usable both as a CLI and as a R… | 10 | 1364 | abandoned |
← prev page 9 / 9