awesome-pentest
Collection of penetration testing tools
https://github.com/al1ex/awesome-pentest
Last synced: 10 days ago
JSON representation
-
Anonymity Tools
- OnionScan - Tool for investigating the Dark Web by finding operational security issues introduced by Tor hidden service operators.
- Tor - Free software and onion routed overlay network that helps you defend against traffic analysis.
- Nipe - Script to redirect all traffic from the machine to the Tor network.
- kalitorify - Transparent proxy through Tor for Kali Linux OS.
- What Every Browser Knows About You - Comprehensive detection page to test your own Web browser's configuration for privacy and identity leaks.
- I2P - The Invisible Internet Project.
-
Anti-virus Evasion Tools
- AntiVirus Evasion Tool (AVET) - Post-process exploits containing executable files targeted for Windows machines to avoid being recognized by antivirus software.
- UniByAv - Simple obfuscator that takes raw shellcode and generates Anti-Virus friendly executables by using a brute-forcable, 32-bit XOR key.
- Veil - Generate metasploit payloads that bypass common anti-virus solutions.
- peCloak.py - Automates the process of hiding a malicious Windows executable from antivirus (AV) detection.
- peCloakCapstone - Multi-platform fork of the peCloak.py automated malware antivirus evasion tool.
- Shellter - Dynamic shellcode injection tool, and the first truly dynamic PE infector ever created.
-
Books
-
Defensive Programming Books
-
Hacker's Handbook Series Books
- Android Hacker's Handbook by Joshua J. Drake et al., 2014
- The Browser Hacker's Handbook by Wade Alcorn et al., 2014
- The Database Hacker's Handbook, David Litchfield et al., 2005
- The Mac Hacker's Handbook by Charlie Miller & Dino Dai Zovi, 2009
- The Mobile Application Hacker's Handbook by Dominic Chell et al., 2015
- The Shellcoder's Handbook by Chris Anley et al., 2007
- The Web Application Hacker's Handbook by D. Stuttard, M. Pinto, 2011
- iOS Hacker's Handbook by Charlie Miller et al., 2012
-
Lock Picking Books
-
Malware Analysis Books
-
Network Analysis Books
-
Penetration Testing Books
- Btfm: Blue Team Field Manual by Alan J White & Ben Clark, 2017
- Fuzzing: Brute Force Vulnerability Discovery by Michael Sutton et al., 2007
- Advanced Penetration Testing by Wil Allsopp, 2017
- Advanced Persistent Threat Hacking: The Art and Science of Hacking Any Organization by Tyler Wrightson, 2014
- Black Hat Python: Python Programming for Hackers and Pentesters by Justin Seitz, 2014
- Unauthorised Access: Physical Penetration Testing For IT Security Teams by Wil Allsopp, 2010
- Penetration Testing: Procedures & Methodologies by EC-Council, 2010
- Rtfm: Red Team Field Manual by Ben Clark, 2014
- The Hacker Playbook by Peter Kim, 2014
- Advanced Penetration Testing for Highly-Secured Environments by Lee Allen, 2012
-
Reverse Engineering Books
-
Social Engineering Books
- Social Engineering in IT Security: Tools, Tactics, and Techniques by Sharon Conheady, 2014
- The Art of Deception by Kevin D. Mitnick & William L. Simon, 2002
- The Art of Intrusion by Kevin D. Mitnick & William L. Simon, 2005
- Unmasking the Social Engineer: The Human Element of Security by Christopher Hadnagy, 2014
-
Windows Books
-
-
Collaboration Tools
-
Windows Books
- RedELK - Track and alarm about Blue Team activities while providing better usability in long term offensive operations.
-
-
Conferences and Events
-
Windows Books
- 44Con - Annual Security Conference held in London.
- BalCCon - Balkan Computer Congress, annually held in Novi Sad, Serbia.
- CCC - Annual meeting of the international hacker scene in Germany.
- CHCon - Christchurch Hacker Con, Only South Island of New Zealand hacker con.
- CarolinaCon - Infosec conference, held annually in North Carolina.
- DEF CON - Annual hacker convention in Las Vegas.
- DeepSec - Security Conference in Vienna, Austria.
- DefCamp - Largest Security Conference in Eastern Europe, held annually in Bucharest, Romania.
- DerbyCon - Annual hacker conference based in Louisville.
- HITB - Deep-knowledge security conference held in Malaysia and The Netherlands.
- Hack.lu - Annual conference held in Luxembourg.
- PhreakNIC - Technology conference held annually in middle Tennessee.
- RSA Conference USA - Annual security conference in San Francisco, California, USA.
- SECUINSIDE - Security Conference in [Seoul](https://en.wikipedia.org/wiki/Seoul).
- ShmooCon - Annual US East coast hacker convention.
- Swiss Cyber Storm - Annual security conference in Lucerne, Switzerland.
- Virus Bulletin Conference - Annual conference going to be held in Denver, USA for 2016.
- Nullcon - Annual conference in Delhi and Goa, India.
- BalCCon - Balkan Computer Congress, annually held in Novi Sad, Serbia.
- AppSecUSA - Annual conference organized by OWASP.
- Black Hat - Annual security conference in Las Vegas.
- BalCCon - Balkan Computer Congress, annually held in Novi Sad, Serbia.
- LayerOne - Annual US security conference held every spring in Los Angeles.
- Virus Bulletin Conference - Annual conference going to be held in Denver, USA for 2016.
- BSides - Framework for organising and holding security conferences.
-
-
CTF Tools
-
Windows Books
- Pwntools - Rapid exploit development framework built for use in CTFs.
- RsaCtfTool - Decrypt data enciphered using weak RSA keys, and recover private keys from public keys using a variety of automated attacks.
- ctf-tools - Collection of setup scripts to install various security research tools easily and quickly deployable to new machines.
- shellpop - Easily generate sophisticated reverse or bind shell commands to help you save time during penetration tests.
-
-
Docker Containers
-
Docker Containers of Intentionally Vulnerable Systems
- OWASP NodeGoat - `docker-compose build && docker-compose up`.
- Vulnerability as a service: Heartbleed - `docker pull hmlio/vaas-cve-2014-0160`.
- Vulnerability as a service: Shellshock - `docker pull hmlio/vaas-cve-2014-6271`.
-
Docker Containers of Penetration Testing Distributions and Tools
- Official OWASP ZAP - `docker pull owasp/zap2docker-stable`.
- Security Ninjas - `docker pull opendns/security-ninjas`.
-
-
File Format Analysis Tools
-
Docker Containers of Penetration Testing Distributions and Tools
- Veles - Binary data visualization and analysis tool.
-
-
GNU/Linux Utilities
-
Docker Containers of Penetration Testing Distributions and Tools
- Hwacha - Post-exploitation tool to quickly execute payloads via SSH on one or more Linux systems simultaneously.
- LinEnum - Scripted local Linux enumeration and privilege escalation checker useful for auditing a host and during CTF gaming.
- unix-privesc-check - Shell script to check for simple privilege escalation vectors on UNIX systems.
- Linux Exploit Suggester - Heuristic reporting on potentially viable exploits for a given GNU/Linux system.
-
-
Hash Cracking Tools
-
Docker Containers of Penetration Testing Distributions and Tools
- BruteForce Wallet - Find the password of an encrypted wallet file (i.e. `wallet.dat`).
- CeWL - Generates custom wordlists by spidering a target's website and collecting unique words.
- JWT Cracker - Simple HS256 JSON Web Token (JWT) token brute force cracker.
- Rar Crack - RAR bruteforce cracker.
- StegCracker - Steganography brute-force utility to uncover hidden data inside files.
- John the Ripper - Fast password cracker.
-
-
Hex Editors
-
Docker Containers of Penetration Testing Distributions and Tools
- 0xED - Native macOS hex editor that supports plug-ins to display custom data types.
- Bless - High quality, full featured, cross-platform graphical hex editor written in Gtk#.
- Hexinator - World's finest (proprietary, commercial) Hex Editor.
- hexedit - Simple, fast, console-based hex editor.
- wxHexEditor - Free GUI hex editor for GNU/Linux, macOS, and Windows.
- Frhed - Binary file editor for Windows.
-
-
Industrial Control and SCADA Systems
-
Docker Containers of Penetration Testing Distributions and Tools
- awesome-industrial-control-system-security
- Industrial Exploitation Framework (ISF) - Metasploit-like exploit framework based on routersploit designed to target Industrial Control Systems (ICS), SCADA devices, PLC firmware, and more.
- s7scan - Scanner for enumerating Siemens S7 PLCs on a TCP/IP or LLC network.
-
-
macOS Utilities
-
Multi-paradigm Frameworks
-
Docker Containers of Penetration Testing Distributions and Tools
- Armitage - Java-based GUI front-end for the Metasploit Framework.
- AutoSploit - Automated mass exploiter, which collects target by employing the Shodan.io API and programmatically chooses Metasploit exploit modules based on the Shodan query.
- Decker - Penetration testing orchestration and automation framework, which allows writing declarative, reusable configurations capable of ingesting variables and using outputs of tools it has run as inputs to others.
- Faraday - Multiuser integrated pentesting environment for red teams performing cooperative penetration tests, security audits, and risk assessments.
- Metasploit - Software for offensive security teams to help verify vulnerabilities and manage security assessments.
- Pupy - Cross-platform (Windows, Linux, macOS, Android) remote administration and post-exploitation tool.
-
-
Network Tools
-
DDoS Tools
- Anevicon - Powerful UDP-based load generator, written in Rust.
- HOIC - Updated version of Low Orbit Ion Cannon, has 'boosters' to get around common counter measures.
- JS LOIC - JavaScript in-browser version of LOIC.
- Memcrashed - DDoS attack tool for sending forged UDP packets to vulnerable Memcached servers obtained using Shodan API.
- SlowLoris - DoS tool that uses low bandwidth on the attacking side.
- UFONet - Abuses OSI layer 7 HTTP to create/manage 'zombies' and to conduct different attacks using; `GET`/`POST`, multithreading, proxies, origin spoofing methods, cache evasion techniques, etc.
- JS LOIC - JavaScript in-browser version of LOIC.
-
Docker Containers of Penetration Testing Distributions and Tools
- CrackMapExec - Swiss army knife for pentesting networks.
- IKEForce - Command line IPSEC VPN brute forcing tool for Linux that allows group name/ID enumeration and XAUTH brute forcing capabilities.
- Intercepter-NG - Multifunctional network toolkit.
- Legion - Graphical semi-automated discovery and reconnaissance framework based on Python 3 and forked from SPARTA.
- Network-Tools.com - Website offering an interface to numerous basic network utilities like `ping`, `traceroute`, `whois`, and more.
- Praeda - Automated multi-function printer data harvester for gathering usable data during security assessments.
- Printer Exploitation Toolkit (PRET) - Tool for printer security testing capable of IP and USB connectivity, fuzzing, and exploitation of PostScript, PJL, and PCL printer language features.
- SPARTA - Graphical interface offering scriptable, configurable access to existing network infrastructure scanning and enumeration tools.
- THC Hydra - Online password cracking tool with built-in support for many network protocols, including HTTP, SMB, FTP, telnet, ICQ, MySQL, LDAP, IMAP, VNC, and more.
- Zarp - Network attack tool centered around the exploitation of local networks.
- dnstwist - Domain name permutation engine for detecting typo squatting, phishing and corporate espionage.
- dsniff - Collection of tools for network auditing and pentesting.
- hping3 - Network tool able to send custom TCP/IP packets.
- pig - GNU/Linux packet crafting tool.
- routersploit - Open source exploitation framework similar to Metasploit but dedicated to embedded devices.
- rshijack - TCP connection hijacker, Rust rewrite of `shijack`.
- scapy - Python-based interactive packet manipulation program & library.
-
Exfiltration Tools
- Cloakify - Textual steganography toolkit that converts any filetype into lists of everyday strings.
- DET - Proof of concept to perform data exfiltration using either single or multiple channel(s) at the same time.
- Iodine - Tunnel IPv4 data through a DNS server; useful for exfiltration from networks where Internet access is firewalled, but DNS queries are allowed.
- pwnat - Punches holes in firewalls and NATs.
- tgcd - Simple Unix network utility to extend the accessibility of TCP/IP based network services beyond firewalls.
-
Network Reconnaissance Tools
- ACLight - Script for advanced discovery of sensitive Privileged Accounts - includes Shadow Admins.
- CloudFail - Unmask server IP addresses hidden behind Cloudflare by searching old database records and detecting misconfigured DNS.
- DNSDumpster - Online DNS recon and search service.
- Mass Scan - TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.
- ScanCannon - Python script to quickly enumerate large networks by calling `masscan` to quickly identify open ports and then `nmap` to gain details on the systems/services on those ports.
- XRay - Network (sub)domain discovery and reconnaissance automation tool.
- dnstracer - Determines where a given DNS server gets its information from, and follows the chain of DNS servers.
- fierce - Python3 port of the original `fierce.pl` DNS reconnaissance tool for locating non-contiguous IP space.
- nmap - Free security scanner for network exploration & security audits.
- passivedns-client - Library and query tool for querying several passive DNS providers.
- passivedns - Network sniffer that logs all DNS server replies for use in a passive DNS setup.
- scanless - Utility for using websites to perform port scans on your behalf so as not to reveal your own IP.
- smbmap - Handy SMB enumeration tool.
- zmap - Open source network scanner that enables researchers to easily perform Internet-wide network studies.
- dnsenum - Perl script that enumerates DNS information from a domain, attempts zone transfers, performs a brute force dictionary style attack, and then performs reverse look-ups on the results.
- dnsmap - Passive DNS network mapper.
- dnsrecon - DNS enumeration script.
-
Protocol Analyzers and Sniffers
- Debookee - Simple and powerful network traffic analyzer for macOS.
- Dripcap - Caffeinated packet analyzer.
- Dshell - Network forensic analysis framework.
- Netzob - Reverse engineering, traffic generation and fuzzing of communication protocols.
- Wireshark - Widely-used graphical, cross-platform network protocol analyzer.
- netsniff-ng - Swiss army knife for for network sniffing.
- sniffglue - Secure multithreaded packet sniffer.
- Debookee - Simple and powerful network traffic analyzer for macOS.
-
Proxies and Machine-in-the-Middle (MITM) Tools
- BetterCAP - Modular, portable and easily extensible MITM framework.
- Habu - Python utility implementing a variety of network attacks, such as ARP poisoning, DHCP starvation, and more.
- Lambda-Proxy - Utility for testing SQL Injection vulnerabilities on AWS Lambda serverless functions.
- MITMf - Framework for Man-In-The-Middle attacks.
- Morpheus - Automated ettercap TCP/IP Hijacking tool.
- SSH MITM - Intercept SSH connections with a proxy; all plaintext passwords and sessions are logged to disk.
- dnschef - Highly configurable DNS proxy for pentesters.
- evilgrade - Modular framework to take advantage of poor upgrade implementations by injecting fake updates.
- mallory - HTTP/HTTPS proxy over SSH.
- mitmproxy - Interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
- oregano - Python module that runs as a machine-in-the-middle (MITM) accepting Tor client requests.
-
Transport Layer Security Tools
- SSLyze - Fast and comprehensive TLS/SSL configuration analyzer to help identify security mis-configurations.
- crackpkcs12 - Multithreaded program to crack PKCS#12 files (`.p12` and `.pfx` extensions), such as TLS/SSL certificates.
- tls_prober - Fingerprint a server's SSL/TLS implementation.
- testssl.sh - Command line tool which checks a server's service on any port for the support of TLS/SSL ciphers, protocols as well as some cryptographic flaws.
-
Wireless Network Tools
- Aircrack-ng - Set of tools for auditing wireless networks.
- Airgeddon - Multi-use bash script for Linux systems to audit wireless networks.
- BoopSuite - Suite of tools written in Python for wireless auditing.
- Bully - Implementation of the WPS brute force attack, written in C.
- Cowpatty - Brute-force dictionary attack against WPA-PSK.
- Fluxion - Suite of automated social engineering based WPA attacks.
- KRACK Detector - Detect and prevent KRACK attacks in your network.
- Kismet - Wireless network detector, sniffer, and IDS.
- Reaver - Brute force attack against WiFi Protected Setup.
- WiFi-Pumpkin - Framework for rogue Wi-Fi access point attack.
- Wifite - Automated wireless attack tool.
- infernal-twin - Automated wireless hacking tool.
- krackattacks-scripts - WPA2 Krack attack scripts.
- wifi-arsenal - Resources for Wi-Fi Pentesting.
-
-
Network Vulnerability Scanners
-
Web Vulnerability Scanners
- ACSTIS - Automated client-side template injection (sandbox escape/bypass) detection for AngularJS.
- JCS - Joomla Vulnerability Component Scanner with automatic database updater from exploitdb and packetstorm.
- Nikto - Noisy but fast black box web server and web application vulnerability scanner.
- SecApps - In-browser web application security testing suite.
-
Programming Languages
Categories
Network Tools
83
Online Resources
56
Books
37
OSINT Tools
35
Web Exploitation
30
Conferences and Events
25
Vulnerability Databases
21
Windows Utilities
20
Reverse Engineering Tools
17
Social Engineering Tools
12
Network Vulnerability Scanners
11
Operating System Distributions
10
Physical Access Tools
9
Static Analyzers
7
Hex Editors
6
Anonymity Tools
6
Anti-virus Evasion Tools
6
Hash Cracking Tools
6
Multi-paradigm Frameworks
6
Security Education Courses
5
Docker Containers
5
CTF Tools
4
GNU/Linux Utilities
4
Industrial Control and SCADA Systems
3
macOS Utilities
2
Periodicals
1
License
1
Side-channel Tools
1
Collaboration Tools
1
File Format Analysis Tools
1
Sub Categories
Penetration Testing Report Templates
139
Docker Containers of Penetration Testing Distributions and Tools
45
Web Vulnerability Scanners
44
Other Lists Online
34
Windows Books
32
Network Reconnaissance Tools
17
Wireless Network Tools
16
Proxies and Machine-in-the-Middle (MITM) Tools
11
Penetration Testing Books
10
Protocol Analyzers and Sniffers
8
Hacker's Handbook Series Books
8
DDoS Tools
7
Online Penetration Testing Resources
7
Online Open Sources Intelligence (OSINT) Resources
6
Exfiltration Tools
5
Social Engineering Books
4
Transport Layer Security Tools
4
Network Analysis Books
3
Docker Containers of Intentionally Vulnerable Systems
3
Online Exploit Development Resources
3
Reverse Engineering Books
3
Malware Analysis Books
2
Lock Picking Books
2
Defensive Programming Books
2
Online Lock Picking Resources
1
Online Code Samples and Examples
1
Online Operating Systems Resources
1
Keywords
security
40
python
23
pentesting
21
hacking
18
awesome
16
awesome-list
14
pentest
12
penetration-testing
11
security-tools
11
osint
10
security-audit
8
scanner
8
list
7
linux
7
hacking-tool
7
golang
7
reconnaissance
6
recon
6
rust
5
go
5
network
5
infosec
5
ruby
5
enumeration
4
mitm
4
appsec
4
network-security
4
active-directory
4
man-in-the-middle
4
pentest-tool
4
bruteforce
4
vulnerability-scanners
4
security-scanner
4
phishing
4
windows
4
bugbounty
4
ctf
4
vulnerability-scanner
3
static-analysis
3
malware-analysis
3
offensive-security
3
penetration
3
cybersecurity
3
forensics
3
information-gathering
3
exploitation
3
shell
3
kali
3
dns
3
fuzzing
3