Projects in Awesome Lists tagged with penetration-testing-tools
A curated list of projects in awesome lists tagged with penetration-testing-tools .
https://github.com/urbanadventurer/whatweb
Next generation web scanner
application-security appsec hacking hacking-tools kali-linux network-security owasp penetration-test penetration-testing penetration-testing-tools pentest pentesting pentesting-tools recon ruby scanner security security-tools web web-hacking
Last synced: 14 May 2025
https://github.com/urbanadventurer/WhatWeb
Next generation web scanner
application-security appsec hacking hacking-tools kali-linux network-security owasp penetration-test penetration-testing penetration-testing-tools pentest pentesting pentesting-tools recon ruby scanner security security-tools web web-hacking
Last synced: 14 Mar 2025
https://github.com/drk1wi/Modlishka
Modlishka. Reverse Proxy.
mitm penetration-testing-tools phishing reverse-proxy security-tools
Last synced: 30 Mar 2025
https://github.com/drk1wi/modlishka
Modlishka. Reverse Proxy.
mitm penetration-testing-tools phishing reverse-proxy security-tools
Last synced: 13 Mar 2025
https://github.com/cdk-team/cdk
📦 Make security testing of K8s, Docker, and Containerd easier.
blackhat cloud-native cloud-native-security container container-escape container-security docker exploits hacktools hitb k8s k8s-penetration-toolkit kernel-exploitation kubernetes kubernetes-security linux penetration penetration-testing-tools privilege-escalation vulnerabilities
Last synced: 15 May 2025
https://github.com/t3l3machus/villain
Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).
c2 cybersecurity hacking hacking-tool offensive-security open-source penetration-testing penetration-testing-tools pentest pentesting readteaming redteam redteam-tools
Last synced: 13 May 2025
https://github.com/cdk-team/CDK
📦 Make security testing of K8s, Docker, and Containerd easier.
blackhat cloud-native cloud-native-security container container-escape container-security docker exploits hacktools hitb k8s k8s-penetration-toolkit kernel-exploitation kubernetes kubernetes-security linux penetration penetration-testing-tools privilege-escalation vulnerabilities
Last synced: 04 Apr 2025
https://github.com/t3l3machus/Villain
Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).
c2 cybersecurity hacking hacking-tool offensive-security open-source penetration-testing penetration-testing-tools pentest pentesting readteaming redteam redteam-tools
Last synced: 30 Mar 2025
https://github.com/kelvinben/appinfoscanner
一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。
android apk apk-dex hacking hacking-tool ipa network-security penetration-test penetration-testing-tools python3 scanner security security-tools tools web-hacking
Last synced: 15 May 2025
https://github.com/kelvinBen/AppInfoScanner
一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。
android apk apk-dex hacking hacking-tool ipa network-security penetration-test penetration-testing-tools python3 scanner security security-tools tools web-hacking
Last synced: 15 May 2025
https://github.com/bishopfox/cloudfox
Automating situational awareness for cloud penetration tests.
aws cloud cloud-security golang penetration-testing-tools security
Last synced: 14 May 2025
https://github.com/BishopFox/CloudFox
Automating situational awareness for cloud penetration tests.
aws cloud cloud-security golang penetration-testing-tools security
Last synced: 07 May 2025
https://github.com/BishopFox/cloudfox
Automating situational awareness for cloud penetration tests.
aws cloud cloud-security golang penetration-testing-tools security
Last synced: 02 Apr 2025
https://github.com/x364e3ab6/DudeSuite
DudeSuite Web Security Tools
0day 1day awvs dude dudesuite hacker hackertools hydra nday nmap packet penetration-testing-tools poc scan scanner-web sqlmap tools
Last synced: 07 Sep 2025
https://github.com/cyberark/kubesploit
Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.
agent c2 command-and-control containers golang http2 kubernetes penetration-testing-framework penetration-testing-tools post-exploitation red-teams redteam-tools security security-tools
Last synced: 28 Sep 2025
https://github.com/nhas/reverse_ssh
SSH based reverse shell
conpty golang hacking penetration-testing-tools pentest pentesting proxy reverse-shell scp security-tools sftp shell ssh static-binary terminal tunnel
Last synced: 16 May 2025
https://github.com/rhaidiz/broxy
An HTTP/HTTPS intercept proxy written in Go.
broxy go golang hacking http-interceptor http-proxy http-security interceptor penetration-testing penetration-testing-tools proxy qt-wrapper qt5-gui security wapt websecurity
Last synced: 13 Apr 2025
https://github.com/Fahrj/reverse-ssh
Statically-linked ssh server with reverse shell functionality for CTFs and such
backdoor conpty golang hacking penetration-testing penetration-testing-tools remote-admin-tool remote-shell reverse-shell security security-tools ssh terminal
Last synced: 29 Mar 2025
https://github.com/Esc4iCEscEsc/skanuvaty
Dangerously fast DNS/network/port scanner
cybersecurity dns dns-client hacking-tools osint-tool penetration-testing penetration-testing-tools pentest pentesting redteam redteam-tools rust rust-lang scanner security security-tools subdomain-enumeration subdomain-scanner
Last synced: 05 Apr 2025
https://github.com/esc4icescesc/skanuvaty
Dangerously fast DNS/network/port scanner
cybersecurity dns dns-client hacking-tools osint-tool penetration-testing penetration-testing-tools pentest pentesting redteam redteam-tools rust rust-lang scanner security security-tools subdomain-enumeration subdomain-scanner
Last synced: 04 Apr 2025
https://github.com/Hackmanit/Web-Cache-Vulnerability-Scanner
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).
bugbounty hacking hacking-tool penetration-testing penetration-testing-tools pentesting scanner security security-audit security-scanner security-tools vulnerability-scanners web-cache
Last synced: 04 Apr 2025
https://github.com/r0x4r/garud
An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
assetfinder bash-script bugbounty bugbounty-tool bugbountytips garud gf-patterns golang penetration-testing penetration-testing-tools reconnaissance subdomain-takeover vulnerability vulnerability-scanner
Last synced: 12 Apr 2025
https://github.com/R0X4R/Garud
An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
assetfinder bash-script bugbounty bugbounty-tool bugbountytips garud gf-patterns golang penetration-testing penetration-testing-tools reconnaissance subdomain-takeover vulnerability vulnerability-scanner
Last synced: 07 Apr 2025
https://github.com/sinfulz/JustTryHarder
JustTryHarder, a cheat sheet which will aid you through the PWK course & the OSCP Exam. (Inspired by PayloadAllTheThings)
hacktoberfest hacktoberfest-accepted oscp penetration penetration-test penetration-test-framework penetration-testing penetration-testing-tools penetration-tests pentest pentest-environment pentest-scripts pentest-tool pentest-tools pentesters pentesting pentesting-networks pentesting-tools pentesting-windows testing
Last synced: 11 Jul 2025
https://github.com/vladko312/SSTImap
Automatic SSTI detection tool with interactive interface
information-security penetration-testing penetration-testing-tools pentest pentest-tool pentesting pentesting-tools python rce ssti
Last synced: 18 Apr 2025
https://github.com/jwt1399/Sec-Tools
🍉一款基于Python-Django的多功能Web安全渗透测试工具,包含漏洞扫描,端口扫描,指纹识别,目录扫描,旁站扫描,域名扫描等功能。
django penetration-testing-tools python3 scan-tool security-tools vulnerability-scanners
Last synced: 21 Jul 2025
https://github.com/Cgboal/SonarSearch
A rapid API for the Project Sonar dataset
bugbounty dns enumeration osint osint-tool penetration-testing penetration-testing-tools rapid7 sonar-api subdomain subdomain-enumeration
Last synced: 19 Apr 2025
https://github.com/MattKeeley/Spoofy
Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.
application-security appsec cybersecurity deliverability dmarc email-security emails infosec penetration-testing penetration-testing-tools pentesting phishing python python3 redteam security spf
Last synced: 03 Apr 2025
https://github.com/hueristiq/xurlfind3r
A command-line utility designed to discover URLs for a given domain in a simple, efficient way. It works by gathering information from a variety of passive sources, meaning it doesn't interact directly with the target but instead gathers data that is already publicly available.
bug-bounty bug-bounty-tools contentdiscovery ethical-hacking ethical-hacking-tools go golang osint osint-tools penetration-testing penetration-testing-tools reconnaissance red-teaming red-teaming-tools web-security
Last synced: 24 Oct 2025
https://github.com/InfosecMatter/Minimalistic-offensive-security-tools
A repository of tools for pentesting of restricted and isolated environments.
active-directory brute-force login-automation login-brute-force-attacks penetration-testing penetration-testing-tools port-scanner port-scanning portscan portscanner powershell restricted-environments security-audit security-automation smb windows
Last synced: 29 Apr 2025
https://github.com/coalfire-research/slackor
A Golang implant that uses Slack as a command and control server
c2 command-and-control golang penetration-testing penetration-testing-tools pentest python red-team remote-admin-tool
Last synced: 05 Apr 2025
https://github.com/Coalfire-Research/Slackor
A Golang implant that uses Slack as a command and control server
c2 command-and-control golang penetration-testing penetration-testing-tools pentest python red-team remote-admin-tool
Last synced: 20 Mar 2025
https://github.com/factionsecurity/faction
Pen Test Report Generation and Assessment Collaboration
application-security hacking penetration-testing penetration-testing-tools pentesting reporting security security-audit security-automation security-tools security-vulnerability
Last synced: 27 Oct 2025
https://github.com/mhmdiaa/second-order
Second-order subdomain takeover scanner
crawler crawling infosec mapping penetration-testing penetration-testing-tools pentesting recon reconnaissance security security-tools web-application-security wordlist wordlist-generator
Last synced: 05 Apr 2025
https://github.com/MS-WEB-BN/t14m4t
Automated brute-forcing attack tool.
brute-force brute-force-attack brute-force-attacks brute-force-passwords bruteforce hacking hacking-tool hacking-tools nmap penetration-test penetration-testing-tools penetration-tests thc-hydra wrapper
Last synced: 12 Jul 2025
https://github.com/sofianehamlaoui/pentest-notes
Collection of Pentest Notes and Cheatsheets from a lot of repos (SofianeHamlaoui,dostoevsky,mantvydasb,adon90,BriskSec)
cheatsheets offensive-security penetration-testing penetration-testing-tools pentesting security security-audit security-tools sofianehamlaoui
Last synced: 12 Mar 2025
https://github.com/SofianeHamlaoui/Pentest-Notes
Collection of Pentest Notes and Cheatsheets from a lot of repos (SofianeHamlaoui,dostoevsky,mantvydasb,adon90,BriskSec)
cheatsheets offensive-security penetration-testing penetration-testing-tools pentesting security security-audit security-tools sofianehamlaoui
Last synced: 12 Jul 2025
https://github.com/itaymigdal/Nimbo-C2
Nimbo-C2 is yet another (simple and lightweight) C2 framework
c2 c2-framework command-and-control payload-generator penetration-testing-tools pentesting-tools rat red-team red-team-tools
Last synced: 05 Apr 2025
https://github.com/PalindromeLabs/STEWS
A Security Tool for Enumerating WebSockets
penetration-testing penetration-testing-tools security web-application-security websocket websocket-security websockets websockets-security
Last synced: 10 May 2025
https://github.com/edoardottt/lit-bb-hack-tools
Little Bug Bounty & Hacking Tools⚔️
bug-bounty bug-bounty-recon bugbounty cli cli-tool ctf-tool ctf-tools hacking hacking-tool hacking-tools hacktoberfest infosec infosectools penetration-testing-tools security-tools tools
Last synced: 11 Nov 2025
https://github.com/cyberark/evasor
A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies
bypass-applocker-policies full-automated penetration-testing-tools post-exploitation
Last synced: 04 Jul 2025
https://github.com/cyberark/Evasor
A tool to be used in post exploitation phase for blue and red teams to bypass APPLICATIONCONTROL policies
bypass-applocker-policies full-automated penetration-testing-tools post-exploitation
Last synced: 11 Jul 2025
https://github.com/zishanadthandar/pentest
Pentesting and Bug Bounty Notes, Cheetsheets and Guide for Ethical Hacker, Whitehat Pentesters and CTF Players.
activedirectory cheetsheet cyber-security cybersecurity cybersecurity-tool ethical-hacking hacking hacking-tool infosec penetration-testing penetration-testing-tools pentest pentesting powershell redteam redteaming security web-application-penetration-testing web-application-security whitehat-hacker
Last synced: 16 May 2025
https://github.com/dfw1n/dfw1n-osint
Australian Open Source Intelligence Gathering Resources, Australias Largest Open Source Intelligence Repository for Cyber Professionals and Ethical Hackers
australia cryptography cybersecurity darkweb-data ethical-hacking forensics intelligence intelligence-search-service investigator opensource osint osint-framework osint-reconnaissance osint-resources penetration-testing-tools police redteaming social-media social-network
Last synced: 20 Mar 2025
https://github.com/CervantesSec/cervantes
Cervantes is an open-source, collaborative platform designed specifically for pentesters and red teams. It serves as a comprehensive management tool, streamlining the organization of projects, clients, vulnerabilities, and reports in a single, centralized location.
audit burpsuite collaboration collaboration-platform collaborative cve hacking nessus nmap penetration-testing penetration-testing-tools pentesters pentesting red-team red-teaming report reporting security vulnerability vulnerability-management
Last synced: 11 Jul 2025
https://github.com/DontPanicO/jwtXploiter
A tool to test security of json web token
ctf ctf-tools jku jsonwebtoken jwks jwt jwt-cracker jwt-exploit jwt-security penetration-testing penetration-testing-tools pentest pentest-tool pentesting pentesting-tools security security-tools websecurity x5u-injection
Last synced: 13 May 2025
https://github.com/dontpanico/jwtxploiter
A tool to test security of json web token
ctf ctf-tools jku jsonwebtoken jwks jwt jwt-cracker jwt-exploit jwt-security penetration-testing penetration-testing-tools pentest pentest-tool pentesting pentesting-tools security security-tools websecurity x5u-injection
Last synced: 05 Apr 2025
https://github.com/trickest/mksub
Generate tens of thousands of subdomain combinations in a matter of seconds
bugbounty bugbountytips enumeration infosec infosectools penetration-testing penetration-testing-tools pentesting pentesting-tools recon reconnaissance security security-tools subdomain subdomain-enumeration subdomain-finder subdomain-scanner
Last synced: 24 Dec 2025
https://github.com/Stratus-Security/Subdominator
The Internets #1 Subdomain Takeover Tool
bug-bounty infosec penetration-testing penetration-testing-tools pentesting security subdomain subdomain-takeover
Last synced: 27 Sep 2025
https://github.com/shadow-workers/shadow-workers
Shadow Workers is a free and open source C2 and proxy designed for penetration testers to help in the exploitation of XSS and malicious Service Workers (SW)
c2 penetration-testing-tools proxy service-worker xss-exploitation
Last synced: 02 Apr 2025
https://github.com/yakuza8/peniot
PENIOT: Penetration Testing Tool for IoT
amqp ble coap hacking hacking-tools iot iot-hacking mqtt penetration-testing penetration-testing-framework penetration-testing-tools python python2-7 security security-attacks
Last synced: 07 May 2025
https://github.com/putsi/privatecollaborator
A script for installing private Burp Collaborator with free Let's Encrypt SSL-certificate
bugbounty burp burpsuite burpsuitepro collaborator penetration-testing penetration-testing-tools
Last synced: 12 May 2025
https://github.com/mhmdiaa/chronos
Wayback Machine OSINT Framework
infosec mapping penetration-testing penetration-testing-tools pentesting recon reconnaissance security security-tools wayback-machine web-application-security wordlist wordlist-generator wordlists
Last synced: 23 Aug 2025
https://github.com/michaeldim02/narthex
Modular personalized dictionary generator.
c dictionary dictionary-attack hacking password-attack password-cracking password-recovery penetration-testing penetration-testing-tools shell shell-script unix
Last synced: 27 Oct 2025
https://github.com/iomoath/SharpStrike
A Post exploitation tool written in C# uses either CIM or WMI to query remote systems.
cybersecurity penetration-testing penetration-testing-tools redteam-tools redteaming winrm wmi wsman
Last synced: 11 Jul 2025
https://github.com/InfosecHouse/InfosecHouse
Tools & Resources for Cyber Security Operations
bugbounty bugbounty-tool defensive-security hacking incident-response infosec infosec-reference infosectools offensive-security penetration-testing-tools pentest-tools resources
Last synced: 20 Apr 2025
https://github.com/MichaelDim02/Narthex
Modular personalized dictionary generator.
c dictionary dictionary-attack hacking password-attack password-cracking password-recovery penetration-testing penetration-testing-tools shell shell-script unix
Last synced: 11 Jul 2025
https://github.com/trickest/dsieve
Filter and enrich a list of subdomains by level
bugbounty enumeration infosec infosectools penetration-testing penetration-testing-tools pentesting pentesting-tools security subdomain subdomain-enumeration subdomain-finder subdomain-scanner
Last synced: 24 Dec 2025
https://github.com/the-z-labs/bof-launcher
Beacon Object File (BOF) launcher - library for executing BOF files in C/C++/Zig applications
adversarial-attacks beacon beaconobjectfile bof cobalt cobalt-strike coff cybersecurity elf execution in-memory penetration-testing-tools post-exploitation red-team security-tools
Last synced: 04 Apr 2025
https://github.com/The-Z-Labs/bof-launcher
Beacon Object File (BOF) launcher - library for executing BOF files in C/C++/Zig applications
adversarial-attacks beacon beaconobjectfile bof cobalt cobalt-strike coff cybersecurity elf execution in-memory penetration-testing-tools post-exploitation red-team security-tools
Last synced: 05 Apr 2025
https://github.com/softrams/bulwark
An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.
angular application-security appsec blue-team bugbounty express nodejs penetration-testing-tools pentesting red-team security-tool security-tools typeorm typescript vulnerability-assessment vulnerability-management vulnerability-report vulnerability-research webappsec
Last synced: 12 Jul 2025
https://github.com/trickest/mkpath
Make URL path combinations using a wordlist
bugbountytips directory-bruteforce enumeration fuzzing penetration-testing penetration-testing-tools pentesting pentesting-tools recon reconnaissance security webappsecurity
Last synced: 24 Dec 2025
https://github.com/viralmaniar/xposedornot
XposedOrNot (XoN) tool is to search an aggregated repository of xposed passwords comprising of ~850 million real time passwords. Usage of such compromised passwords is detrimental to individual account security.
breach-compilation credentials-gathering intelligence-gathering osint osinttool password-breach password-leak penetration-testing-tools recon reconnaissance
Last synced: 24 Apr 2025
https://github.com/Viralmaniar/XposedOrNot
XposedOrNot (XoN) tool is to search an aggregated repository of xposed passwords comprising of ~850 million real time passwords. Usage of such compromised passwords is detrimental to individual account security.
breach-compilation credentials-gathering intelligence-gathering osint osinttool password-breach password-leak penetration-testing-tools recon reconnaissance
Last synced: 11 Jul 2025
https://github.com/t3l3machus/synergy-httpx
A Python http(s) server designed to assist in red teaming activities such as receiving intercepted data via POST requests and serving content dynamically (e.g. payloads).
arduino attiny85 hacking hacking-tools offensive-security penetration-testing-tools pentesting red-teaming redteam t3l3machus
Last synced: 12 Apr 2025
https://github.com/iomoath/SharpSpray
Active Directory password spraying tool. Auto fetches user list and avoids potential lockouts.
penetration-testing penetration-testing-tools
Last synced: 11 Jul 2025
https://github.com/hueristiq/xsubfind3r
A command-line utility designed to discover subdomains for a given domain in a simple, efficient way. It works by gathering information from a variety of passive sources, meaning it doesn't interact directly with the target but instead gathers data that is already publicly available.
asset-discovery bug-bounty bug-bounty-tools docker docker-image ethical-hacking ethical-hacking-tools go golang osint osint-tools penetration-testing penetration-testing-tools reconnaissance red-team-tools red-teaming subdomain-discovery subdomain-enumeration
Last synced: 06 Apr 2025
https://github.com/vxcontrol/pentagi
✨ Fully autonomous AI Agents system capable of performing complex penetration testing tasks
ai-agents ai-security-tool anthropic autonomous-agents golang gpt graphql multi-agent-system offensive-security open-source openai penetration-testing penetration-testing-tools react security-automation security-testing security-tools self-hosted
Last synced: 06 Jan 2026
https://github.com/eonraider/bca-phantom
A multi-platform HTTP(S) Reverse Shell Server and Client in Python 3
http-client http-server network-programming penetration-testing-tools red-teaming reverse-shell security-tools
Last synced: 11 Apr 2025
https://github.com/kostas-pa/LFITester
LFITester is a Python3 program that automates the detection and exploitation of Local File Inclusion (LFI) vulnerabilities on a server.
bugbounty crawler cybersecurity enumeration exploitation fuzzing hacking lfi lfi-detection lfi-exploitation lfi-vulnerability penetration-testing penetration-testing-tools pentest-tool pentesting python web-hacking webhacking
Last synced: 12 Jul 2025
https://github.com/hueristiq/xcrawl3r
A command-line interface (CLI) based utility to recursively crawl webpages. It is designed to systematically browse webpages' URLs and follow links to discover linked webpages' URLs.
bug-bounty bug-bounty-tools contentdiscovery crawler ethical-hacking ethical-hacking-tools go golang penetration-testing penetration-testing-tools reconnaissance red-teaming red-teaming-tools web-security
Last synced: 06 Apr 2025
https://github.com/the-viper-one/activedirectoryattacktool
ADAT is a small tool used to assist CTF players and Penetration testers with easy commands to run against an Active Directory Domain Controller. This tool is is best utilized using a set of known credentials against the host.
active-directory ctf htb oscp penetration-testing-tools red-team security-tools tryhackme
Last synced: 12 Sep 2025
https://github.com/1n3/attacksurfacemanagement
Discover the attack surface and prioritize risks with our continuous Attack Surface Management (ASM) platform - Sn1per Professional #pentest #redteam #bugbounty
attack-surface attacksurface automated bugbounty bugbounty-platform bugbounty-tool cybersecurity hacking-tool hacking-tools osint penetration-testing penetration-testing-framework penetration-testing-tools reconnaissance redteam-tools vulnerability-management vulnerability-scanners
Last synced: 07 May 2025
https://github.com/paulveillard/cybersecurity-dark-web
A collection of awesome software, libraries, learning tutorials, documents, books & technical resources and cool stuff about dark web.
cybercrime-prevention dark-network dark-web dark-websites darknet darknet-python darknet-yolo darkweb deep-web deepweb ethical-artificial-intelligence ethical-hacker ethical-hacking penetration penetration-test penetration-testing penetration-testing-tools
Last synced: 28 Mar 2025
https://github.com/packet-batch/program
An application that utilizes fast AF_XDP Linux sockets to generate and send network packets. Used for penetration testing including Denial of Service (DoS) and network monitoring. Made by @gamemann!
af-xdp ddos ddos-attack-tools ddos-tool dos dos-attack-tool dos-tool hack-tool linux networking packet packet-generator penetration penetration-testing penetration-testing-tools pentest pentest-tool pentesting pktgen xdp
Last synced: 01 Mar 2025
https://github.com/1N3/AttackSurfaceManagement
Discover the attack surface and prioritize risks with our continuous Attack Surface Management (ASM) platform - Sn1per Professional #pentest #redteam #bugbounty
attack-surface attacksurface automated bugbounty bugbounty-platform bugbounty-tool cybersecurity hacking-tool hacking-tools osint penetration-testing penetration-testing-framework penetration-testing-tools reconnaissance redteam-tools vulnerability-management vulnerability-scanners
Last synced: 12 Jul 2025
https://github.com/i5nipe/nipejs
Simplify your life with leak detection in JavaScript. NipeJS streamlines the use of regex, making it effortless to uncover potential leaks.
bug-bounty bugbounty bugbounty-tool infosec penetration-testing-tools pentesting
Last synced: 11 Jul 2025
https://github.com/paulveillard/cybersecurity-penetration-testing
An ongoing & curated collection of awesome software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidelines and important resources about Penetration Testing in Cybersecurity.
cybersecurity cybersecurity-education penetration penetration-test-framework penetration-tester penetration-testing penetration-testing-tools pentest-scripts pentest-tool pentester pentesting pentesting-networks pentesting-windows threat-intelligence
Last synced: 10 Jul 2025
https://github.com/himazawa/bento
Bento Toolkit is a minimal fedora-based container for penetration tests and CTF with the sweet addition of GUI applications.
ctf ctf-tools docker minimal penetration penetration-testing-tools security-vulnerability
Last synced: 11 Jul 2025
https://github.com/dotnetrussell/minerinthemiddle
This application was created as a POC for how to scan your local network traffic for HTTP requests and then inject various javascript cryptocurrency miners into the response payloads
bug-bounty bugbounty hacking hacking-tool info-sec information-security infosec infosectools injection miner monero penetration-testing penetration-testing-tools python red-team
Last synced: 24 Oct 2025
https://github.com/gnothiseautonlw/burp-shell-fwd-lfi
A Burp Suite plugin/extension that offers a shell in Burp. Both useful for OS Command injection and LFI exploration
burp-extensions burp-plugin burpsuite burpsuite-extender penetration-testing penetration-testing-tools pentesting security security-tools
Last synced: 11 Jul 2025
https://github.com/IngoKl/HTTPUploadExfil
A simple HTTP server for delivering and exfiltrating files/data during, for example, CTFs.
ctf ctf-tools golang http http-server oscp-tools penetration-testing-tools pentest-tool pentesting security-tools
Last synced: 11 Jul 2025
https://github.com/r3dhulk/fsociety
fsociety is a penetration toolkit inspired from MR. ROBOT
blackhat-python ethical ethical-hacking ethical-hacking-tools fsociety fsociety-hacking hacking hacking-tool hacking-tools mr-robot mrrobot offensive-python offensive-scripts offensive-security offensivepython offensivesecurity penetration-testing penetration-testing-framework penetration-testing-tools pythonforethicalhacking
Last synced: 31 Jul 2025
https://github.com/Whomrx666/Wifi-crackerX
Wifi-crackerX is a tool for hacking a WPS/WPA/WPA2 Networks
hacking-tools kali-linux linux penetration-testing-tools root termux wifi-crackerx wifi-hacking wifi-security
Last synced: 18 Jul 2025
https://github.com/elliottophellia/aizawa
Aizawa is a command-line webshell designed to execute commands through HTTP header
1kb-webshell bypass bypass-disable-function bypass-webshell command-line command-line-tool hacking hacktoberfest mini-shell pantest pantesting penetration-testing-tools php php-backdoor php-webshell tiny-shell web-security webshell webshell-bypass-403 webshells
Last synced: 17 Mar 2025
https://github.com/whomrx666/wifi-crackerx
Wifi-crackerX is a tool for hacking a WPS/WPA/WPA2 Networks
hacking-tools kali-linux linux penetration-testing-tools root termux wifi-crackerx wifi-hacking wifi-security
Last synced: 08 Oct 2025
https://github.com/datalux/instagram-weak-encryption
Get the length of the Instagram encrypted password
encryption facebook instagram padding penetration-testing-tools vulnerability
Last synced: 07 Oct 2025
https://github.com/netlas-io/netlas-scripts
Several scripts are based on the Netlas.io search engine. They will allow you to carry out the reconnaissance phase before the pen test in a semi-automatic mode: collect all the domains and IP addresses associated with the target and save the responses received after contacting these hosts in HTML format. Over time, new scripts will appear here.
netlas osint penetration-testing-tools security-tools
Last synced: 25 Aug 2025
https://github.com/jonaslejon/lolcrawler
Headless web crawler for bugbounty and penetration-testing/redteaming
bugbounty crawler docker penetration-testing penetration-testing-tools redteam redteam-tools redteaming
Last synced: 12 Jul 2025
https://github.com/scipag/websocket_fuzzer
Simple WebSocket fuzzer
fuzzing penetration-testing-tools pentest-script pentest-tool security-automation security-scanner security-tools websocket-fuzzing
Last synced: 20 Jun 2025
https://github.com/ivan-sincek/phishing-mobile-app
Phishing mobile application made in React Native for both Android and iOS devices.
android bug-bounty ethical-hacking ios javascript mobile-application mobile-penetration-testing offensive-security penetration-testing-tools phishing react-native red-team-engagement security
Last synced: 15 Apr 2025
https://github.com/r0x4r/snetra
A Python based scanner uses shodan-internetdb to scan the IP.
bugbounty penetration-testing penetration-testing-tools python3 shodan
Last synced: 28 Jul 2025
https://github.com/slendidev/picoduck
A cheap "bad" USB using a Raspberry Pi Pico running on Lua.
bad-usb keyboard keyboard-emulation lua lua-script mouse mouse-emulation penetration-testing penetration-testing-tools pentest raspberry-pi raspberry-pi-pico rp2040 rubber-ducky rubberducky trolling usb-hid
Last synced: 30 Apr 2025
https://github.com/R0X4R/snetra
A Python based scanner uses shodan-internetdb to scan the IP.
bugbounty penetration-testing penetration-testing-tools python3 shodan
Last synced: 12 Jul 2025
https://github.com/alechilczenko/Deep-Inside
Command line tool that allows you to explore IoT devices by using Shodan API.
command-line-tool hacking hacking-tool internet-of-things iot linux penetration-testing penetration-testing-tools pentesting python3 scanner script scripting shodan shodan-api shodan-cli
Last synced: 07 Apr 2025
https://github.com/codytolene/red-portals
An educational repository focused on Evil Portals—rogue captive portals designed to mimic legitimate login systems. This project provides insights into their functionality and potential exploitation techniques, helping security researchers, penetration testers, and ethical hackers identify and defend against network vulnerabilities.
access-point ap evil evil-portals penetration penetration-testing penetration-testing-tools pentesting portal portals testing
Last synced: 17 Jun 2025
https://github.com/eonraider/bca-reaper
Log keystrokes, take screenshots and grab system information from a target host and exfiltrate to Discord and Google Forms.
hacking-tools keylogger penetration-testing-tools screen-capture
Last synced: 11 Apr 2025
https://github.com/johnsaigle/scary-strings
Collection of wordlists containing dangerous function calls in many languages
application-security appsec bug-bounty bugbounty go hacking infosec penetration-testing penetration-testing-tools pentesting php rust security security-tools source-code-analysis static-analysis white-box-testing wordlist wordlists
Last synced: 14 Apr 2025
https://github.com/gh0x0st/raven
A lightweight http file upload service used for penetration testing and incident response.
file-upload http-server incident-response kali-linux kali-linux-tools penetration-testing penetration-testing-tools python3-script security-tools
Last synced: 10 Jul 2025
https://github.com/elliottophellia/ophellia
A cutting-edge PHP 7.4+ webshell designed for advanced penetration testing.
file-manager filemanager hacking hacktoberfest infosec mini-shell penetration-testing penetration-testing-tools pentest pentesting php php-backdoor php-webshell web-security webshell
Last synced: 12 Apr 2025