Ecosyste.ms: Awesome

An open API service indexing awesome lists of open source software.

Awesome Lists | Featured Topics | Projects

Projects in Awesome Lists tagged with pentest-tool

A curated list of projects in awesome lists tagged with pentest-tool .

https://github.com/t94j0/airmaster

Use ExpiredDomains.net and BlueCoat to find useful domains for red team.

engagements pentest-tool pentesting red-team security security-tools

Last synced: 19 Dec 2024

https://github.com/DrPython3/MailRipV2

Improved SMTP Checker / SMTP Cracker with proxy-support, inbox test and many more features.

checker cracker pentest pentest-tool pentesting pentesting-tools python-script python3 security-audit smtp smtp-checker smtp-cracker smtplib

Last synced: 21 Nov 2024

https://github.com/coffeehb/struts2_check

一个用于识别目标网站是否采用Struts2框架开发的工具demo

pentest-tool python27 struts2

Last synced: 22 Dec 2024

https://github.com/giovanifss/Gitmails

An information gathering tool to collect git commit emails in version control host services

bitbucket emails git github gitlab harvester information-gathering pentest-tool

Last synced: 21 Nov 2024

https://github.com/xfiftyone/xTools

xTools,一个辅助小工具

fofa fofa-search hunter nuclei pentest-tool quake

Last synced: 21 Nov 2024

https://github.com/01rabbit/PAKURI

PAKURI has been merged with Python and launched as a new project, PAKURI-THON.

arsenal exploitation faraday kali metasploit openvas penetration-testing pentest-tool pentesting-tools scanning vulnerabilities

Last synced: 21 Nov 2024

https://github.com/azathothas/toolpacks

📦 Largest Collection of Multi-Platform (Android|Linux|Windows) Pre-Compiled (+ UPXed) Static Binaries (incl. Build Scripts) :: https://bin.ajam.dev

aarch64 android arm64 binary bug-bounty bugbounty executable golang linux musl pentest-tool pre-compiled rust static static-binary statically-linked tools upx windows x86-64

Last synced: 29 Dec 2024

https://github.com/ariary/QueenSono

Golang binary for data exfiltration with ICMP protocol (+ ICMP bindshell, http over ICMP tunneling, ...)

bindshell data-exfiltration golang icmp pentest pentest-tool tunneling

Last synced: 21 Nov 2024

https://github.com/ariary/queensono

Golang binary for data exfiltration with ICMP protocol (+ ICMP bindshell, http over ICMP tunneling, ...)

bindshell data-exfiltration golang icmp pentest pentest-tool tunneling

Last synced: 11 Nov 2024

https://github.com/viralmaniar/peekaboo

PeekABoo tool can be used during internal penetration testing when a user needs to enable Remote Desktop on the targeted machine. It uses PowerShell remoting to perform this task. Note: Remote desktop is disabled by default on all Windows operating systems.

bluekeep infrastructure-testing internal-pentest network-pentest pentest pentest-tool pentest-tools pentesters pentesting powershell remote-desktop security security-tools

Last synced: 10 Nov 2024

https://github.com/EnnioX/IPWarden

IPWarden(守望者)是一个IP资产风险巡查工具。持续发现系统、Web两个维度的资产和安全风险。所有扫描结果可通过API访问json数据,方便二次开发或数据整理。适合甲方安全人员用于监控管理公网/内网IP资产风险暴露面。

ipwarden pentest-tool poc python scan security-tools

Last synced: 21 Nov 2024

https://github.com/cytopia/smtp-user-enum

SMTP user enumeration via VRFY, EXPN and RCPT with clever timeout, retry and reconnect functionality.

cytopia-sec enumeration penetration-testing pentest pentest-tool pentesting pentesting-python pentesting-tools smtp smtp-server smtp-user-enumeration user-enumeration

Last synced: 30 Dec 2024

https://github.com/SKVNDR/FastDork

⚡Chrome extension allows you to create lists of Google and Github dork to open multiple tabs with one click, import "scope/out of scope" from #HackerOne #Bugcrowd #Intigriti ...

bugbounty bugcrowd chrome cybersecurity dork extension fastdork google hackerone intigriti pentest-tool

Last synced: 21 Nov 2024

https://github.com/mytechnotalent/turbo-attack

A turbo traffic generator pentesting tool to generate random traffic with random MAC and IP addresses in addition to random sequence numbers to a particular IP and port.

cyber-security cyberattack cybersecurity ddos ddos-attacks ddos-tool go golang hack hacking hacking-tool hacking-tools penetration-testing pentest pentest-tool pentesting pentesting-tools redteam redteam-tools redteaming

Last synced: 21 Nov 2024

https://github.com/ariary/notionterm

🖥️📖 Embed reverse shell in Notion pages

c2c infosec notion notion-api pentest pentest-tool redteam reverse-shell webshell

Last synced: 11 Nov 2024

https://github.com/ariary/volana

🌒 Shell command obfuscation to avoid detection systems

exploitation infosec obfuscator pentest pentest-tool redteam security shell-obfuscate

Last synced: 11 Nov 2024

https://github.com/sule01u/AutorizePro

🧿 AutorizePro是一款越权检测 Burp 插件,通过增加AI分析模块 && 进一步优化检测逻辑,大幅降低误报率,提升越权漏洞检出效率。 [ AutorizePro is a authorization enforcement detection extension for burp suite. By adding AI analysis modules, it significantly reduces the false positive rate and improves the efficiency of vulnerability detection.

ai authorization bounty-hunters bounty-hunting-tools broken-access-control bugbounty burp-extensions burpsuite llm pentest-tool pentesting sdlc-tools security-tools unauthorized unauthorized-access-tool vulnerability-detection

Last synced: 12 Dec 2024

https://github.com/adityatelange/bhhb

Burp HTTP history browser (BHHB) - A tool to view HTTP history exported from Burp Suite Community Edition

burpsuite burpsuite-tools http-history offline pentest-tool

Last synced: 16 Dec 2024

https://github.com/viralmaniar/hivejack

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM, SECURITY and SAM hives and once copied to the attacker machines provides option to delete these files to clear the trace.

infrastructure-pentest intenalpentest internal-pentest lateral-movement pentest-tool pentesting reghives samdump secretdump system-hives

Last synced: 10 Nov 2024

https://github.com/Viralmaniar/HiveJack

This tool can be used during internal penetration testing to dump Windows credentials from an already-compromised host. It allows one to dump SYSTEM, SECURITY and SAM hives and once copied to the attacker machines provides option to delete these files to clear the trace.

infrastructure-pentest intenalpentest internal-pentest lateral-movement pentest-tool pentesting reghives samdump secretdump system-hives

Last synced: 21 Nov 2024

https://github.com/lefayjey/sharpsqlpwn

C# tool to identify and exploit weaknesses within MSSQL instances in Active Directory environments

active-directory adsecurity automation exploitation hacking mssql pentest-tool pentesting redteaming

Last synced: 02 Dec 2024

https://github.com/oppsec/tomcter

😹 Tomcter is a python tool developed to bruteforce Apache Tomcat manager login with default credentials.

apache apache-tomcat bruteforce docker hacktoberfest login pentest pentest-tool python python3 tomcat tool

Last synced: 16 Nov 2024

https://github.com/ddddddo/packemon

Packet monster (っ‘-’)╮=͟͟͞͞◒ ヽ( '-'ヽ) TUI tool for sending packets of arbitrary input and monitoring packets on any network interfaces (default: eth0).

ebpf linux network networking packet packet-analyzer packet-generator packet-monitoring penetration-testing pentest-tool protocol routing-protocols

Last synced: 01 Jan 2025

https://github.com/naltun/eyes.sh

Let's you perform domain/IP information gathering... in BASH! Wasn't it esr who said "With enough eyeballs, all your IP info are belong to us?"

information-gathering penetration-testing pentest-tool pentesting

Last synced: 02 Nov 2024

https://github.com/kostas-pa/LFITester

LFITester is a Python3 program that automates the detection and exploitation of Local File Inclusion (LFI) vulnerabilities on a server.

bugbounty crawler cybersecurity enumeration exploitation fuzzing hacking lfi lfi-detection lfi-exploitation lfi-vulnerability penetration-testing penetration-testing-tools pentest-tool pentesting python web-hacking webhacking

Last synced: 21 Nov 2024

https://github.com/PinkP4nther/EroDir

A fast web directory/file enumeration tool written in Rust

dirbrute enumeration penetration-testing pentest-tool rust rust-lang scanner web-application

Last synced: 21 Nov 2024

https://github.com/viralmaniar/in-spectre-meltdown

This tool allows to check speculative execution side-channel attacks that affect many modern processors and operating systems designs. CVE-2017-5754 (Meltdown) and CVE-2017-5715 (Spectre) allows unprivileged processes to steal secrets from privileged processes. These attacks present 3 different ways of attacking data protection measures on CPUs enabling attackers to read data they shouldn't be able to. This tool is originally based on Microsoft: https://support.microsoft.com/en-us/help/4073119/protect-against-speculative-execution-side-channel-vulnerabilities-in

cpu cve-2017-5715 cve-2017-5754 hacking meltdown penetration-testing pentest-tool spectre tool vulnerability

Last synced: 10 Nov 2024

https://github.com/elddy/Nim-SMBExec

SMBExec implementation in Nim - SMBv2 using NTLM Authentication with Pass-The-Hash technique

nim nim-lang ntlm pass-the-hash pentest-tool red-teaming smb windows

Last synced: 21 Nov 2024

https://github.com/zha0gongz1/three-eyedraven

内网探测工具(Internal network detection tool that not contain any exploit code)

dcom detection-network enumeration-tool go netbios pentest-tool

Last synced: 09 Nov 2024

https://github.com/k8gege/porttran

PortTran (.NET端口转发工具,支持任意权限)

hacking lcx pentest-tool portforward porttran security tunnel

Last synced: 13 Nov 2024

https://github.com/kelvinben/autoredtools

AutoRedTools是一款轻量级一站式自动下载/自动更新常用开源软件的工具,主要帮助安全从业者/安全开发人员快速进行环境搭建以及常用软件的更新,节约软件的更新或者安 装的时间,从而提升生产效率或工作效率。

developer-tools devtools efficiency efficiency-tool pentest-tool pentesting redteam-tools security security-tools toolset toolsk

Last synced: 09 Nov 2024

https://github.com/IngoKl/HTTPUploadExfil

A simple HTTP server for delivering and exfiltrating files/data during, for example, CTFs.

ctf ctf-tools golang http http-server oscp-tools penetration-testing-tools pentest-tool pentesting security-tools

Last synced: 21 Nov 2024

https://github.com/paulveillard/cybersecurity-penetration-testing

An ongoing & curated collection of awesome software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidelines and important resources about Penetration Testing in Cybersecurity.

cybersecurity cybersecurity-education penetration penetration-test-framework penetration-tester penetration-testing penetration-testing-tools pentest-scripts pentest-tool pentester pentesting pentesting-networks pentesting-windows threat-intelligence

Last synced: 29 Dec 2024

https://github.com/sebastian-mora/AWS-Loot

Pull secrets from an AWS environment

aws pentest-tool pentesting red-team security security-tools

Last synced: 21 Nov 2024

https://github.com/p0dalirius/owabrute

Hydra wrapper for bruteforcing Microsoft Outlook Web Application.

hydra outlook pentest pentest-tool tool

Last synced: 30 Dec 2024

https://github.com/aziz0x48/xsmtp

xSMTP 🦟 Lightning fast, multithreaded smtp scanner targeting open-relay and unsecured servers in multiple network ranges.

bot crawler exploit exploit-scanner multithreading networking pentest-tool pentesting pentesting-tools portscan portscanner python python-exploits scanner-web security security-tools smtp smtp-cracker

Last synced: 16 Dec 2024

https://github.com/ronin-rb/ronin-vulns

Tests URLs for Local File Inclusion (LFI), Remote File Inclusion (RFI), SQL injection (SQLi), and Cross Site Scripting (XSS), Server Side Template Injection (SSTI), and Open Redirects.

hacktoberfest lfi open-redirect pentest-tool pentesting rfi ronin-rb ruby security sql-injection sqli ssti vulnerability-detection vulnerability-scanners web-security xss

Last synced: 04 Jan 2025

https://github.com/venerasf/Venera

A modular exploitation framework extensible with Lua

exploit lua pentest pentest-tool qa-automation scanner security security-tools testing venera

Last synced: 26 Sep 2024

https://github.com/christophetd/nmap-nse-info

Browse and search through nmap's NSE scripts.

nmap nmap-scan-script nse-script nsescript pentest-tool pentesting

Last synced: 07 Nov 2024

https://github.com/naltun/eyes

👀 🖥️ Golang rewrite of eyes.sh. Let's you perform domain/IP address information gathering. Wasn't it esr who said "With enough eyeballs, all your IP info are belong to us?" 🔍 🕵️

information-gathering penetration-testing pentest-tool pentesting reconnaissance

Last synced: 09 Nov 2024

https://github.com/giovanifss/Dumb

Dumain Bruteforcer - a fast and flexible domain bruteforcer

bruteforce dns domain haskell pentest-tool pentesting subdomain subdomain-brute

Last synced: 26 Sep 2024

https://github.com/leeyangee/pylineshell

基于Python3的Shell Payload库,针对于渗透测试中拿到exec、pickle等命令执行点后不落地内存加载Py代码、无落地直接运行Py项目、无回显不出网等场景

cyber-security cybersecurity penetration-testing pentest-tool pentesting python python3 script shellcode

Last synced: 08 Nov 2024

https://github.com/k8gege/KaliLadon

Ladon for Linux (Kali), Large Network Penetration Scanner, vulnerability / exploit / detection / MS17010 / password

bruteforce detection exploit hacking hacking-tool kali ladon ms17010 pentest-tool poc portscanner scanner security-tools

Last synced: 21 Nov 2024

https://github.com/yutianqaq/supernova_cn

Supernova 的中文版和扩展了一些加密方式(ROT, XOR, RC4, AES, CHACHA20, B64XOR, B64RC4, B64AES, B64CHACHA20)

aes chacha20 decryption encryption evasion go golang pentest-tool rc4 redteam shellcode

Last synced: 08 Nov 2024

https://github.com/k8gege/kaliladon

Ladon for Linux (Kali), Large Network Penetration Scanner, vulnerability / exploit / detection / MS17010 / password

bruteforce detection exploit hacking hacking-tool kali ladon ms17010 pentest-tool poc portscanner scanner security-tools

Last synced: 13 Nov 2024

https://github.com/DeepakPawar95/cswsh

A command-line tool for Cross-Site WebSocket Hijacking

pentest-tool security-tools websocket

Last synced: 21 Nov 2024

https://github.com/lambdahuang/FlashRoute

🚀 Takes minutes to explore the topology of all routable /24 prefixes in IPv4 address space. Now supports IPv6 scan!

efficiency internet ipv4 ipv6-compatibility network-scanner network-tools network-topology pentest-tool probe topology traceroute

Last synced: 05 Nov 2024

https://github.com/gamemann/packet-sequence

A pen-test/DoS tool that can be used to send single or multiple packets in sequences with a lot of packet customization.

denial-of-service dos monitor multithreaded network packet-generator packet-sequence pcktflood pcktgen pentest pentest-scripts pentest-tool pentesting pentesting-tools security-tools

Last synced: 27 Oct 2024

https://github.com/caustickirbyz/spraycannon

Fast multithreaded multiplatform password spraying tool designed for easy use. Supports webhooks, jitter, delay, files, rotation, backend database

adfs crystal-lang o365 o365spray owa password-spray password-spraying password-spraying-attacks passwordspray passwordspraying pentest-tool pentesting pentesting-tools red-team security-tools

Last synced: 01 Nov 2024

https://github.com/mkbeh/pyshella-toolkit

Hacking toolkit for BTC/forks peers: peers-scanner | jsonrpc-searcher | jsonrpc-bruter | coins-withdrawal

bitcoin bitcoin-forks blockchain bruteforce hacking pentest-tool scan-tool toolkit

Last synced: 02 Dec 2024

https://github.com/ph4ntonn/Behold3r

👻Behold3r -- 收集指定网站的子域名,并可监控指定网站的子域名更新情况,发送变更报告至指定邮箱

cybersecurity information pentest-tool pentesting python redis redteam security-tools subdomain subdomain-scanner

Last synced: 21 Nov 2024

https://github.com/k8gege/phpstudydoor

PhpStudy 2016 & 2018 BackDoor Exploit

backdoor exploit hacking k8cscan pentest pentest-tool phpstudy security

Last synced: 13 Nov 2024

https://github.com/jaykali/pentest-handbook

This is a guide for Penetration Testers how to use Penetration Testing tools and their advanced used. Need everyone's help to make it batter. Please send Pool Request to keep this updated for the community.

command-line-tool ethical-hacking hacking hacking-tool hacking-tools hacktoberfest hacktoberfest-accepted linuxcommand notes penetration-testing pentest-tool pentesting

Last synced: 16 Nov 2024

https://github.com/kulkansecurity/gitxray

A multifaceted security tool which leverages Public GitHub REST APIs for OSINT, Forensics, Pentesting and more.

attackers disclosure github information osint osint-python osint-resources osint-tool pentest pentest-tool pentesting pentesting-tools security supply-chain

Last synced: 27 Dec 2024

https://github.com/Myskiv-Ivan/SecTools

List of tools for SecDevOps, vulnerability analysis, network scanning

appsec devops devsecops hacking osint pentest-tool pentesting scanner-web secdevops security security-tools vulnerability-scanners

Last synced: 29 Nov 2024

https://github.com/blackhatethicalhacking/s3-buckets-aio-pwn

An AIO Tool to check for Vulnerable Amazon S3 Buckets as part of Bug Bounty, the uniqueness of this tool is that it can take a file full of buckets, and check all of them with various attack scenarios if they are vulnerable

bugbounty hacking penetration-testing pentest-tool pentesting redteam s3-bucket

Last synced: 05 Nov 2024

https://github.com/gamemann/packet-flooder

A packet flooding/generating program I made that supports TCP, UDP, and ICMP packets. Includes functionality to change characteristics per packet and is also multithreaded.

c denial-of-service dos dos-attack fast flood flooding multithreading network packet packet-flood packet-flooder packet-generator packetflood pcktflood pcktgen pentest pentest-tool pentesting security

Last synced: 27 Oct 2024

https://github.com/aldo-moreno-leon/ORtester

Open Redirect scanner - (out of date)

bugbounty pentest-tool

Last synced: 21 Nov 2024

https://github.com/juffalow/pentest-tool-lite

Test your page against basic security, html, wordpress, ... check lists

node pentest-tool pentesting typescript web-security

Last synced: 02 Jan 2025

https://github.com/ariary/tacos

🌮 INTERACTIVE reverse shell everywhere! (Particularly digestible with socat multi-handler listener)

ctf golang infosec interactive pentest pentest-tool reverse-shell security socat

Last synced: 11 Nov 2024

https://github.com/shosta/androsectest

From this app, Connect a Phone, Extract any app from It, Decompile, Deobfuscate, Remove Certificate Pinning and Repackage it. Meanwhile, Perform some Static and Dynamic Analysis on It.

android android-security-audit apk docker-container go golang pentest-scripts pentest-tool pentesting

Last synced: 27 Oct 2024

https://github.com/caesarovich/rome-webshell

A powerful and delightful PHP WebShell

pentest-tool pentesting vanilla-javascript webshell webshells

Last synced: 28 Nov 2024

https://github.com/ariary/httpcustomhouse

HTTP request smuggling attack helper/CLI tools to manipulate HTTP packets

bug-bounty burp cli http-client http-request-smuggling infosec learning pentest-tool request-smuggling security websecurity

Last synced: 11 Nov 2024

https://github.com/eikendev/hackenv

Manage and access your Kali Linux or Parrot Security VM from the terminal (SSH support + file sharing, especially convenient during CTFs, Hack The Box, etc.) :rocket::wrench:

cli ctf ctf-scripts ctf-tools hacking hackthebox kali kali-linux kali-setup kalilinux libvirt parrot-sec parrotsec penetration-testing pentest-scripts pentest-tool pentest-tools pentesting security security-tools

Last synced: 09 Nov 2024

https://github.com/zidansec/subscan

Subscan is a simple tool for subdomain scanner, it can scan subdomains fast.

cyber-security hacktool information-security linux-tools osint osint-tool pentest pentest-tool security subdomain-scanner

Last synced: 29 Oct 2024

https://github.com/nof0rte/slack-slurp

Pentesting post exploitation tool for slack

go golang pentest-tool pentesting postexplotation slack

Last synced: 02 Nov 2024

https://github.com/PadishahIII/SecretScraper

SecretScraper is a web scraper that crawl through target websites, scrape from http response and extract secret information via regular expression.

crawler cyper hyperscan pentest-tool pentesting python sensitivity-analysis webscraper

Last synced: 04 Dec 2024

https://github.com/ariary/domxssfinder

Find sources and sinks in js code that could lead to DOM XSS 🔎💧🚰

bug-bounty dom-xss pentest pentest-tool scanner security web-application-security web-application-security-scanner xss

Last synced: 11 Nov 2024