Full-featured Web Reconnaissance framework written in Python.
PythonGNU General Public License v3.0slowing
257 projects53 categoriesshowing 61–120, page 2 of 5
Sourced fromenaqx/awesome-pentest
Full-featured Web Reconnaissance framework written in Python.
PythonGNU General Public License v3.0slowing
Automated all-in-one operating system command injection and exploitation tool.
PythonOtheractive
Domain name permutation engine for detecting typo squatting, phishing and corporate espionage.
PythonApache License 2.0slowing
Information security resources for pentesting, forensics, and more.
active
UEFI firmware image viewer and editor.
CBSD 2-Clause "Simplified" Licenseactive
Cross-platform post-exploitation HTTP/2 Command and Control server and agent written in Golang.
GoGNU General Public License v3.0slowing
Distro organized around the Penetration Testing Execution Standard (PTES), providing a curated collection of utilities that omits less frequently used utilities.
Pythonslowing
Awesome resources, tools, and other shiny things for cybersecurity blue teams.
slowing
Network forensic analysis framework.
PythonOtherslowing
Flexible and powerful reverse proxy with real-time two-factor authentication.
GoGNU General Public License v3.0active
Post-exploitation and adversary emulation framework with PowerShell, Python, and C# agents.
PowerShellBSD 3-Clause "New" or "Revised" Licenseactive
Automated mass exploiter, which collects target by employing the Shodan.io API and programmatically chooses Metasploit exploit modules based on the Shodan query.
PythonGNU General Public License v3.0dormant
Fast parameter analysis and XSS scanner.
RustMIT Licenseactive
Toolset for raw Kerberos interaction and abuses.
C#Otheractive
Web application attack and audit framework.
Pythondormant
Link-Local Multicast Name Resolution (LLMNR), NBT-NS, and mDNS poisoner.
PythonGNU General Public License v3.0dormantarchived
Social media phishing framework that can run on an Android phone or in a Docker container.
CSSBSD 3-Clause "New" or "Revised" Licenseactive
ASP.NET Core application that serves as a collaborative command and control platform for red teamers.
C#GNU General Public License v3.0slowing
Tool for printer security testing capable of IP and USB connectivity, fuzzing, and exploitation of PostScript, PJL, and PCL printer language features.
PythonGNU General Public License v2.0slowing
SSH server & client auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc).
PythonMIT Licenseactive
Curated list of security conferences.
steady
Automatic server-side template injection and Web server takeover tool.
PythonGNU General Public License v3.0slowing
Automatically find and download Web-accessible .git repositories.
ShellMIT Licenseactive
Advanced SQL injection detection and exploitation tool.
PythonMIT Licensesteady
High performance offensive security tool for reconnaissance and vulnerability scanning.
PythonMIT Licensesteady
Tool designed to create an encrypted command and control channel over the DNS protocol, which is an effective tunnel out of almost every network.
PHPBSD 3-Clause "New" or "Revised" Licenseslowing
Shellcode generator for numerous attack vectors, including Microsoft Office macros, PowerShell, HTML applications (HTA), or certutil (using fake certificates).
PythonOtheractive
Punches holes in firewalls and NATs.
CGNU General Public License v3.0steady
Fast and comprehensive TLS/SSL configuration analyzer to help identify security mis-configurations.
PythonGNU Affero General Public License v3.0active
Free online security knowledge library for pentesters and researchers.
PythonMIT Licenseslowing
Automated wireless attack tool.
Pythondormant
Framework for Man-In-The-Middle attacks.
PythonGNU General Public License v3.0dormantarchived
Advanced IT security professional toolkit on Android featuring an integrated Metasploit daemon and MITM capabilities.
JavaGNU General Public License v3.0slowing
Weaponized PHP-based web shell.
PythonGNU General Public License v3.0steady
DNS meta-query spider that enumerates DNS records, and subdomains.
PythonGNU General Public License v3.0dormant
WPA2 Krack attack scripts.
COtherslowing
Open Source Intrusion Prevention System
C++Othersteady
Automate Google Hacking Database scraping.
PythonGNU General Public License v3.0steady
Automatic NoSQL injection and database takeover tool.
PythonGNU General Public License v3.0active
Modular tool for searching through email in a Microsoft Exchange environment, gathering the Global Address List from Outlook Web Access (OWA) and Exchange Web Services (EWS), and more.
PowerShellMIT Licenseslowing
CLI tool to scan GitHub repos/organizations for potential sensitive information leaks.
PythonApache License 2.0steady
DNS enumeration script.
PythonGNU General Public License v2.0active
Windows PowerShell ADIDNS/LLMNR/mDNS/NBNS spoofer/machine-in-the-middle tool.
C#BSD 3-Clause "New" or "Revised" Licensesteady
Open source network stress tool written for Windows.
C#Otherslowingarchived
Detect and bypass web application firewalls and protection systems.
PythonOtherslowing
Lots of pentesting tools are written in Python.
MIT Licenseactive
DoS tool that uses low bandwidth on the attacking side.
PythonMIT Licenseslowing
Unmask server IP addresses hidden behind Cloudflare by searching old database records and detecting misconfigured DNS.
PythonMIT Licenseslowing
Track and alarm about Blue Team activities while providing better usability in long term offensive operations.
PythonBSD 3-Clause "New" or "Revised" Licensesteady
Tool to dump a git repository from a website.
PythonMIT Licenseactive
Tool for exploration and tracing of the Windows kernel.
GoOtheractive
Semi-automatic OSINT framework and package manager.
RustGNU General Public License v3.0steady
Abuses OSI layer 7 HTTP to create/manage 'zombies' and to conduct different attacks using; GET/POST, multithreading, proxies, origin spoofing methods, cache evasion techniques, etc.
Pythonactive
Framework for rogue Wi-Fi access point attack.
PythonApache License 2.0slowing
Full-featured C2 framework which silently persists on webserver via evil PHP oneliner.
PythonGNU General Public License v3.0slowing
Modular RAT that uses numerous evasion and exfiltration techniques out-of-the-box.
PythonGNU General Public License v3.0dormant
Network (sub)domain discovery and reconnaissance automation tool.
GoGNU General Public License v3.0slowingarchived
Abuses client-side Outlook features to gain a remote shell on a Microsoft Exchange server.
GoOtherslowing
The de-facto language for writing exploits.
steady
Resources for Wi-Fi Pentesting.
Cdormant