Tool written in PowerShell to perform a password spray attack against users of a domain.
PowerShellMIT Licenseslowing
257 projects53 categoriesshowing 121–180, page 3 of 5
Sourced fromenaqx/awesome-pentest
Tool written in PowerShell to perform a password spray attack against users of a domain.
PowerShellMIT Licenseslowing
Handy SMB enumeration tool.
PythonGNU General Public License v3.0steady
Easy to remember reverse shell that should work on most Unix-like systems.
GoMIT Licensesteady
Automatic LFI scanner and exploiter.
PythonGNU General Public License v3.0dormant
Burp Suite extension that, working as a bridge between Burp and Frida, lets you use and manipulate applications' own methods while tampering the traffic exchanged between the applications and their back-end services.
JavaMIT Licensesteady
Tool for automating cracking methodologies through Hashcat.
Pythonactive
Python3 port of the original fierce.pl DNS reconnaissance tool for locating non-contiguous IP space.
PythonGNU General Public License v3.0slowing
Security-focused static analysis for the Phoenix Framework.
ElixirApache License 2.0slowing
Rip web accessible (distributed) version control systems: SVN/GIT/HG/BZR.
PerlGNU General Public License v2.0slowing
Post-process exploits containing executable files targeted for Windows machines to avoid being recognized by antivirus software.
ShellGNU General Public License v3.0slowing
Intercept SSH connections with a proxy; all plaintext passwords and sessions are logged to disk.
COtherdormantarchived
Network sniffer that logs all DNS server replies for use in a passive DNS setup.
Cslowing
Network tool able to send custom TCP/IP packets.
COtherslowing
Python scriptable Reverse Engineering sandbox by Cisco-Talos.
CGNU General Public License v2.0slowingarchived
Textual steganography toolkit that converts any filetype into lists of everyday strings.
PythonMIT Licensedormant
Interactive Collaborative Translation Framework (CTF) exploration tool capable of launching cross-session edit session attacks.
CApache License 2.0dormant
Search email addresses and discover all known breaches that this email has been seen in, and download the breached database if it is publicly available.
Pythonslowing
Python script that uses Empire's RESTful API to automate gaining Domain Admin rights in Active Directory environments.
PythonGNU General Public License v3.0slowing
Scripts to make password spraying attacks against Lync/S4B, Outlook Web Access (OWA) and Office 365 (O365) a lot quicker, less painful and more efficient.
PythonGNU General Public License v3.0dormantarchived
Network attack tool centered around the exploitation of local networks.
PythonOtherdormant
Geolocation OSINT tool.
PythonGNU General Public License v3.0dormant
Full-fledged phishing framework to manage all phishing engagements.
PHPGNU General Public License v3.0slowing
Reflective PE packer for converting native PE files to position-independent shellcode.
GoMIT Licenseslowing
Tool that creates a spoofed certificate of any online website and signs an Executable for AV evasion.
PythonApache License 2.0dormant
Swiss army knife for network sniffing.
COtherslowing
DDoS attack tool for sending forged UDP packets to vulnerable Memcached servers obtained using Shodan API.
Pythondormant
Suite of tools built atop the Binary Analysis Platform (BAP) to heuristically detect CWEs in compiled binaries and firmware.
RustGNU Lesser General Public License v3.0active
Client/server tool for masking command and control and data exfiltration through a normally browsable website, not typical HTTP POST requests.
COtherdormant
Modular framework to take advantage of poor upgrade implementations by injecting fake updates.
Perldormant
Metadata harvester.
PythonGNU General Public License v2.0slowing
Virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, aliases and dynamic default pages.
PythonGNU General Public License v3.0steady
Automated wireless hacking tool.
Pythondormant
Secure multithreaded packet sniffer.
RustGNU General Public License v3.0steady
A collection of fascinating and bizarre Censys Search Queries.
PythonCreative Commons Zero v1.0 Universalactive
Post-exploitation tool for retrieving password hashes and credentials from Windows workstations, servers, and domain controllers.
PowerShellApache License 2.0dormant
Simple HS256 JSON Web Token (JWT) token brute force cracker.
JavaScriptMIT Licenseslowing
OSINT scraping framework that utilizes basic Python webscraping (BeautifulSoup) of PII paywall sites to compile passive information on a target on a ramen noodle budget.
PythonApache License 2.0dormant
Umbrella script that automates numerous useful PowerShell modules to discover security misconfigurations and attempt privilege escalation against Active Directory.
PowerShelldormant
Utility for using websites to perform port scans on your behalf so as not to reveal your own IP.
PythonThe Unlicensedormantarchived
Metasploit-like exploit framework based on routersploit designed to target Industrial Control Systems (ICS), SCADA devices, PLC firmware, and more.
PythonBSD 2-Clause "Simplified" Licenseslowingarchived
Open source, cross-platform interactive disassembler.
C++Othersteady
Shell script to check for simple privilege escalation vectors on UNIX systems.
Shelldormant
Tiny and obfuscated ASP.NET webshell for C# web applications.
PythonGNU General Public License v3.0slowing
Highly configurable DNS proxy for pentesters.
PythonBSD 3-Clause "New" or "Revised" Licenseslowing
Ruby framework for developing and using modules which aid in the penetration testing of WordPress powered websites and systems.
RubyGNU General Public License v3.0dormantarchived
General Python programming.
JuliaOtherdormant
Enterprise-grade web vulnerability scanner with 60+ attack modules, built in Rust for penetration testing and security assessments.
RustOtheractive
GNU/Linux distribution focused on tools useful during Internet of Things (IoT) security assessments.
dormant
Open-source CLI security scanner for agentic AI workflows.
PythonApache License 2.0steady
TLS/SSL enabled Basic Auth credential harvester.
GoMIT Licensedormant
Guide on Android Exploitation and Hacks.
HTMLdormant
Quickly remove duplicates, without changing the order, and without getting OOM on huge wordlists.
C++GNU General Public License v3.0steady
Email recon made fast and easy.
PythonGNU General Public License v3.0dormant
Automated ettercap TCP/IP Hijacking tool.
HTMLdormant
Reverse engineering, traffic generation and fuzzing of communication protocols.
PythonGNU General Public License v3.0slowing
Script for advanced discovery of sensitive Privileged Accounts - includes Shadow Admins.
PowerShellBSD 3-Clause "New" or "Revised" Licensedormant
GyoiThon is an Intelligence Gathering tool using Machine Learning.
PythonOtherdormant
Proof of concept to perform data exfiltration using either single or multiple channel(s) at the same time.
PythonMIT Licensedormant
Perl script that enumerates DNS information from a domain, attempts zone transfers, performs a brute force dictionary style attack, and then performs reverse look-ups on the results.
Perldormant
Simple script to take screenshots of websites from a list of sites.
PythonGNU Lesser General Public License v3.0steady