Awesome Pentest Cheat Sheets.
Creative Commons Zero v1.0 Universalslowing
257 projects53 categoriesshowing 181–240, page 4 of 5
Sourced fromenaqx/awesome-pentest
Awesome Pentest Cheat Sheets.
Creative Commons Zero v1.0 Universalslowing
A curated list of awesome resources about Electron.js (in)security
slowing
OSINT tool with multiple modules and a telegram scraper.
GoGNU General Public License v3.0dormant
Curated list of awesome serverless security resources such as (e)books, articles, whitepapers, blogs and research papers.
Creative Commons Zero v1.0 Universaldormant
Tool for phishing and corporate espionage written in Ruby.
Rubydormant
Steganography brute-force utility to uncover hidden data inside files.
PythonMIT Licensedormantarchived
Find, prepare, audit, exploit and even Google automatically for LFI/RFI bugs.
PythonGNU General Public License v2.0active
Advanced Web shell.
PHPMIT Licensedormant
Passive leak enumeration CLI tool that searches across 10 breach databases simultaneously.
GoMIT Licenseactive
Script to enumerate Google Storage buckets, determine what access you have to them, and determine if they can be privilege escalated.
PythonBSD 3-Clause "New" or "Revised" Licensedormant
Command-line tool to scan Google (or other) search results for vulnerabilities.
PythonOthersteady
TCP connection hijacker, Rust rewrite of shijack.
RustGNU General Public License v3.0slowing
Intercept SSL/TLS connections with frida; Allows TLS key extraction and decryption of TLS payload as PCAP in real time.
PythonGNU General Public License v3.0active
Comprehensive directory of CTFs, wargames, hacking challenge websites, pentest practice lab exercises, and more.
HTMLThe Unlicenseslowing
GNU/Linux packet crafting tool.
CGNU General Public License v2.0dormant
POSIX-compliant BASH script to quickly enumerate large networks by calling masscan to quickly identify open ports and then nmap to gain details on the systems/services on those ports.
ShellOtheractive
Open-source framework to facilitate side-channel attack research on Intel x86 processors in general and Intel SGX (Software Guard Extensions) platforms in particular.
CGNU General Public License v3.0active
Portable, platform independent and powerful network pivoting toolkit.
PythonOtherslowing
Find the password of an encrypted wallet file (i.e. wallet.dat).
COtherslowing
Scriptable network authentication cracker.
RustGNU General Public License v3.0slowing
An extensible key and secret validation for auditing active secrets against multiple SaaS vendors.
RustApache License 2.0slowing
Information gathering via dorks.
Pythondormant
Asynchronous enumeration and vulnerability scanner that "runs all the tools on all the hosts" in a configurable manner.
PythonMIT Licensedormantarchived
Network address discovery scanner, based on ARP sweeps, developed mainly for those wireless networks without a DHCP server.
CGNU General Public License v3.0slowing
Reactive attack collaboration framework and web application built with meteor.
JavaScriptMIT Licensedormant
Signaling security testing framework dedicated to telecom security for researching vulnerabilites in the signaling protocols used in mobile (cellular phone) operators.
JavaMIT Licensedormant
Tool for bug hunting or pentesting websites that have open .git repositories available in public.
ShellMIT Licensedormant
Crawls a domain's SSL/TLS certificates for its certificate alternative names.
GoGNU General Public License v2.0active
Static security analysis tool for PHP code.
PHPMIT Licensesteady
Domain-specific infrastructure for analyzing, generating, and manipulating syntactically correct but semantically spec-non-compliant video files.
RustMIT Licenseactive
Automated client-side template injection (sandbox escape/bypass) detection for AngularJS.
PythonMIT Licensedormant
SSLStrip version to defeat HSTS.
dormant
HTTP/HTTPS proxy over SSH.
GoMIT Licenseslowing
Python script that can enumerate all users from a Windows Domain Controller and crack those user's passwords using brute-force.
PythonOtherslowing
Penetration testing orchestration and automation framework, which allows writing declarative, reusable configurations capable of ingesting variables and using outputs of tools it has run as inputs to others.
GoMozilla Public License 2.0dormant
Curated collection of awesome malware, botnets, and other post-exploitation tools.
dormant
Fingerprint a server's SSL/TLS implementation.
GLSLMIT Licensedormant
Command line IPSEC VPN brute forcing tool for Linux that allows group name/ID enumeration and XAUTH brute forcing capabilities.
Pythondormantarchived
GNU/Linux bash based Bing and Google Dorking Tool.
Shelldormant
Brute-force dictionary attack against WPA-PSK.
CBSD 3-Clause "New" or "Revised" Licensedormant
Exploit WordPress-powered websites with Metasploit.
RubyMIT Licensedormant
Extensible TCP/UDP proxy with GUI for traffic analysis & modification with SSL/TLS support.
JavaGNU General Public License v3.0slowing
Security reconnaissance and vulnerability scanner for Atlassian Jira, focused on misconfigurations, unauthenticated access and CVE validation.
PythonMIT Licensesteady
Google hack database automation tool.
JavaScriptGNU General Public License v3.0dormant
GitHub Device Code phishing security assessment tool with dynamic device-code generation and automated landing page deployment.
PythonApache License 2.0steady
Library and query tool for querying several passive DNS providers.
RubyMIT Licensedormant
Looks for AWS, Azure and Google cloud storage buckets and lists permissions for vulnerable buckets.
PythonGNU General Public License v3.0slowing
Analyzes source code for Regular Expressions susceptible to Denial of Service attacks.
JavaScriptMIT Licensedormant
Client/Server Binaries for data exfiltration with ICMP. Useful in a network where ICMP protocol is less monitored than others (which is a common case).
GoMIT Licensesteady
Perform Google dorks against a domain.
Pythondormant
Multithreaded program to crack PKCS#12 files (.p12 and .pfx extensions), such as TLS/SSL certificates.
ShellGNU General Public License v3.0dormant
Scanner for enumerating Siemens S7 PLCs on a TCP/IP or LLC network.
Pythondormant
Command line Google dork tool.
PythonBSD 2-Clause "Simplified" Licensedormant
Command line Google dorking tool.
PythonOtherdormant
Plugin-based tool to scan public version control systems for sensitive information.
RubyMIT Licensedormant
Simple, fast, console-based hex editor.
CGNU General Public License v2.0steady
Retrieve and decrypt RunAs credentials stored within Microsoft System Center Operations Manager (SCOM) databases.
C#slowing
Many-sided rowhammer tool suite able to reverse engineer the contents of DDR3 and DDR4 memory chips protected by Target Row Refresh mitigations.
CApache License 2.0dormant
LFI exploitation tool.
PythonGNU General Public License v2.0dormant
Passive DNS network mapper.
Cdormant