LscriptThe LAZY script will make your life easier, and of course faster.
Sh00tSecurity Testing is not as simple as right click > Scan. It's messy, a tough game. What if you had missed to test just that one thing and had to regret later? Sh00t is a highly customizable, intelligent platform that understands the life of bug hunters and emphasizes on manual security testing.
AryAry 是一个集成类工具,主要用于调用各种安全工具,从而形成便捷的一键式渗透。
Wifi DumperThis is an open source tool to dump the wifi profiles and cleartext passwords of the connected access points on the Windows machine. This tool will help you in a Wifi penetration testing. Furthermore, it is useful while performing red team or an internal infrastructure engagements.
RubyfuRubyfu, where Ruby goes evil!
ArmorArmor is a simple Bash script designed to create encrypted macOS payloads capable of evading antivirus scanners.
CameradarCameradar hacks its way into RTSP videosurveillance cameras
Darkspiritz🌔 Official Repository for DarkSpiritz Penetration Framework | Written in Python 🐍
SerpentineC++/Win32/Boost Windows RAT (Remote Administration Tool) with a multiplatform Java/Spring RESTful C2 server and Go, C++/Qt5 frontends
Werdlists⌨️ Wordlists, Dictionaries and Other Data Sets for Writing Software Security Test Cases
TigersharkBilingual PhishingKit. TigerShark intergrates a vast array of various phishing tools and frameworks, from C2 servers, backdoors and delivery methods in multiple scripting languages in order to suit whatever your deployment needs may be.
Capsulecorp PentestVagrant VirtualBox environment for conducting an internal network penetration test
DartDART is a test documentation tool created by the Lockheed Martin Red Team to document and report on penetration tests, especially in isolated network environments.
LnkupGenerates malicious LNK file payloads for data exfiltration
Evil SsdpSpoof SSDP replies and create fake UPnP devices to phish for credentials and NetNTLM challenge/response.
WstgThe Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
DiscoverCustom bash scripts used to automate various penetration testing tasks including recon, scanning, parsing, and creating malicious payloads and listeners with Metasploit.
FdsploitFile Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.
HrshellHRShell is an HTTPS/HTTP reverse shell built with flask. It is an advanced C2 server with many features & capabilities.
Awesome BbhtA bash script that will automatically install a list of bug hunting tools that I find interesting for recon, exploitation, etc. (minus burp) For Ubuntu/Debain.
3klconAutomation Recon tool which works with Large & Medium scopes. It performs more than 20 tasks and gets back all the results in separated files.
WebmapA Python tool used to automate the execution of the following tools : Nmap , Nikto and Dirsearch but also to automate the report generation during a Web Penetration Testing
KnaryA simple HTTP(S) and DNS Canary bot with Slack/Discord/MS Teams & Pushover support
Awesome Shodan Queries🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩💻
GarudAn automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
CrithitTakes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to cross-check vulnerabilities over multiple hosts.
Nndefacctsnnposter's alternate fingerprint dataset for Nmap script http-default-accounts
Arp SpooferA pure-Python ARP Cache Poisoning (a.k.a "ARP Spoofing") tool
TcpproxyIntercepting TCP proxy to modify raw TCP streams using modules on incoming or outgoing traffic
RecsechRecsech is a tool for doing Footprinting and Reconnaissance on the target web. Recsech collects information such as DNS Information, Sub Domains, HoneySpot Detected, Subdomain takeovers, Reconnaissance On Github and much more you can see in Features in tools .
RapidpayloadFramework RapidPayload - Metasploit Payload Generator | Crypter FUD AntiVirus Evasion
Remote Desktop CachingThis tool allows one to recover old RDP (mstsc) session information in the form of broken PNG files. These PNG files allows Red Team member to extract juicy information such as LAPS passwords or any sensitive information on the screen. Blue Team member can reconstruct PNG files to see what an attacker did on a compromised host. It is extremely useful for a forensics team to extract timestamps after an attack on a host to collect evidences and perform further analysis.
SmogcloudFind cloud assets that no one wants exposed 🔎 ☁️
Pe LinuxLinux Privilege Escalation Tool By WazeHell
Zap CliA simple tool for interacting with OWASP ZAP from the commandline.
HydrafwHydraFW official firmware for HydraBus/HydraNFC for researcher, hackers, students, embedded software developers or anyone interested in debugging/hacking/developing/penetration testing
PacuThe AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
VulscanAdvanced vulnerability scanning with Nmap NSE
MinesweeperA Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).
DarksideTool Information Gathering & social engineering Write By [Python,JS,PHP]
PortiaPortia aims to automate a number of techniques commonly performed on internal network penetration tests after a low privileged account has been compromised. Portia performs privilege escalation as well as lateral movement automatically in the network
PhpvulnAudit tool to find common vulnerabilities in PHP source code
DnsmorphDomain name permutation engine written in Go
FuseA penetration testing tool for finding file upload bugs (NDSS 2020)
AstraAutomated Security Testing For REST API's
Print My ShellPython script wrote to automate the process of generating various reverse shells.
QuiverQuiver is the tool to manage all of your tools for bug bounty hunting and penetration testing.
SilentbridgeSilentbridge is a toolkit for bypassing 802.1x-2010 and 802.1x-2004.