AutoPentest-DRLAutoPentest-DRL: Automated Penetration Testing Using Deep Reinforcement Learning
AlfredA friendly Toolkit for Beginner CTF players
Red-Rabbit-V4The Red Rabbit project is just what a hacker needs for everyday automation. Red Rabbit unlike most frameworks out there does not automate other peoples tools like the aircrack suite or the wifite framework, it rather has its own code and is raw source with over 270+ options. This framework might just be your everyday key to your workflow
FYIMy last 10 year's material collection on offensive & defensive security, GRC, risk management, technical security guidelines and much more.
PwnX.py🏴☠️ Pwn misconfigured sites running ShareX custom image uploader API through chained exploit
AttackSurfaceManagementDiscover the attack surface and prioritize risks with our continuous Attack Surface Management (ASM) platform - Sn1per Professional #pentest #redteam #bugbounty
metagoofilSearch Google and download specific file types
sshamebrute force SSH public-key authentication
warfWARF is a Web Application Reconnaissance Framework that helps to gather information about the target.
TokenBreakerJSON RSA to HMAC and None Algorithm Vulnerability POC
AshokAshok is a OSINT Recon Tool , a.k.a 😍 Swiss Army knife .
TIWAPTotally Insecure Web Application Project (TIWAP)
Dark-PhishDark-Phish is a complete phishing tool. For more about Dark-Phish tool please visit the website.
pentest-toolsGeneral stuff for pentesting - password cracking, phishing, automation, Kali, etc.
AntiEye:.IP webcam penetration test suit.:
clairvoyanceObtain GraphQL API Schema even if the introspection is not enabled
c2A simple, extensible C&C beaconing system.
PXXTFFramework For Exploring kernel vulnerabilities, network vulnerabilities ✨
urldedupePass in a list of URLs with query strings, get back a unique list of URLs and query string combinations
peniotPENIOT: Penetration Testing Tool for IoT
pwn-pulseExploit for Pulse Connect Secure SSL VPN arbitrary file read vulnerability (CVE-2019-11510)
huntkitDocker - Ubuntu with a bunch of PenTesting tools and wordlists
graphw00fgraphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint.
boxerBoxer: A fast directory bruteforce tool written in Python with concurrency.
S3ScanScript to spider a website and find publicly open S3 buckets
BURN[WIP] Anti-Forensics ToolKit to clear post-intrusion sensible logfiles 🔥 (For Research Only)
pentest-reportsCollection of penetration test reports and pentest report templates. Published by the the best security companies in the world.
webreconAutomated Web Recon Shell Scripts
DNSExplorerBash script that automates the enumeration of domains and DNS servers in the active information gathering.
reverieAutomated Pentest Tools Designed For Parrot Linux
filter-var-sqliBypassing FILTER_SANITIZE_EMAIL & FILTER_VALIDATE_EMAIL filters in filter_var for SQL Injection ( xD )
KaliIntelligenceSuiteKali Intelligence Suite (KIS) shall aid in the fast, autonomous, central, and comprehensive collection of intelligence by executing standard penetration testing tools. The collected data is internally stored in a structured manner to allow the fast identification and visualisation of the collected information.
ADMMutateClassic code from 1999+ I am fairly sure this is the first public polymorphic shellcode ever (best IMHO and others http://ids.cs.columbia.edu/sites/default/files/ccs07poly.pdf :) If I ever port this to 64 or implement a few other suggestions (sorry I lost ppc code version contributed) it will be orders of magnitude more difficult to spot, so I h…
toolsTools used for Penetration testing / Red Teaming
pyhtoolsA Python Hacking Library consisting of network scanner, arp spoofer and detector, dns spoofer, code injector, packet sniffer, network jammer, email sender, downloader, wireless password harvester credential harvester, keylogger, download&execute, ransomware, data harvestors, etc.
GoPhish-TemplatesGoPhish Templates that I have retired and/or templates I've recreated.
minipwnerA script to configure a TP-Link MR3040 running OpenWRT into a simple, yet powerful penetration-testing "dropbox".
xmlrpc-bruteforcerAn XMLRPC brute forcer targeting Wordpress written in Python 3. (DISCONTINUED)
hathiA dictionary attack tool for PostgreSQL and MSSQL
tugareconPentest: Subdomains enumeration tool for penetration testers.
frisbeeCollect email addresses by crawling search engine results.
brutekragPenetration tests on SSH servers using brute force or dictionary attacks. Written in Python.
sqlscanQuick SQL Scanner, Dorker, Webshell injector PHP
default-http-login-hunterLogin hunter of default credentials for administrative web interfaces leveraging NNdefaccts dataset.
vafVaf is a cross-platform very advanced and fast web fuzzer written in nim
WPA2-FritzBox-Pswd-Wordlist-GeneratorThis Script will produce all of the WPA2 Passwords used by various Router companies aswell as Fritzbox. All of these Passwords will be 16 Numbers in length. So it could get a bit large.