All Categories → Security → pentest

Top 269 pentest open source projects

Ary
Ary 是一个集成类工具,主要用于调用各种安全工具,从而形成便捷的一键式渗透。
Payloads
Git All the Payloads! A collection of web attack payloads.
Hadoop Attack Library
A collection of pentest tools and resources targeting Hadoop environments
Patator
Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.
Pentest Wiki
PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others.
Runascs
RunasCs - Csharp and open version of windows builtin runas.exe
Doxycannon
A poorman's proxycannon and botnet, using docker, ovpn files, and a dante socks5 proxy
Oscp Cheat Sheet
This is my OSCP cheat sheet made by combining a lot of different resources online with a little bit of tweaking. I used this cheat sheet during my exam (Fri, 13 Sep 2019) and during the labs. I can proudly say it helped me pass so I hope it can help you as well ! Good Luck and Try Harder
Hackers Tool Kit
Its a framework filled with alot of options and hacking tools you use directly in the script from brute forcing to payload making im still adding more stuff i now have another tool out called htkl-lite its hackers-tool-kit just not as big and messy to see updates check on my instagram @tuf_unkn0wn or if there are any problems message me on instagram
Capsulecorp Pentest
Vagrant VirtualBox environment for conducting an internal network penetration test
Cloudlist
Cloudlist is a tool for listing Assets from multiple Cloud Providers.
Berserker
A list of useful payloads for Web Application Security and Pentest/CTF
Ladon
大型内网渗透扫描器&Cobalt Strike,Ladon8.9内置120个模块,包含信息收集/存活主机/端口扫描/服务识别/密码爆破/漏洞检测/漏洞利用。漏洞检测含MS17010/SMBGhost/Weblogic/ActiveMQ/Tomcat/Struts2,密码口令爆破(Mysql/Oracle/MSSQL)/FTP/SSH(Linux)/VNC/Windows(IPC/WMI/SMB/Netbios/LDAP/SmbHash/WmiHash/Winrm),远程执行命令(smbexec/wmiexe/psexec/atexec/sshexec/webshell),降权提权Runas、GetSystem,Poc/Exploit,支持Cobalt Strike 3.X-4.0
Canisrufus
A stealthy Python based Windows backdoor that uses Github as a command and control server
Proxenet
The ONLY hacker friendly proxy for webapp pentests.
Wsuspendu
Implement WSUSpendu attack
Insanity Framework
Generate Payloads and Control Remote Machines. [Discontinued]
Debinject
Inject malicious code into *.debs
Socialfish
Phishing Tool & Information Collector
Poet
[unmaintained] Post-exploitation tool
Umbrella
A Phishing Dropper designed to Pentest.
Enigma
Multiplatform payload dropper
Tuktuk
Tool for catching and logging different types of requests.
Technowlogger
TechNowLogger is Windows/Linux Keylogger Generator which sends key-logs via email with other juicy target info
Pymeta
Pymeta will search the web for files on a domain to download and extract metadata. This technique can be used to identify: domains, usernames, software/version numbers and naming conventions.
Aboutsecurity
A list of payload and bypass lists for penetration testing and red team infrastructure build.
Asnlookup
Leverage ASN to look up IP addresses (IPv4 & IPv6) owned by a specific organization for reconnaissance purposes, then run port scanning on it.
Portia
Portia aims to automate a number of techniques commonly performed on internal network penetration tests after a low privileged account has been compromised. Portia performs privilege escalation as well as lateral movement automatically in the network
Offensive Dockerfiles
Offensive tools as Dockerfiles. Lightweight & Ready to go
Stuff
Unsorted, raw, ugly & probably poorly usable tools for reversing, exploit and pentest
Mida Multitool
Bash script purposed for system enumeration, vulnerability identification and privilege escalation.
Ntlmscan
scan for NTLM directories
Pentest
some pentest scripts & tools by [email protected]
Wavecrack
Wavestone's web interface for password cracking with hashcat
O365spray
Username enumeration and password spraying tool aimed at Microsoft O365.
Awesome Vulnerable
A curated list of VULNERABLE APPS and SYSTEMS which can be used as PENETRATION TESTING PRACTICE LAB.
Trigmap
A wrapper for Nmap to quickly run network scans
Oscprepo
A list of commands, scripts, resources, and more that I have gathered and attempted to consolidate for use as OSCP (and more) study material. Commands in 'Usefulcommands' Keepnote. Bookmarks and reading material in 'BookmarkList' CherryTree. Reconscan Py2 and Py3. Custom ISO building.
Penta
Open source all-in-one CLI tool to semi-automate pentesting.
Hookish
Hooks in to interesting functions and helps reverse the web app faster.
Cloud Buster
A Cloudflare resolver that works
Pidrila
Python Interactive Deepweb-oriented Rapid Intelligent Link Analyzer
Nray
nray distributed port scanner
C2hack
C2Hack, sharing tips and tricks for pentesters
Purplecloud
An Infrastructure as Code (IaC) deployment of a small Active Directory pentest lab in the cloud. The deployment simulates a semi-realistic corporate enterprise Active Directory with a DC and endpoints. Purple team goals include blue team detection capabilities and R&D for detection engineering new approaches.
Ssrf Testing
SSRF (Server Side Request Forgery) testing resources
Defaultcreds Cheat Sheet
One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password 🛡️
Shodan Dorks
Dorks for shodan.io. Some basic shodan dorks collected from publicly available data.
1-60 of 269 pentest projects