All Categories → Security → pentesting

Top 584 pentesting open source projects

HIDAAF
Python - Human Interface Device Android Attack Framework
PastebinMarkdownXSS
XSS in pastebin.com and reddit.com via unsanitized markdown output
winallenum
This powershell script has got to run in remote hacked windows host, even for pivoting
HolyTips
A Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.
OSCP-Prep
Contained is all my reference material for my OSCP preparation. Designed to be a one stop shop for code, guides, command syntax, and high level strategy. One simple clone and you have access to some of the most popular tools used for pentesting.
ldapconsole
The ldapconsole script allows you to perform custom LDAP requests to a Windows domain.
365-Stealer
365-Stealer is a phishing simualtion tool written in python3. It can be used to execute Illicit Consent Grant Attack.
MITM-cheatsheet
All MITM attacks in one place.
Powerexploit
Post-Exploitation 😎 module for Penetration Tester and Hackers.
attack-surface-detector-zap
The Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parameters
conote-community
Conote 综合安全测试平台社区版。
VulWebaju
VulWebaju is a platform that automates setting up your pen-testing environment for learning purposes.
behindflare
This tool was created as a Proof of Concept to reveal the threats related to web service misconfiguration using CloudFlare as reverse proxy and WAF
onedrive user enum
onedrive user enumeration - pentest tool to enumerate valid onedrive users
Damn-Vulnerable-Bank
Damn Vulnerable Bank is designed to be an intentionally vulnerable android application. This provides an interface to assess your android application security hacking skills.
webapp-wordlists
This repository contains wordlists for each versions of common web applications and content management systems (CMS). Each version contains a wordlist of all the files directories for this version.
BeFree
Website Security, Antivirus & Firewall || a powerful application that can secure your website against hackers, attacks and other incidents of abuse
Ubunter
An automated tool to turn your ubuntu machine into a hacking lab
SQL-Injection-cheat-sheet
Cheatsheet to exploit and learn SQL Injection.
ldap2json
The ldap2json script allows you to extract the whole LDAP content of a Windows domain into a JSON file.
transportc2
PoC Command and Control Server. Interact with clients through a private web interface, add new users for team sharing and more.
BackToMe
Little tool made in python to create payloads for Linux, Windows and OSX with unique handler
ReverseShellDll
C++ Windows Reverse Shell - Universal DLL Hijack | SSL Encryption | Statically Linked
cent
Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place
Dumb
Dumain Bruteforcer - a fast and flexible domain bruteforcer
OWASP-Calculator
🧮 An online calculator to assess the risk of web vulnerabilities based on OWASP Risk Assessment
GoRAT
GoRAT (Go Remote Access Tool) is an extremely powerful reverse shell, file server, and control plane using HTTPS reverse tunnels as a transport mechanism.
OffensiveAutoIt
Offensive tooling notes and experiments in AutoIt v3 (https://www.autoitscript.com/site/autoit/)
nozzlr
Nozzlr is a bruteforce framework, trully modular and script-friendly
x509sak
X.509 Swiss Army Knife is a toolkit atop OpenSSL to ease generation of CAs and aid white-hat pentesting
CommandGenInterface
Simple vueJS based command generator which I developed in order to learn vueJS a little bit more.
smbaudit
Perform various SMB-related attacks, particularly useful for testing large Active Directory environments.
MITMsmtp
MITMsmtp is an Evil SMTP Server for pentesting SMTP clients to catch login credentials and mails sent over plain or SSL encrypted connections.
xzf
EXIF-based command and control PoC
cracken
a fast password wordlist generator, Smartlist creation and password hybrid-mask analysis tool written in pure safe Rust
Astra
Astra is a tool to find URLs and secrets inside a webpage/files
421-480 of 584 pentesting projects