RspetRSPET (Reverse Shell and Post Exploitation Tool) is a Python based reverse shell equipped with functionalities that assist in a post exploitation scenario.
CobraSource Code Security Audit (源代码安全审计)
BettercapDEPRECATED, bettercap developement moved here: https://github.com/bettercap/bettercap
KubestrikerA Blazing fast Security Auditing tool for Kubernetes
G ScoutGoogle Cloud Platform Security Tool
WhispersIdentify hardcoded secrets and dangerous behaviours
OpencspmOpen Cloud Security Posture Management Engine
Sbt Dependency CheckSBT Plugin for OWASP DependencyCheck. Monitor your dependencies and report if there are any publicly known vulnerabilities (e.g. CVEs). 🌈
Biu FrameworkBiu-framework🚀 Security Scan Framework For Enterprise Intranet Based Services(企业内网基础服务安全扫描框架)
CrithitTakes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to cross-check vulnerabilities over multiple hosts.
YawastYAWAST ...where a pentest starts. Security Toolkit for Web-based Applications
Nndefacctsnnposter's alternate fingerprint dataset for Nmap script http-default-accounts
AnteaterAnteater - CI/CD Gate Check Framework
RecsechRecsech is a tool for doing Footprinting and Reconnaissance on the target web. Recsech collects information such as DNS Information, Sub Domains, HoneySpot Detected, Subdomain takeovers, Reconnaissance On Github and much more you can see in Features in tools .
Zap CliA simple tool for interacting with OWASP ZAP from the commandline.
VulscanAdvanced vulnerability scanning with Nmap NSE
Striptlsproxy poc implementation of STARTTLS stripping attacks
MinesweeperA Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).
HardentheworldHarden the world is a community driven project to develop hardening guidelines and checklists for common software and devices.
NebulousadNebulousAD automated credential auditing tool.
Git ScannerA tool for bug hunting or pentesting for targeting websites that have open .git repositories available in public
LibdiffuzzCustom memory allocator that helps discover reads from uninitialized memory
Mix audit🕵️♀️ MixAudit provides a mix deps.audit task to scan a project Mix dependencies for known Elixir security vulnerabilities
Gcp AuditA tool for auditing security properties of GCP projects.
Sqlite LabThis code is vulnerable to SQL Injection and having SQLite database. For SQLite database, SQL Injection payloads are different so it is for fun. Just enjoy it \m/
Edr Testing ScriptTest the accuracy of Endpoint Detection and Response (EDR) software with simple script which executes various ATT&CK/LOLBAS/Invoke-CradleCrafter/Invoke-DOSfuscation payloads
ReconnoitreA security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.
NosqlmapAutomated NoSQL database enumeration and web application exploitation tool.
Find Sec BugsThe SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
Horn3tPowerful Visual Subdomain Enumeration at the Click of a Mouse
SipptsSet of tools to audit SIP based VoIP Systems
Encrypt.toSend encrypted PGP messages with one click
WynisAudit Windows Security with best Practice
DockleContainer Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start
KccssKubernetes Common Configuration Scoring System
CatnipCat-Nip Automated Basic Pentest Tool - Designed For Kali Linux
Gda Android Reversing ToolGDA is a new fast and powerful decompiler in C++(working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which supports malicious behavior detection, privacy leaking detection, vulnerability detection, path solving, packer identification, variable tracking, deobfuscation, python&java scripts, device memory extraction, dat…
DrekA static-code-analysis tool for performing security-focused code reviews. It enables an auditor to swiftly map the attack-surface of a large application, with an emphasis on identifying development anti-patterns and footguns.
VsauditVOIP Security Audit Framework
Aws Securitygroup GrapherThis ansible role gets information from an AWS VPC and generate a graphical representation of security groups
FrostUnit testing framework for test driven security of AWS, GCP, Heroku and more.
Pentest NotesCollection of Pentest Notes and Cheatsheets from a lot of repos (SofianeHamlaoui,dostoevsky,mantvydasb,adon90,BriskSec)
Btle SnifferPassively scan for Bluetooth Low Energy devices and attempt to fingerprint them
Rails Security Checklist🔑 Community-driven Rails Security Checklist (see our GitHub Issues for the newest checks that aren't yet in the README)