#pentest (30 Repositories)
Ranked open-source repositories tagged with #pentest, scored by pull request acceptance likelihood and maintainer engagement velocity.
17.5%
17.1h
30 repositories tagged #pentest
yaklang/yakit
Cyber Security ALL-IN-ONE Platform
oasm-platform/open-asm
AI-powered open-source platform for Attack Surface Management (OASM)
BlackArch/blackarch
An ArchLinux based distribution for penetration testers and security researchers.
c0tton-fluff/caido-mcp-server
MCP server for Caido proxy integration. Enables AI assistants like Claude Code to browse, analyse, and interact with HTTP traffic.
g0h4n/RustHound-CE
Active Directory data ingestor for BloodHound Community Edition written in Rust. 🦀
Ch0pin/medusa
Mobile Edge-Dynamic Unified Security Analysis
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
scipag/nac_bypass
Script collection to bypass Network Access Control (NAC, 802.1x)
ksg97031/frida-gadget
Automated tool for patching APKs to enable the use of Frida gadget by downloading the library and injecting code into the main activity.
Dest1ny-Sec/DesJsFinder
被动JS分析 + 框架识别 + 主动Fuzz + 响应指纹 — 红队API挖掘利器
InfoSecWarrior/Offensive-Payloads
List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.
Sliim/pentest-env
Pentest environment deployer (kali linux + targets) using vagrant and chef.
quarkslab/kdigger
Kubernetes focused container assessment and context discovery tool for penetration testing
k8gege/PowerLadon
Ladon hacking Scanner for PowerShell, vulnerability / exploit / detection / MS17010/SmbGhost,Brute-Force SMB/IPC/WMI/NBT/SSH/FTP/MSSQL/MYSQL/ORACLE/VNC
owtf/owtf
Offensive Web Testing Framework (OWTF), is a framework which tries to unite great tools and make pen testing more efficient http://owtf.org https://twitter.com/owtfp
Puliczek/CVE-2022-0337-PoC-Google-Chrome-Microsoft-Edge-Opera
🎩 🤟🏻 [P1-$10,000] Google Chrome, Microsoft Edge and Opera - vulnerability reported by Maciej Pulikowski - System environment variables leak - CVE-2022-0337
cdxiaodong/cain-agent
Real-world AI penetration testing engineer for authorized assessments — built-in cloud module covering AWS/Azure/GCP + Aliyun/Tencent/Huawei clouds. Built on Claude Agent SDK
howmp/dsh-pentest
面向 DeepSeek Harness(dsh)的渗透测试模式 @CloverSecLabs
Chocapikk/wpprobe
A fast WordPress plugin enumeration tool
chu1337/dnsbrute
a fast domain brute tool
six2dez/dorks_hunter
Simple Google Dorks search tool
christophetd/CloudFlair
🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.
transilienceai/communitytools
Open-source Claude Code skills, agents, and slash commands for AI-powered penetration testing, bug bounty hunting, and security research
lolc2/lolc2.github.io
lolC2 is a collection of C2 frameworks that leverage legitimate services to evade detection
CommonHuman-Lab/nyxstrike
AI Powered penetration testing Platform for offensive security research
sspsec/Scan-Spring-GO
Spring 全家桶漏洞扫描工具 | 17 个漏洞模块 + MCP 服务端(AI 自动化渗透)| Go 实现
Sliim/pentest-lab
Pentest Lab on OpenStack with Heat, Chef provisioning and Docker
SecWiki/windows-kernel-exploits
windows-kernel-exploits Windows平台提权漏洞集合