#pentesting (30 Repositories)
Ranked open-source repositories tagged with #pentesting, scored by pull request acceptance likelihood and maintainer engagement velocity.
35.2%
50.8h
30 repositories tagged #pentesting
ipa-lab/hackingBuddyGPT
Helping Ethical Hackers use LLMs in 50 Lines of Code or less..
chainreactors/aiscan
AI-driven pi-like agent for cyber security — single binary for pentest, red team, bug bounty
hashtopolis/server
Hashtopolis - distributed password cracking with Hashcat
maurosoria/dirsearch
Web path scanner
HackTricks-wiki/hacktricks
Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
praetorian-inc/nerva
Fast service fingerprinting CLI for 170+ protocols (TCP/UDP/SCTP) - built by Praetorian
e-m-b-a/emba
EMBA - The firmware security analyzer
CERT-Polska/Artemis
A modular vulnerability scanner with automatic report generation capabilities.
thomasbuilds/Spectre
Radio frequency scanner with recon and offensive capabilities
BlackArch/blackarch
An ArchLinux based distribution for penetration testers and security researchers.
caido/caido
🚀 Caido releases, wiki and roadmap
KeygraphHQ/shannon
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
reconmap/reconmap
Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With built-in command automation, output parsing, and AI‑assisted summaries, it delivers faster, more structured, and high‑quality security assessments.
lachlan2k/phatcrack
Modern web-based distributed hashcracking solution, built on hashcat
righettod/toolbox-pentest-web
Docker toolbox for pentest of web based application.
Ragnt/AngryOxide
802.11 Attack Tool
OJ/gobuster
Directory/File, DNS and VHost busting tool written in Go
botesjuan/Burp-Suite-Certified-Practitioner-Exam-Study
Burp Suite Certified Practitioner Exam Study
juice-shop/juice-shop
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
topscoder/nuclei-wordfence-cve
80k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒
opsqw/scoop-security
Scoop bucket for Penetration Testing and Cybersecurity related tools. 用于渗透测试和网络安全相关工具下载、安装和自动更新的Scoop软件仓库。
b1-team/superman
🤖 Kill The Protected Process 🤖
nlkguy/archer-t2u-plus-linux
TP-Link Archer T2U Plus / AC600 High Gain USB Wifi Adapter Review & Driver installation Guide for various platforms.
eslam3kl/SQLiDetector
Simple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests with 14 payloads and checking for 152 regex patterns for different databases.
thewhiteh4t/FinalRecon
All In One Web Recon
InfoSecWarrior/Offensive-Payloads
List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.
reconmap/pentest-reports
Collection of penetration test reports and pentest report templates. Published by the the best security companies in the world.
fportantier/habu
Hacking Toolkit
abhijithb200/investigator
An online handy-recon tool
Leo4j/Amnesiac
Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with lateral movement within Active Directory environments