Showing 36 of 342 projects
A PowerShell framework for offensive security, penetration testing, and red teaming with scripts for all phases.
A free, open-source WordPress security scanner for professionals and site maintainers to test website vulnerabilities.
A comprehensive, curated collection of tools, research, and resources for Android application security analysis and reverse engineering.
A comprehensive, curated collection of tools, research, and resources for Android application security analysis and penetration testing.
A collection of setup scripts to install and manage security research tools for CTFs and binary analysis.
A runtime mobile exploration toolkit powered by Frida for security assessment of iOS and Android apps without jailbreak.
An AI-powered WiFi security auditing tool that uses deep reinforcement learning to optimize capture of WPA handshakes.
The most comprehensive open dictionary of attack patterns, predictable resource locations, and regex for black-box application security testing.
A fast, simple, recursive content discovery tool written in Rust for forced browsing attacks.
A post-exploitation framework with PowerShell and Python agents for cryptographically secure communications and flexible modules.
A post-exploitation framework with PowerShell and Python agents for security testing and red team operations.
A curated collection of interesting, funny, and concerning search queries for Shodan.io to find exposed devices and services.
A curated list of resources for learning and practicing web application security, including tools, books, courses, and vulnerable labs.
An automated cyber security platform for adversary emulation, red teaming, and incident response built on the MITRE ATT&CK framework.
An open-source adversary emulation platform that simulates malware attacks to test and improve network security defenses.
A next-generation web scanner that identifies websites and their technologies using over 1800 plugins with configurable aggression levels.
A modular web application fuzzer that replaces FUZZ keywords with payloads to test parameters, authentication, forms, and directories.
A community-curated collection of payloads, tools, and techniques for bug bounty hunters and security researchers.
Exploits locked computers via USB to hijack internet traffic, steal browser cookies, and install persistent web backdoors using a Raspberry Pi Zero.
A Python tool for generating custom wordlists by profiling users to guess weak passwords during penetration tests.
A Python extension for GDB that enhances exploit development with colorized displays, security checks, and specialized commands.
A Python-based hacking tool for remotely exploiting Android devices via ADB and Metasploit to gain Meterpreter sessions.
A comprehensive, free information security reference covering techniques, tools, tactics, and resources for learning and professional development.
A tool for visual inspection of websites across many hosts, providing an overview of HTTP-based attack surfaces.
A modular reconnaissance framework for conducting open source intelligence (OSINT) gathering from web-based sources.
An automated penetration testing tool that detects and exploits command injection vulnerabilities in web applications.
A curated list of awesome information security courses, training resources, and hands-on labs for cybersecurity professionals and students.
A Python framework to automate the installation and updating of penetration testing tools on Debian/Ubuntu/ArchLinux systems.
A comprehensive cheat sheet and tool collection for mobile application penetration testing, mapped to OWASP Mobile Top 10 risks.
A curated collection of XSS resources including payloads, polyglots, bypass techniques, and tools for security researchers.
A penetration testing tool that discovers and accesses RTSP video surveillance cameras through network scanning and dictionary attacks.
An open-source web application security scanner that identifies and exploits 200+ vulnerabilities for developers and penetration testers.
A network poisoning tool that captures authentication credentials by spoofing LLMNR, NBT-NS, and mDNS responses.
A security testing framework for Android that identifies vulnerabilities by interacting with apps, IPC endpoints, and the OS.
A curated list of free, legal, and safe hacking environments for cybersecurity training and skill development.
A Golang command-line utility that uses Chrome Headless to capture website screenshots and gather web data.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.