Showing 36 of 137 projects
A Python script that discovers endpoints and their parameters in JavaScript files for penetration testing and bug hunting.
A curated collection of cheat sheets and resources for penetration testing and security assessments.
A Golang command-line utility that uses Chrome Headless to capture website screenshots and gather web data.
A security testing toolkit for exploiting printer languages (PostScript, PJL, PCL) to capture/manipulate print jobs, access filesystems, and cause physical damage.
A categorized collection of bug bounty write-ups organized by vulnerability type for security researchers.
A security auditing tool for SSH server and client configurations, analyzing algorithms, vulnerabilities, and policy compliance.
A penetration testing tool that detects and exploits Server-Side Template Injection (SSTI) and code injection vulnerabilities.
A scanner that detects JavaScript libraries with known vulnerabilities and can generate a Software Bill of Materials (SBOM).
An open-source intelligence (OSINT) tool for crawling and analyzing websites on the dark web and beyond.
An OSINT tool that uses facial recognition to correlate social media profiles across multiple platforms for security professionals.
A multi-threaded Python brute-forcing tool with a modular design for reliable and flexible password guessing attacks.
A DNS-based encrypted command-and-control (C&C) tunnel for secure communication and data exfiltration.
A library and tool to generate PHP unserialize() payloads for exploiting gadget chains in popular frameworks.
An Nmap NSE script that transforms nmap into a vulnerability scanner using offline vulnerability databases.
A high-performance DNS brute-force tool for enumerating subdomains during penetration testing.
A 'Vulnerable by Design' cloud deployment tool for creating and completing capture-the-flag style security scenarios on AWS and Azure.
A high-performance offensive security tool for reconnaissance, vulnerability scanning, and information gathering.
A weaponized PHP web shell for post-exploitation with over 30 modules for remote administration, auditing, and network pivoting.
A curated collection of proof-of-concept exploits for Common Vulnerabilities and Exposures (CVEs).
An open-source firmware security analyzer for embedded Linux devices, performing extraction, static/dynamic analysis, SBOM generation, and vulnerability reporting.
Nmap NSE script that uses Vulners.com API to detect software vulnerabilities during network scans.
A collection of potentially dangerous file names and paths for security testing and fuzzing.
An automated Python tool for auditing and exploiting NoSQL database vulnerabilities and web application injection attacks.
A web interface powered by FRIDA for runtime manipulation, analysis, and security testing of Android and iOS applications.
An Xposed module for dynamic analysis of Android apps via API hooks, unexported activity launching, and runtime inspection.
A comprehensive collection of HTML5-related XSS attack vectors and testing resources for web security professionals.
A curated list of free, hands-on educational resources for learning cybersecurity through practical exercises and CTF challenges.
A framework that generates randomly vulnerable virtual machines for security education, labs, and CTF events.
A Python tool for mapping and tracking WiFi networks and devices through raw 802.11 monitoring, similar to nmap for wireless networks.
A PowerShell toolkit for attacking, auditing, and securing Microsoft SQL Server environments during penetration tests.
An automated security testing framework for REST APIs that detects vulnerabilities like SQL injection, XSS, and CSRF.
A phishing campaign toolkit for simulating real-world attacks to test and promote user security awareness.
A Python tool to dump a git repository from a website, even when directory listing is disabled.
A collection of proof-of-concept (PoC) and exploit (Exp) scripts for various security vulnerabilities.
A stealthy command and control framework that persists on webservers via a polymorphic PHP one-liner backdoor.
A semi-automatic OSINT framework and package manager for gathering intelligence and enumerating attack surfaces.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.