Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Penetration Testing

Penetration Testing

137 projects

Showing 36 of 137 projects

LinkFinder
LinkFinderPython

A Python script that discovers endpoints and their parameters in JavaScript files for penetration testing and bug hunting.

#endpoints#web-security#javascript-analysis
Stars4.3k
Forks654
Last commit2 years ago
Awesome Pentest Cheat Sheets
Awesome Pentest Cheat Sheets

A curated collection of cheat sheets and resources for penetration testing and security assessments.

#vulnerability-assessment#pentest#penetration-testing
Stars4.3k
Forks787
Last commit2 years ago
gowitness
gowitnessGo

A Golang command-line utility that uses Chrome Headless to capture website screenshots and gather web data.

#reporting#chrome#screenshot
Stars4.2k
Forks427
Last commit2 days ago
PRET
PRETPython

A security testing toolkit for exploiting printer languages (PostScript, PJL, PCL) to capture/manipulate print jobs, access filesystems, and cause physical damage.

#printer-security#postscript#hardware-hacking
Stars4.2k
Forks650
Last commit1 year ago
bug-bounty-reference
bug-bounty-reference

A categorized collection of bug bounty write-ups organized by vulnerability type for security researchers.

#web-security#vulnerability-database#penetration-testing
Stars4.2k
Forks1.0k
Last commit1 year ago
ssh-audit
ssh-auditPython

A security auditing tool for SSH server and client configurations, analyzing algorithms, vulnerabilities, and policy compliance.

#python-tool#ssh-security#compliance-checking
Stars4.2k
Forks211
Last commit7 months ago
tplmap
tplmapPython

A penetration testing tool that detects and exploits Server-Side Template Injection (SSTI) and code injection vulnerabilities.

#vulnerability-exploitation#ssti-detection#web-security
Stars4.1k
Forks685
Last commit2 years ago
retire.js
retire.jsJavaScript

A scanner that detects JavaScript libraries with known vulnerabilities and can generate a Software Bill of Materials (SBOM).

#sbom#vulnerabilities#owasp
Stars4.1k
Forks436
Last commit2 days ago
TorBot
TorBotPython

An open-source intelligence (OSINT) tool for crawling and analyzing websites on the dark web and beyond.

#python-web-crawler#spider#osint
Stars4.0k
Forks668
Last commit3 months ago
Social Mapper
Social MapperPython

An OSINT tool that uses facial recognition to correlate social media profiles across multiple platforms for security professionals.

#osint#red-teaming#selenium
Stars4.0k
Forks814
Last commit4 years ago
Patator
PatatorPython

A multi-threaded Python brute-forcing tool with a modular design for reliable and flexible password guessing attacks.

#python-tool#protocol-fuzzing#pentest
Stars3.9k
Forks831
Last commit11 months ago
Dnscat2
Dnscat2PHP

A DNS-based encrypted command-and-control (C&C) tunnel for secure communication and data exfiltration.

#red-teaming#penetration-testing#dns-tunneling
Stars3.9k
Forks646
Last commit2 years ago
PHPGGC
PHPGGCPHP

A library and tool to generate PHP unserialize() payloads for exploiting gadget chains in popular frameworks.

#exploit-development#php-security#gadget-chains
Stars3.8k
Forks548
Last commit6 months ago
vulscan
vulscanLua

An Nmap NSE script that transforms nmap into a vulnerability scanner using offline vulnerability databases.

#vulnerability-assessment#vulnerability#nmap
Stars3.7k
Forks692
Last commit2 months ago
subDomainsBrute
subDomainsBrutePython

A high-performance DNS brute-force tool for enumerating subdomains during penetration testing.

#multi-process#penetration-testing#reconnaissance
Stars3.6k
Forks1.0k
Last commit3 years ago
CloudGoat
CloudGoatPython

A 'Vulnerable by Design' cloud deployment tool for creating and completing capture-the-flag style security scenarios on AWS and Azure.

#vulnerable-lab#aws-security#security-training
Stars3.5k
Forks751
Last commit2 days ago
Raccoon
RaccoonPython

A high-performance offensive security tool for reconnaissance, vulnerability scanning, and information gathering.

#python-tool#enumeration#vulnerability-assessment
Stars3.5k
Forks441
Last commit3 days ago
Weevely
WeevelyPython

A weaponized PHP web shell for post-exploitation with over 30 modules for remote administration, auditing, and network pivoting.

#php-agent#web-shell#stealth-communication
Stars3.5k
Forks632
Last commit6 months ago
awesome-cve-poc
awesome-cve-poc

A curated collection of proof-of-concept exploits for Common Vulnerabilities and Exposures (CVEs).

#cve#exploit-development#penetration-testing
Stars3.5k
Forks722
Last commit4 years ago
emba
embaShell

An open-source firmware security analyzer for embedded Linux devices, performing extraction, static/dynamic analysis, SBOM generation, and vulnerability reporting.

#iot#sbom#embedded-systems
Stars3.4k
Forks299
Last commit3 days ago
nmap-vulners
nmap-vulnersLua

Nmap NSE script that uses Vulners.com API to detect software vulnerabilities during network scans.

#nmap-scripts#cve-detection#penetration-testing
Stars3.4k
Forks558
Last commit7 months ago
fuzz.txt
fuzz.txt

A collection of potentially dangerous file names and paths for security testing and fuzzing.

#vulnerability#vulnerability-discovery#files
Stars3.3k
Forks530
Last commit8 months ago
NoSQLMap
NoSQLMapPython

An automated Python tool for auditing and exploiting NoSQL database vulnerabilities and web application injection attacks.

#python-tool#enumeration#vulnerability-assessment
Stars3.3k
Forks624
Last commit2 months ago
Runtime Mobile Security (RMS)
Runtime Mobile Security (RMS)JavaScript

A web interface powered by FRIDA for runtime manipulation, analysis, and security testing of Android and iOS applications.

#runtime-analysis#mobile-security#ios
Stars3.0k
Forks406
Last commit
Inspeckage
InspeckageJava

An Xposed module for dynamic analysis of Android apps via API hooks, unexported activity launching, and runtime inspection.

#mobile-security#android-application#api-hooking
Stars3.0k
Forks523
Last commit5 years ago
H5SC
H5SCJavaScript

A comprehensive collection of HTML5-related XSS attack vectors and testing resources for web security professionals.

#web-security#xss#vulnerability-database
Stars2.9k
Forks417
Last commit4 years ago
Cyber Security University
Cyber Security University

A curated list of free, hands-on educational resources for learning cybersecurity through practical exercises and CTF challenges.

#digital-forensics#education#hands-on-learning
Stars2.9k
Forks279
Last commit8 months ago
SecGen
SecGenPython

A framework that generates randomly vulnerable virtual machines for security education, labs, and CTF events.

#cybersecurity-labs#randomization#cybok
Stars2.8k
Forks328
Last commit7 days ago
trackerjacker
trackerjackerPython

A Python tool for mapping and tracking WiFi networks and devices through raw 802.11 monitoring, similar to nmap for wireless networks.

#python-tool#network-mapping#network-reconnaissance
Stars2.7k
Forks190
Last commit1 month ago
PowerUpSQL
PowerUpSQLPowerShell

A PowerShell toolkit for attacking, auditing, and securing Microsoft SQL Server environments during penetration tests.

#windows-security#red-teaming#sql-server
Stars2.7k
Forks477
Last commit1 year ago
Astra
AstraPython

An automated security testing framework for REST APIs that detects vulnerabilities like SQL injection, XSS, and CSRF.

#owasp#web-security#sdlc
Stars2.6k
Forks412
Last commit1 year ago
King Phisher
King PhisherPython

A phishing campaign toolkit for simulating real-world attacks to test and promote user security awareness.

#security-training#social-engineering#self-hosted-security
Stars2.5k
Forks578
Last commit13 days ago
git-dumper
git-dumperPython

A Python tool to dump a git repository from a website, even when directory listing is disabled.

#web-security#source-code-extraction#repository-recovery
Stars2.5k
Forks296
Last commit1 month ago
Some-PoC-oR-ExP
Some-PoC-oR-ExPPython

A collection of proof-of-concept (PoC) and exploit (Exp) scripts for various security vulnerabilities.

#exploit-development#vulnerability-analysis#penetration-testing
Stars2.5k
Forks968
Last commit10 months ago
PhpSploit
PhpSploitPython

A stealthy command and control framework that persists on webservers via a polymorphic PHP one-liner backdoor.

#php-backdoor#hacktool#hacking-framework
Stars2.5k
Forks471
Last commit1 year ago
sn0int
sn0intRust

A semi-automatic OSINT framework and package manager for gathering intelligence and enumerating attack surfaces.

#osint#subdomain-enumeration#data-enrichment
Stars2.4k
Forks222
Last commit1 year ago
PreviousPage 3 of 4

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
27 days ago
Next
#Security42
#Security Tools36
#Web Security30
#Hacking25
#Cybersecurity24
#Network Security22
#Ethical Hacking21
#Vulnerability Assessment21
#Red Teaming19
#Python17
#Security Testing17
#Docker17