Showing 36 of 342 projects
A Golang command-line utility that uses Chrome Headless to capture website screenshots and gather web data.
A Python script that discovers endpoints and their parameters in JavaScript files for penetration testing and bug hunting.
A highly customizable USB attack platform for penetration testing, based on a Raspberry Pi Zero.
A curated collection of cheat sheets and resources for penetration testing and security assessments.
A security testing toolkit for exploiting printer languages (PostScript, PJL, PCL) to capture/manipulate print jobs, access filesystems, and cause physical damage.
A security auditing tool for SSH server and client configurations, analyzing algorithms, vulnerabilities, and policy compliance.
A categorized collection of bug bounty write-ups organized by vulnerability type for security researchers.
A penetration testing tool that detects and exploits Server-Side Template Injection (SSTI) and code injection vulnerabilities.
A scanner that detects JavaScript libraries with known vulnerabilities and can generate a Software Bill of Materials (SBOM).
An OSINT tool that uses facial recognition to correlate social media profiles across multiple platforms for security professionals.
A high-performance offensive security tool for reconnaissance, vulnerability scanning, and information gathering.
A DNS-based encrypted command-and-control (C&C) tunnel for secure communication and data exfiltration.
A multi-threaded Python brute-forcing tool with a modular design for reliable and flexible password guessing attacks.
A library and tool to generate PHP unserialize() payloads for exploiting gadget chains in popular frameworks.
An Nmap NSE script that transforms nmap into a vulnerability scanner using offline vulnerability databases.
A 'Vulnerable by Design' cloud deployment tool for creating and completing capture-the-flag style security scenarios on AWS and Azure.
An open-source firmware security analyzer for embedded Linux devices, performing extraction, static/dynamic analysis, SBOM generation, and vulnerability reporting.
A high-performance DNS brute-force tool for enumerating subdomains during penetration testing.
A weaponized PHP web shell for post-exploitation with over 30 modules for remote administration, auditing, and network pivoting.
A curated collection of proof-of-concept exploits for Common Vulnerabilities and Exposures (CVEs).
A curated list of free, hands-on educational resources for learning cybersecurity through practical exercises and CTF challenges.
Nmap NSE script that uses Vulners.com API to detect software vulnerabilities during network scans.
An automated Python tool for auditing and exploiting NoSQL database vulnerabilities and web application injection attacks.
A collection of potentially dangerous file names and paths for security testing and fuzzing.
A web interface powered by FRIDA for runtime manipulation, analysis, and security testing of Android and iOS applications.
An Xposed module for dynamic analysis of Android apps via API hooks, unexported activity launching, and runtime inspection.
A comprehensive collection of HTML5-related XSS attack vectors and testing resources for web security professionals.
A framework that generates randomly vulnerable virtual machines for security education, labs, and CTF events.
A PowerShell toolkit for attacking, auditing, and securing Microsoft SQL Server environments during penetration tests.
A Python tool for mapping and tracking WiFi networks and devices through raw 802.11 monitoring, similar to nmap for wireless networks.
An automated security testing framework for REST APIs that detects vulnerabilities like SQL injection, XSS, and CSRF.
A Python tool to dump a git repository from a website, even when directory listing is disabled.
A phishing campaign toolkit for simulating real-world attacks to test and promote user security awareness.
A fast, multi-protocol credential brute-forcer that parses Nmap, Nessus, and Nexpose output to test credentials across 30+ services.
A semi-automatic OSINT framework and package manager for gathering intelligence and enumerating attack surfaces.
A collection of proof-of-concept (PoC) and exploit (Exp) scripts for various security vulnerabilities.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.