Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Penetration Testing

Penetration Testing

288 projects

Showing 36 of 288 projects

brutespray
brutesprayGo

A fast, multi-protocol credential brute-forcer that parses Nmap, Nessus, and Nexpose output to test credentials across 30+ services.

#nmap#infosec#penetration-testing
Stars2.4k
Forks427
Last commit1 day ago
OWASP MASVS
OWASP MASVSPython

The OWASP Mobile Application Security Verification Standard (MASVS) is the industry standard for mobile app security.

#app-security#mobile-security#standard
Stars2.4k
Forks685
Last commit5 months ago
Diamorphine
DiamorphineC

A Linux Kernel Module (LKM) rootkit for hiding processes, granting root privileges, and making files invisible.

#loadable-kernel-module#kernel-module#file-hiding
Stars2.4k
Forks482
Last commit1 month ago
xray
xrayGo

A network OSINT tool that automates subdomain enumeration, service fingerprinting, and data collection via Shodan and ViewDNS APIs.

#osint#subdomain-enumeration#banner-grabbing
Stars2.3k
Forks299
Last commit1 year ago
xssor2
xssor2JavaScript

A web-based toolkit for XSS (Cross-Site Scripting) testing, encoding/decoding, and payload generation.

#pentest#pentest-tool#web-security
Stars2.2k
Forks381
Last commit4 years ago
PowerTools
PowerToolsPowerShell

A deprecated collection of PowerShell tools for offensive security operations and penetration testing.

#windows-security#red-teaming#penetration-testing
Stars2.2k
Forks815
Last commit4 years ago
FakeNet-NG
FakeNet-NGPython

A dynamic network analysis tool that intercepts and simulates network services for malware analysis and penetration testing.

#traffic-interception#gsoc-2026#penetration-testing
Stars2.1k
Forks376
Last commit11 days ago
nodepass
nodepassGo

An open-source, lightweight TCP/UDP tunneling solution with connection pooling and multi-protocol support for bypassing network restrictions.

#udp-tunneling#tcp-tunneling#tcp
Stars2.1k
Forks237
Last commit1 month ago
snallygaster
snallygasterPython

A Python tool that scans HTTP servers for publicly accessible secret files and security vulnerabilities like git repos and backup files.

#python-tool#http-server#web-security
Stars2.1k
Forks229
Last commit4 months ago
pwn_jenkins
pwn_jenkinsPython

A collection of notes, scripts, and techniques for exploiting vulnerabilities and attacking Jenkins servers.

#credential-dumping#automation-server#pentest
Stars2.1k
Forks326
Last commit1 year ago
ReconDog
ReconDogPython

A reconnaissance tool that gathers information about targets using APIs without direct contact.

#honeypot-detector#information-gathering#subdomain-enumeration
Stars2.1k
Forks358
Last commit5 years ago
OWASP NodeGoat
OWASP NodeGoatHTML

A vulnerable Node.js web application designed to teach how to identify and fix OWASP Top 10 security vulnerabilities.

#security-training#vulnerable-app#owasp-top-10
Stars2.0k
Forks2.6k
Last commit2 years ago
Mentalist
MentalistPython

A graphical tool for custom wordlist generation using human password paradigms, with output for Hashcat and John the Ripper.

#cracking#tkinter-gui#python-tool
Stars2.0k
Forks258
Last commit1 month ago
Brida
BridaJava

A Burp Suite extension that bridges to Frida, enabling dynamic analysis and manipulation of mobile app traffic using the app's own code.

#traffic-manipulation#mobile-security#ios
Stars1.9k
Forks226
Last commit7 months ago
Lockpicking
Lockpicking

A curated list of awesome guides, tools, and resources related to lockpicking, physical security, and locksport.

#physical-security#locksport#locksmith
Stars1.9k
Forks123
Last commit4 years ago
domain_analyzer
domain_analyzerPython

A Python security analysis tool that automatically discovers and reports comprehensive information about a given domain.

#python-tool#dns-analysis#web-crawling
Stars1.9k
Forks237
Last commit3 years ago
TIDoS Framework
TIDoS FrameworkPython

A comprehensive offensive web application penetration testing framework with 108 modules covering reconnaissance to vulnerability analysis.

#web-penetration-testing#web-security#vulnerability-analysis
Stars1.9k
Forks391
Last commit
TIDoS-Framework
TIDoS-FrameworkPython

A comprehensive offensive web application penetration testing framework with 108 modules covering reconnaissance to vulnerability analysis.

#web-penetration-testing#web-security#vulnerability-analysis
Stars1.9k
Forks391
Last commit
net-creds
net-credsPython

A Python tool that sniffs sensitive credentials and data from network interfaces or pcap files across multiple protocols.

#python-tool#credential-capture#penetration-testing
Stars1.8k
Forks438
Last commit2 years ago
hate_crack
hate_crackPython

A command-line tool that automates password cracking methodologies through Hashcat with integrated wordlist management and attack orchestration.

#security-automation#python-cli#penetration-testing
Stars1.8k
Forks283
Last commit11 days ago
InQL Scanner
InQL ScannerKotlin

A Burp Suite extension for advanced GraphQL security testing, featuring vulnerability scanning, batch attacks, and schema analysis.

#burpsuite#graphql#penetration-testing
Stars1.8k
Forks185
Last commit1 month ago
DVCS Ripper
DVCS RipperPerl

A Perl toolkit for ripping web-accessible version control repositories (Git, SVN, Mercurial, Bazaar, CVS) even when directory browsing is disabled.

#mercurial#version-control#source-code-recovery
Stars1.8k
Forks317
Last commit1 year ago
pyrdp
pyrdpPython

A Python RDP man-in-the-middle tool and library for intercepting, monitoring, and analyzing Remote Desktop Protocol connections.

#rdp-mitm#hacktoberfest#pentest
Stars1.8k
Forks272
Last commit27 days ago
Hashtopolis
HashtopolisPHP

A multi-platform client-server tool for distributing Hashcat password cracking tasks across multiple computers.

#cracking#hashlist#passwords
Stars1.8k
Forks250
Last commit4 days ago
ssh-mitm
ssh-mitmC

A penetration testing tool that intercepts SSH connections to log plaintext passwords and full sessions.

#ssh-security#password-logging#arp-spoofing
Stars1.7k
Forks213
Last commit5 years ago
OneRuleToRuleThemAll
OneRuleToRuleThemAll

A comprehensive password cracking rule combining multiple sources for improved hashcat performance.

#penetration-testing#cybersecurity-tools#offensive-security
Stars1.6k
Forks298
Last commit4 years ago
fapro
faproPython

A free, cross-platform, single-file fake protocol server simulator that can start or stop multiple network services.

#traffic-analysis#simulation#honeypot
Stars1.6k
Forks181
Last commit1 year ago
hashcat-utils
hashcat-utilsC

A collection of small, chainable command-line utilities for advanced password cracking operations.

#penetration-testing#security-tools#password-analysis
Stars1.6k
Forks405
Last commit7 months ago
Hob0Rules
Hob0Rules

Statistical password cracking rules for Hashcat based on industry patterns and frequency analysis.

#penetration-testing#offensive-security#password-cracking
Stars1.5k
Forks312
Last commit7 years ago
AWSBucketDump
AWSBucketDumpPython

A security tool that enumerates AWS S3 buckets to discover and download interesting files using wordlist-based scanning.

#aws-security#python-tool#enumeration
Stars1.5k
Forks244
Last commit2 years ago
WrongSecrets
WrongSecretsJava

An OWASP training app with 62 challenges demonstrating real-world secrets management mistakes and how to find them.

#security-training#vulnerable-app#owasp
Stars1.4k
Forks568
Last commit7 days ago
Amber
AmberGo

A reflective PE packer for in-memory execution of Windows executables to bypass security products.

#in-memory-execution#pe#assembly
Stars1.4k
Forks219
Last commit2 years ago
pdfrip
pdfripRust

A multithreaded PDF password cracking utility with structured search builders, checkpoint/resume, and optimized performance.

#password-cracker#pdf-password-cracking#dictionary-attack
Stars1.4k
Forks138
Last commit2 months ago
Statistically Likely Usernames
Statistically Likely UsernamesPython

Wordlists for statistically likely usernames, optimized for horizontal password attacks and security testing.

#statistical-analysis#horizontal-attack#penetration-testing
Stars1.3k
Forks159
Last commit
RedHunt OS
RedHunt OS

A pre-configured Linux virtual machine for adversary emulation and threat hunting with attacker and defender toolkits.

#osint#penetration-testing#virtual-machine
Stars1.3k
Forks200
Last commit1 year ago
VHostScan
VHostScanPython

A virtual host scanner for penetration testing that performs reverse lookups, detects catch-all scenarios, and works around wildcards and aliases.

#penetration-test#subdomain-enumeration#virtual-host-scanner
Stars1.3k
Forks239
Last commit
PreviousPage 4 of 8

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
3 years ago
3 years ago
3 months ago
9 months ago
Next
#Security Tools69
#Security66
#Cybersecurity53
#Web Security46
#Network Security46
#Python41
#Hacking41
#Password Cracking40
#Security Testing37
#Security Tool37
#Docker37
#Security Research34