Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Penetration Testing

Penetration Testing

137 projects

Showing 29 of 137 projects

brutespray
brutesprayGo

A fast, multi-protocol credential brute-forcer that parses Nmap, Nessus, and Nexpose output to test credentials across 30+ services.

#nmap#infosec#penetration-testing
Stars2.4k
Forks425
Last commit4 days ago
OWASP MASVS
OWASP MASVSPython

The OWASP Mobile Application Security Verification Standard (MASVS) is the industry standard for mobile app security.

#app-security#mobile-security#standard
Stars2.4k
Forks663
Last commit4 months ago
Diamorphine
DiamorphineC

A Linux Kernel Module (LKM) rootkit for hiding processes, granting root privileges, and making files invisible.

#loadable-kernel-module#kernel-module#file-hiding
Stars2.3k
Forks480
Last commit1 month ago
xray
xrayGo

A network OSINT tool that automates subdomain enumeration, service fingerprinting, and data collection via Shodan and ViewDNS APIs.

#osint#subdomain-enumeration#banner-grabbing
Stars2.3k
Forks298
Last commit1 year ago
xssor2
xssor2JavaScript

A web-based toolkit for XSS (Cross-Site Scripting) testing, encoding/decoding, and payload generation.

#pentest#pentest-tool#web-security
Stars2.2k
Forks380
Last commit4 years ago
PowerTools
PowerToolsPowerShell

A deprecated collection of PowerShell tools for offensive security operations and penetration testing.

#windows-security#red-teaming#penetration-testing
Stars2.2k
Forks815
Last commit4 years ago
FakeNet-NG
FakeNet-NGPython

A dynamic network analysis tool that intercepts and simulates network services for malware analysis and penetration testing.

#traffic-interception#gsoc-2026#penetration-testing
Stars2.1k
Forks379
Last commit22 days ago
nodepass
nodepassGo

An open-source, lightweight TCP/UDP tunneling solution with connection pooling and multi-protocol support for bypassing network restrictions.

#udp-tunneling#tcp-tunneling#tcp
Stars2.1k
Forks232
Last commit2 days ago
snallygaster
snallygasterPython

A Python tool that scans HTTP servers for publicly accessible secret files and security vulnerabilities like git repos and backup files.

#python-tool#http-server#web-security
Stars2.1k
Forks228
Last commit2 months ago
pwn_jenkins
pwn_jenkinsPython

A collection of notes, scripts, and techniques for exploiting vulnerabilities and attacking Jenkins servers.

#credential-dumping#automation-server#pentest
Stars2.1k
Forks325
Last commit1 year ago
ReconDog
ReconDogPython

A reconnaissance tool that gathers information about targets using APIs without direct contact.

#honeypot-detector#information-gathering#subdomain-enumeration
Stars2.0k
Forks354
Last commit5 years ago
OWASP NodeGoat
OWASP NodeGoatHTML

A vulnerable Node.js web application designed to teach how to identify and fix OWASP Top 10 security vulnerabilities.

#security-training#vulnerable-app#owasp-top-10
Stars2.0k
Forks2.4k
Last commit1 year ago
Mentalist
MentalistPython

A graphical tool for custom wordlist generation using human password paradigms, with output for Hashcat and John the Ripper.

#cracking#tkinter-gui#python-tool
Stars2.0k
Forks258
Last commit11 days ago
Brida
BridaJava

A Burp Suite extension that bridges to Frida, enabling dynamic analysis and manipulation of mobile app traffic using the app's own code.

#traffic-manipulation#mobile-security#ios
Stars1.9k
Forks227
Last commit5 months ago
domain_analyzer
domain_analyzerPython

A Python security analysis tool that automatically discovers and reports comprehensive information about a given domain.

#python-tool#dns-analysis#web-crawling
Stars1.9k
Forks237
Last commit3 years ago
Lockpicking
Lockpicking

A curated list of awesome guides, tools, and resources related to lockpicking, physical security, and locksport.

#physical-security#locksport#locksmith
Stars1.9k
Forks125
Last commit3 years ago
TIDoS Framework
TIDoS FrameworkPython

A comprehensive offensive web application penetration testing framework with 108 modules covering reconnaissance to vulnerability analysis.

#web-penetration-testing#web-security#vulnerability-analysis
Stars1.9k
Forks395
Last commit
TIDoS-Framework
TIDoS-FrameworkPython

A comprehensive offensive web application penetration testing framework with 108 modules covering reconnaissance to vulnerability analysis.

#web-penetration-testing#web-security#vulnerability-analysis
Stars1.9k
Forks395
Last commit
net-creds
net-credsPython

A Python tool that sniffs sensitive credentials and data from network interfaces or pcap files across multiple protocols.

#python-tool#credential-capture#penetration-testing
Stars1.8k
Forks439
Last commit2 years ago
hate_crack
hate_crackPython

A command-line tool that automates password cracking methodologies through Hashcat with integrated wordlist management and attack orchestration.

#security-automation#python-cli#penetration-testing
Stars1.8k
Forks279
Last commit2 days ago
DVCS Ripper
DVCS RipperPerl

A Perl toolkit for ripping web-accessible version control repositories (Git, SVN, Mercurial, Bazaar, CVS) even when directory browsing is disabled.

#mercurial#version-control#source-code-recovery
Stars1.8k
Forks317
Last commit1 year ago
InQL Scanner
InQL ScannerKotlin

A Burp Suite extension for advanced GraphQL security testing, featuring vulnerability scanning, batch attacks, and schema analysis.

#burpsuite#graphql#penetration-testing
Stars1.8k
Forks183
Last commit2 days ago
pyrdp
pyrdpPython

A Python RDP man-in-the-middle tool and library for intercepting, monitoring, and analyzing Remote Desktop Protocol connections.

#rdp-mitm#hacktoberfest#pentest
Stars1.8k
Forks270
Last commit9 months ago
Hashtopolis
HashtopolisPHP

A multi-platform client-server tool for distributing Hashcat password cracking tasks across multiple computers.

#cracking#hashlist#passwords
Stars1.7k
Forks249
Last commit3 days ago
ssh-mitm
ssh-mitmC

A penetration testing tool that intercepts SSH connections to log plaintext passwords and full sessions.

#ssh-security#password-logging#arp-spoofing
Stars1.7k
Forks212
Last commit4 years ago
OneRuleToRuleThemAll
OneRuleToRuleThemAll

A comprehensive password cracking rule combining multiple sources for improved hashcat performance.

#penetration-testing#cybersecurity-tools#offensive-security
Stars1.6k
Forks298
Last commit4 years ago
fapro
faproPython

A free, cross-platform, single-file fake protocol server simulator that can start or stop multiple network services.

#traffic-analysis#simulation#honeypot
Stars1.6k
Forks181
Last commit1 year ago
hashcat-utils
hashcat-utilsC

A collection of small, chainable command-line utilities for advanced password cracking operations.

#penetration-testing#security-tools#password-analysis
Stars1.6k
Forks400
Last commit5 months ago
Hob0Rules
Hob0Rules

Statistical password cracking rules for Hashcat based on industry patterns and frequency analysis.

#penetration-testing#offensive-security#password-cracking
Stars1.5k
Forks314
Last commit6 years ago
PreviousPage 4 of 4

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
3 years ago
3 years ago
#Security42
#Security Tools36
#Web Security30
#Hacking25
#Cybersecurity24
#Network Security22
#Ethical Hacking21
#Vulnerability Assessment21
#Red Teaming19
#Python17
#Security Testing17
#Docker17