Showing 36 of 288 projects
PowerShell module to check Windows binaries for security features like ASLR, DEP, SafeSEH, and Authenticode.
A Ruby-based command-line tool for analyzing password dumps to generate statistics and insights for security reports.
A security tool that identifies DTDs in filesystem snapshots and generates XXE payloads using those local DTDs.
A malicious DNS server for executing DNS rebinding attacks dynamically via domain name requests.
A lightweight Python utility for running common security tests against GraphQL APIs, ideal for CI/CD checks.
An optimized hashcat rule set for password cracking with reduced rule count and zero performance loss against major breach datasets.
A curated list of Bluetooth security resources covering vulnerabilities, tools, research, and conference talks for BR/EDR, LE, and Mesh.
An advanced keyboard-walk generator for password cracking, configurable with base characters, keymaps, and routes.
A steganography brute-force utility that uncovers hidden data inside files by trying passwords from a wordlist.
A collection of PowerShell scripts for security testing, penetration testing, and general system administration tasks.
A command-line tool for security testing and offensive operations against Jenkins CI/CD servers.
A utility for bug hunters and organizations to identify Blind Cross-Site Scripting vulnerabilities via customizable payloads and notifications.
A collection of password cracking rules and masks for hashcat, generated from analysis of real breached password data.
A TCP connection hijacking tool written in Rust, enabling packet injection into established connections.
A curated list of security resources for penetration testing and vulnerability assessment of VoIP, WebRTC, and VoLTE systems.
A tool that creates a JavaScript shell payload for exploiting XSS vulnerabilities to execute code in a victim's browser.
An exhaustive security checklist for Node.js web services, focused on Express and Hapi frameworks.
A collection of useful notes and reference materials for penetration testing hardware and related topics.
A frontend JavaScript framework for developing DNS rebinding exploits against vulnerable LAN devices and IoT products.
A high-performance word generator for password cracking with per-position configurable character sets.
A fast and flexible HTTP fuzzer for content discovery, credential bruteforcing, and security testing.
A framework for exploiting DNS rebinding vulnerabilities to bypass Same-Origin Policy and attack internal networks from browsers.
A collection of hashcat and John the Ripper rules for password cracking, optimized for common password generation patterns.
A family of extremely stealthy, code-golfed PHP webshells designed for undetectable remote command execution.
Extracts password-protected 7-Zip archive data into hashcat-compatible hashes for password cracking.
A command-line tool for managing webshells on compromised web servers via terminal.
A scriptable network authentication cracker for custom services, using Lua scripts to test credentials.
A scriptable network authentication cracker for custom services, using Lua scripts to test credentials.
A tool to spy on and control TTY sessions of SSH-connected clients with built-in keylogging and session recording.
Large hashcat rulesets generated from real-world compromised passwords to improve password cracking effectiveness.
A Python tool that automates DDoS attacks through the Tor network for security testing and education.
A web-based platform for organizing, automating, and analyzing password cracking tasks using Hashcat.
A versatile Rust tool for generating and mutating wordlists using patterns, web scraping, and password formats.
A web GUI for Hashcat that provides session management, notifications, and a multi-user interface for password cracking.
A toolkit for security testing IoT devices using protocols like CoAP, MQTT, DTLS, and HTTP/2.
A curated collection of videos, articles, books, tools, and resources focused on ARM architecture exploitation techniques.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.