Showing 36 of 342 projects
A fast, efficient SNMP scanner that sends requests in parallel and logs responses, unlike traditional sequential scanners.
A lightweight Python utility for running common security tests against GraphQL APIs, ideal for CI/CD checks.
PowerShell module to check Windows binaries for security features like ASLR, DEP, SafeSEH, and Authenticode.
A security tool that identifies DTDs in filesystem snapshots and generates XXE payloads using those local DTDs.
A Ruby-based command-line tool for analyzing password dumps to generate statistics and insights for security reports.
A malicious DNS server for executing DNS rebinding attacks dynamically via domain name requests.
An optimized hashcat rule set for password cracking with reduced rule count and zero performance loss against major breach datasets.
A curated list of Bluetooth security resources covering vulnerabilities, tools, research, and conference talks for BR/EDR, LE, and Mesh.
An advanced keyboard-walk generator for password cracking, configurable with base characters, keymaps, and routes.
A steganography brute-force utility that uncovers hidden data inside files by trying passwords from a wordlist.
A collection of PowerShell scripts for security testing, penetration testing, and general system administration tasks.
A utility for bug hunters and organizations to identify Blind Cross-Site Scripting vulnerabilities via customizable payloads and notifications.
A command-line tool for security testing and offensive operations against Jenkins CI/CD servers.
A collection of password cracking rules and masks for hashcat, generated from analysis of real breached password data.
A curated list of security resources for penetration testing and vulnerability assessment of VoIP, WebRTC, and VoLTE systems.
A TCP connection hijacking tool written in Rust, enabling packet injection into established connections.
A tool that creates a JavaScript shell payload for exploiting XSS vulnerabilities to execute code in a victim's browser.
An exhaustive security checklist for Node.js web services, focused on Express and Hapi frameworks.
A collection of useful notes and reference materials for penetration testing hardware and related topics.
A high-performance word generator for password cracking with per-position configurable character sets.
A frontend JavaScript framework for developing DNS rebinding exploits against vulnerable LAN devices and IoT products.
A fast and flexible HTTP fuzzer for content discovery, credential bruteforcing, and security testing.
A framework for exploiting DNS rebinding vulnerabilities to bypass Same-Origin Policy and attack internal networks from browsers.
A collection of hashcat and John the Ripper rules for password cracking, optimized for common password generation patterns.
A family of extremely stealthy, code-golfed PHP webshells designed for undetectable remote command execution.
Extracts password-protected 7-Zip archive data into hashcat-compatible hashes for password cracking.
A command-line tool for managing webshells on compromised web servers via terminal.
A scriptable network authentication cracker for custom services, using Lua scripts to test credentials.
A scriptable network authentication cracker for custom services, using Lua scripts to test credentials.
A Python tool that automates DDoS attacks through the Tor network for security testing and education.
A tool to spy on and control TTY sessions of SSH-connected clients with built-in keylogging and session recording.
Large hashcat rulesets generated from real-world compromised passwords to improve password cracking effectiveness.
A web-based platform for organizing, automating, and analyzing password cracking tasks using Hashcat.
A versatile Rust tool for generating and mutating wordlists using patterns, web scraping, and password formats.
A web GUI for Hashcat that provides session management, notifications, and a multi-user interface for password cracking.
A tool for extracting secrets from CI/CD environments by deploying malicious pipelines, supporting Azure DevOps, GitHub, and GitLab.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.