Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Penetration Testing

Penetration Testing

288 projects

Showing 36 of 288 projects

PESecurity
PESecurityPowerShell

PowerShell module to check Windows binaries for security features like ASLR, DEP, SafeSEH, and Authenticode.

#windows-security#control-flow-guard#security-hardening
Stars664
Forks148
Last commit1 year ago
Pipal
PipalRuby

A Ruby-based command-line tool for analyzing password dumps to generate statistics and insights for security reports.

#ruby-cli#penetration-testing#security-tools
Stars662
Forks118
Last commit2 years ago
dtd-finder
dtd-finderKotlin

A security tool that identifies DTDs in filesystem snapshots and generates XXE payloads using those local DTDs.

#hacktoberfest#xxe#penetration-testing
Stars661
Forks115
Last commit2 years ago
Whonow DNS Server
Whonow DNS ServerJavaScript

A malicious DNS server for executing DNS rebinding attacks dynamically via domain name requests.

#dns-rebinding#dns#penetration-testing
Stars661
Forks94
Last commit4 years ago
GraphQL Cop
GraphQL CopPython

A lightweight Python utility for running common security tests against GraphQL APIs, ideal for CI/CD checks.

#graphql#penetration-testing#security
Stars651
Forks95
Last commit6 months ago
OneRuleToRuleThemStill
OneRuleToRuleThemStill

An optimized hashcat rule set for password cracking with reduced rule count and zero performance loss against major breach datasets.

#breach-data#penetration-testing#offensive-security
Stars640
Forks58
Last commit1 year ago
Awesome Bluetooth Security
Awesome Bluetooth Security

A curated list of Bluetooth security resources covering vulnerabilities, tools, research, and conference talks for BR/EDR, LE, and Mesh.

#conference-talks#bluetooth-hacking#bluetooth-security
Stars605
Forks60
Last commit8 months ago
kwprocessor
kwprocessorC

An advanced keyboard-walk generator for password cracking, configurable with base characters, keymaps, and routes.

#human-behavior-simulation#penetration-testing#keyboard-walk
Stars605
Forks93
Last commit9 months ago
StegCracker
StegCrackerPython

A steganography brute-force utility that uncovers hidden data inside files by trying passwords from a wordlist.

#ctf-tools#penetration-testing#steganography
Stars595
Forks106
Last commit5 years ago
Powershellery
PowershelleryPowerShell

A collection of PowerShell scripts for security testing, penetration testing, and general system administration tasks.

#windows-automation#penetration-testing#system-administration
Stars581
Forks120
Last commit1 year ago
Jenkins Attack Framework
Jenkins Attack FrameworkPython

A command-line tool for security testing and offensive operations against Jenkins CI/CD servers.

#credential-dumping#jenkins#command-line-tool
Stars576
Forks60
Last commit11 months ago
bXSS
bXSSJavaScript

A utility for bug hunters and organizations to identify Blind Cross-Site Scripting vulnerabilities via customizable payloads and notifications.

#web-security#xss#cross-site-scripting
Stars574
Forks65
Last commit3 years ago
nsa-rules
nsa-rulesShell

A collection of password cracking rules and masks for hashcat, generated from analysis of real breached password data.

#mask-files#penetration-testing#password-cracking
Stars565
Forks127
Last commit9 years ago
rshijack
rshijackRust

A TCP connection hijacking tool written in Rust, enabling packet injection into established connections.

#tcp-hijacking#ctf-tools#tcp
Stars538
Forks44
Last commit1 year ago
Awesome RTC Hacking
Awesome RTC Hacking

A curated list of security resources for penetration testing and vulnerability assessment of VoIP, WebRTC, and VoLTE systems.

#voip-security#vulnerability-assessment#sip
Stars537
Forks51
Last commit1 month ago
JShell
JShellPython

A tool that creates a JavaScript shell payload for exploiting XSS vulnerabilities to execute code in a victim's browser.

#web-security#javascript-shell#penetration-testing
Stars532
Forks133
Last commit7 years ago
Strong node.js
Strong node.jsJavaScript

An exhaustive security checklist for Node.js web services, focused on Express and Hapi frameworks.

#secure-coding#vulnerability-assessment#owasp
Stars507
Forks28
Last commit2 years ago
Pentesting Hardware - A Practical Handbook (DRAFT)
Pentesting Hardware - A Practical Handbook (DRAFT)

A collection of useful notes and reference materials for penetration testing hardware and related topics.

#creative-commons#reference-materials#penetration-testing
Stars504
Forks82
Last commit7 years ago
DNS Rebind Toolkit
DNS Rebind ToolkitJavaScript

A frontend JavaScript framework for developing DNS rebinding exploits against vulnerable LAN devices and IoT products.

#iot#javascript-framework#web-security
Stars501
Forks84
Last commit4 years ago
maskprocessor
maskprocessorC

A high-performance word generator for password cracking with per-position configurable character sets.

#wordlist-generator#penetration-testing#password-recovery
Stars500
Forks118
Last commit4 years ago
monsoon
monsoonGo

A fast and flexible HTTP fuzzer for content discovery, credential bruteforcing, and security testing.

#wordlist-fuzzing#fuzzer#enumerator
Stars496
Forks40
Last commit1 year ago
dref
drefJavaScript

A framework for exploiting DNS rebinding vulnerabilities to bypass Same-Origin Policy and attack internal networks from browsers.

#iot#iot-security-testing#web-security
Stars493
Forks70
Last commit5 years ago
clem9669 rules
clem9669 rules

A collection of hashcat and John the Ripper rules for password cracking, optimized for common password generation patterns.

#john#john-rules#penetration-testing
Stars463
Forks47
Last commit1 year ago
nano
nanoPHP

A family of extremely stealthy, code-golfed PHP webshells designed for undetectable remote command execution.

#code-golf#mini-shell#tiny-shell
Stars449
Forks91
Last commit6 years ago
7z2hashcat
7z2hashcatPerl

Extracts password-protected 7-Zip archive data into hashcat-compatible hashes for password cracking.

#penetration-testing#security-tool#cryptanalysis
Stars430
Forks49
Last commit2 years ago
Webshell-Sniper
Webshell-SniperPython

A command-line tool for managing webshells on compromised web servers via terminal.

#webshell-sniper#pentest#terminal-utility
Stars421
Forks110
Last commit5 years ago
authoscope
authoscopeRust

A scriptable network authentication cracker for custom services, using Lua scripts to test credentials.

#cracking#lua-scripting#password-cracker
Stars418
Forks46
Last commit2 years ago
badtouch
badtouchRust

A scriptable network authentication cracker for custom services, using Lua scripts to test credentials.

#cracking#bruteforce-tool#lua-scripting
Stars418
Forks46
Last commit2 years ago
SSHPry v2
SSHPry v2Python

A tool to spy on and control TTY sessions of SSH-connected clients with built-in keylogging and session recording.

#ssh-security#tty-control#penetration-testing
Stars401
Forks77
Last commit8 years ago
pantagrule
pantagrule

Large hashcat rulesets generated from real-world compromised passwords to improve password cracking effectiveness.

#passwords#rulesets#penetration-testing
Stars399
Forks55
Last commit5 years ago
torDDoS
torDDoSPython

A Python tool that automates DDoS attacks through the Tor network for security testing and education.

#ddos-attack#penetration-testing#denial-of-service
Stars398
Forks58
Last commit2 years ago
Hashview
HashviewPython

A web-based platform for organizing, automating, and analyzing password cracking tasks using Hashcat.

#security-analytics#distributed#flask
Stars394
Forks47
Last commit1 day ago
Gorilla
GorillaRust

A versatile Rust tool for generating and mutating wordlists using patterns, web scraping, and password formats.

#cracking#hash#infosec
Stars392
Forks22
Last commit4 months ago
crackerjack
crackerjackPython

A web GUI for Hashcat that provides session management, notifications, and a multi-user interface for password cracking.

#penetration-testing#python#security-tools
Stars381
Forks93
Last commit2 years ago
Cotopaxi
CotopaxiPython

A toolkit for security testing IoT devices using protocols like CoAP, MQTT, DTLS, and HTTP/2.

#vulnerability-assessment#protocol-fuzzing#mqtt
Stars362
Forks79
Last commit2 years ago
Awesome ARM Exploitation
Awesome ARM Exploitation

A curated collection of videos, articles, books, tools, and resources focused on ARM architecture exploitation techniques.

#embedded-security#arm#arm-exploitation
Stars362
Forks45
Last commit2 years ago
PreviousPage 6 of 8

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
Next
#Security Tools69
#Security66
#Cybersecurity53
#Web Security46
#Network Security46
#Python41
#Hacking41
#Password Cracking40
#Security Testing37
#Security Tool37
#Docker37
#Security Research34