Showing 36 of 342 projects
A curated collection of videos, articles, books, tools, and resources focused on ARM architecture exploitation techniques.
A curated list of tools, add-ons, articles, and exploits built with the Scapy packet manipulation library.
A toolkit for security testing IoT devices using protocols like CoAP, MQTT, DTLS, and HTTP/2.
A security tool that scans for Windows accessibility tools backdoors via automated RDP sessions.
A Python library for generating format string exploitation payloads in binary exploitation and CTF challenges.
A tool and guide for cracking hashed SSH known_hosts files using hashcat to recover IP addresses.
An automated security testing toolkit for GraphQL endpoints that discovers, analyzes, and scores vulnerabilities.
A fast SNMP brute force, enumeration, and Cisco config downloader with password cracking capabilities.
A toolkit to extract code, configs, and information from web-accessible git, hg, and bzr repositories that aren't fully cloneable.
A web interface for Hashcat that enables distributed password cracking sessions across multiple servers with real-time results.
A Python framework and CLI toolkit for exploring, hacking, and developing tools for wireless protocols using compatible hardware.
A modular attack toolkit for Azure DevOps Services that leverages the REST API for reconnaissance, privilege escalation, and persistence.
A curated collection of CVEs, research, tools, and resources for WebSocket security testing and vulnerability research.
An automated Hashcat wrapper that speeds up hash cracking during security engagements with pre-configured wordlists and rules.
A cross-platform TUI tool for generating arbitrary network packets and monitoring traffic on any interface.
A simple Linux ELF runtime crypter that encrypts and loads executables directly into memory to evade detection.
An open-source, lightweight TCP/UDP tunneling solution with connection pooling and multi-protocol support for bypassing network restrictions.
A framework for automating offensive security testing by scripting security tool APIs like Empire and Metasploit.
An intentionally vulnerable Android shopping app built in Kotlin for security education and penetration testing practice.
A free and open-source scanner that identifies installed components, extensions, and files in Joomla CMS websites.
A Ruby script that fingerprints remote applications and third-party scripts to identify their versions for security assessment.
A terminal-based manager for handling multiple reverse shell sessions and clients during penetration testing.
A penetration testing tool that bypasses wired 802.1x network protection to gain access to target networks.
An open-source Java proxy for penetration testing, enabling traffic analysis and modification of TCP/UDP application protocols.
A tool that extracts all GraphQL endpoints from a given domain using subdomain enumeration, script analysis, and brute force.
A low-level Python library for HTTP/2 single packet attacks and timing attacks using Scapy.
A CLI tool and library for executing padding oracle attacks with concurrent network requests and an elegant UI.
An IPv6 security assessment framework with advanced IPv6 Extension Headers manipulation capabilities for penetration testing and evasion.
A framework for exploiting Android devices and applications for security testing and vulnerability assessment.
A word generator using per-position Markov chains for password cracking and dictionary generation.
A curated collection of Capture The Flag (CTF) competition writeups for cybersecurity learning and practice.
Crack passwords of private key entries in Java Key Store (JKS) files using a GPU-accelerated hashcat implementation.
A deliberately insecure OpenWrt-based firmware designed to teach IoT security testing through hands-on vulnerability challenges.
A Python tool that queries Google's SSL transparency report to discover subdomains and identify expired certificates.
A security toolkit for attacking dynamic routing and first-hop redundancy protocols using weaponized virtual routers.
A BOINC-based distributed password cracking system powered by hashcat, enabling recovery of passwords from encrypted media and hashes across GPU-equipped nodes.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.