Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Penetration Testing

Penetration Testing

288 projects

Showing 36 of 288 projects

Nord Stream
Nord StreamPython

A tool for extracting secrets from CI/CD environments by deploying malicious pipelines, supporting Azure DevOps, GitHub, and GitLab.

#azure-devops#cicd#azuredevops
Stars358
Forks22
Last commit1 month ago
Scapy
Scapy

A curated list of tools, add-ons, articles, and exploits built with the Scapy packet manipulation library.

#python-library#penetration-testing#packet-manipulation
Stars354
Forks47
Last commit1 year ago
libformatstr
libformatstrPython

A Python library for generating format string exploitation payloads in binary exploitation and CTF challenges.

#exploit-development#ctf-tools#python-library
Stars347
Forks36
Last commit4 years ago
Sticky Keys Slayer
Sticky Keys SlayerShell

A security tool that scans for Windows accessibility tools backdoors via automated RDP sessions.

#docker-tool#windows-security#rdp-security
Stars347
Forks69
Last commit8 years ago
known_hosts-hashcat
known_hosts-hashcatPython

A tool and guide for cracking hashed SSH known_hosts files using hashcat to recover IP addresses.

#ssh-security#known-hosts#network-reconnaissance
Stars340
Forks34
Last commit2 years ago
GraphCrawler - The all-in-one GraphQL Security toolkit
GraphCrawler - The all-in-one GraphQL Security toolkitPython

An automated security testing toolkit for GraphQL endpoints that discovers, analyzes, and scores vulnerabilities.

#api#api-hacking#graphql
Stars335
Forks23
Last commit
SNMP-Brute
SNMP-BrutePython

A fast SNMP brute force, enumeration, and Cisco config downloader with password cracking capabilities.

#cisco#enumeration#penetration-testing
Stars333
Forks106
Last commit4 years ago
DVCS-Pillage
DVCS-PillageShell

A toolkit to extract code, configs, and information from web-accessible git, hg, and bzr repositories that aren't fully cloneable.

#version-control-security#web-security#information-disclosure
Stars328
Forks58
Last commit
WebHashCat
WebHashCatJavaScript

A web interface for Hashcat that enables distributed password cracking sessions across multiple servers with real-time results.

#cracking#penetration-testing#python
Stars321
Forks69
Last commit2 months ago
ADOKit
ADOKitC#

A modular attack toolkit for Azure DevOps Services that leverages the REST API for reconnaissance, privilege escalation, and persistence.

#azure-devops#rest-api#red-teaming
Stars316
Forks35
Last commit1 year ago
Awesome WebSocket Security
Awesome WebSocket Security

A curated collection of CVEs, research, tools, and resources for WebSocket security testing and vulnerability research.

#fuzzing#websocket-security#penetration-testing
Stars309
Forks32
Last commit4 years ago
WHAD
WHADPython

A Python framework and CLI toolkit for exploring, hacking, and developing tools for wireless protocols using compatible hardware.

#hardware-hacking#firmware-integration#penetration-testing
Stars309
Forks35
Last commit2 days ago
hat
hatPython

An automated Hashcat wrapper that speeds up hash cracking during security engagements with pre-configured wordlists and rules.

#penetration-testing#hash-cracking#linux-tool
Stars308
Forks28
Last commit2 years ago
packemon
packemonGo

A cross-platform TUI tool for generating arbitrary network packets and monitoring traffic on any interface.

#packet-analyzer#packet-generator#network
Stars304
Forks4
Last commit3 days ago
Ezuri
EzuriGo

A simple Linux ELF runtime crypter that encrypts and loads executables directly into memory to evade detection.

#runtime-encryption#evasion-techniques#penetration-testing
Stars273
Forks56
Last commit1 year ago
AutoTTP
AutoTTPPython

A framework for automating offensive security testing by scripting security tool APIs like Empire and Metasploit.

#procedure#cobalt-strike#ttp-automation
Stars261
Forks64
Last commit3 years ago
JoomlaScan
JoomlaScanPython

A free and open-source scanner that identifies installed components, extensions, and files in Joomla CMS websites.

#python-tool#web-security#penetration-testing
Stars261
Forks72
Last commit2 years ago
Fingerprinter
FingerprinterRuby

A Ruby script that fingerprints remote applications and third-party scripts to identify their versions for security assessment.

#vulnerability-assessment#web-security#version-detection
Stars258
Forks38
Last commit8 months ago
Insecureshop
InsecureshopKotlin

An intentionally vulnerable Android shopping app built in Kotlin for security education and penetration testing practice.

#vulnerable-app#mobile-security#webview-security
Stars256
Forks245
Last commit4 years ago
Reverse-Shell-Manager
Reverse-Shell-ManagerPython

A terminal-based manager for handling multiple reverse shell sessions and clients during penetration testing.

#exploit#web-security#penetration-testing
Stars246
Forks60
Last commit2 years ago
fenrir
fenrirPython

A penetration testing tool that bypasses wired 802.1x network protection to gain access to target networks.

#red-teaming#penetration-testing#802.1x-bypass
Stars240
Forks45
Last commit5 years ago
Escape Graphinder - GraphQL Subdomain Enumeration
Escape Graphinder - GraphQL Subdomain EnumerationPython

A tool that extracts all GraphQL endpoints from a given domain using subdomain enumeration, script analysis, and brute force.

#spider#osint#subdomain-enumeration
Stars228
Forks14
Last commit
PETEP
PETEPJava

An open-source Java proxy for penetration testing, enabling traffic analysis and modification of TCP/UDP application protocols.

#udp-proxy#pentest#traffic-analysis
Stars228
Forks22
Last commit2 years ago
h2spacex
h2spacexPython

A low-level Python library for HTTP/2 single packet attacks and timing attacks using Scapy.

#python-library#single-packet-attack#last-frame-synchronization
Stars224
Forks17
Last commit1 month ago
padding-oracle-attacker
padding-oracle-attackerTypeScript

A CLI tool and library for executing padding oracle attacks with concurrent network requests and an elegant UI.

#crypto#web-security#encryption-attacks
Stars217
Forks32
Last commit3 years ago
Chiron
ChironPython

An IPv6 security assessment framework with advanced IPv6 Extension Headers manipulation capabilities for penetration testing and evasion.

#network-fuzzing#python-security#penetration-testing
Stars211
Forks25
Last commit7 years ago
Android Framework for Exploitation
Android Framework for ExploitationPython

A framework for exploiting Android devices and applications for security testing and vulnerability assessment.

#vulnerability-assessment#app-security#mobile-security
Stars201
Forks79
Last commit10 years ago
Smoke Leet Everyday
Smoke Leet EverydayPython

A curated collection of Capture The Flag (CTF) competition writeups for cybersecurity learning and practice.

#security-training#infosec#ctf-challenges
Stars191
Forks39
Last commit8 years ago
statsprocessor
statsprocessorC

A word generator using per-position Markov chains for password cracking and dictionary generation.

#word-generator#offline-tool#markov-chains
Stars190
Forks70
Last commit2 years ago
JKS private key cracker
JKS private key crackerJava

Crack passwords of private key entries in Java Key Store (JKS) files using a GPU-accelerated hashcat implementation.

#private-key#ctf-tools#java-keystore
Stars188
Forks18
Last commit5 years ago
IoTGoat
IoTGoatC

A deliberately insecure OpenWrt-based firmware designed to teach IoT security testing through hands-on vulnerability challenges.

#security-training#owasp#hands-on-learning
Stars185
Forks38
Last commit6 years ago
GSDF
GSDFPython

A Python tool that queries Google's SSL transparency report to discover subdomains and identify expired certificates.

#subdomain-enumeration#python-2#certificate-transparency
Stars184
Forks52
Last commit8 years ago
routopsy
routopsyPython

A security toolkit for attacking dynamic routing and first-hop redundancy protocols using weaponized virtual routers.

#pentest#infrastructure-security#red-teaming
Stars179
Forks40
Last commit4 years ago
fitcrack
fitcrackC

A BOINC-based distributed password cracking system powered by hashcat, enabling recovery of passwords from encrypted media and hashes across GPU-equipped nodes.

#boinc#penetration-testing#gpu-computing
Stars174
Forks38
Last commit1 month ago
TTPassGen
TTPassGenPython

A flexible and scriptable Python-based password dictionary generator supporting brute-force, combination, and complex rule modes.

#generator#python-tool#wordlist-generator
Stars169
Forks26
Last commit1 year ago
CVE-2016-6366
CVE-2016-6366Python

An improved exploit implementation for CVE-2016-6366 (EXTRABACON) targeting Cisco ASA devices with extended version support.

#cisco-asa#exploit-development#penetration-testing
Stars163
Forks63
Last commit9 years ago
PreviousPage 7 of 8

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
2 years ago
9 years ago
3 years ago
Next
#Security Tools69
#Security66
#Cybersecurity53
#Web Security46
#Network Security46
#Python41
#Hacking41
#Password Cracking40
#Security Testing37
#Security Tool37
#Docker37
#Security Research34