Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Penetration Testing

Penetration Testing

288 projects

Showing 36 of 288 projects

docker-hashcat
docker-hashcatDockerfile

Dockerized hashcat with multiple backends (CUDA, OpenCL, POCL) for GPU-accelerated password recovery and hash cracking.

#cuda#opencl#nvidia
Stars159
Forks45
Last commit9 months ago
hashcat rules collection
hashcat rules collection

A comprehensive collection of 317 hashcat rule files for password cracking and security testing.

#wordlist-generator#wordlist#infosec
Stars156
Forks19
Last commit4 months ago
ntlm_challenger
ntlm_challengerPython

Parse NTLM challenge messages from HTTP, SMB, and MSSQL endpoints to extract server information for security testing.

#mssql#information-gathering#network-reconnaissance
Stars153
Forks26
Last commit3 years ago
canTot
canTotPython

A Python CLI framework for automotive security testing, exploiting known CAN Bus vulnerabilities and fun hacks.

#can-bus#vulnerability-testing#vehicle-pentesting
Stars150
Forks28
Last commit1 year ago
echoCTF.RED
echoCTF.REDPHP

An open-source platform for developing, running, and administering Capture the Flag (CTF) competitions on real IT infrastructure.

#modular-architecture#security-awareness#penetration-testing
Stars148
Forks29
Last commit10 days ago
IPObfuscator
IPObfuscatorC

A simple tool to convert IP addresses into various obfuscated formats like DWORD, hex, and octal representations.

#bypass-filters#octal#penetration-testing
Stars145
Forks45
Last commit3 years ago
Cloud Buster
Cloud BusterPython

A pentest tool that checks Cloudflare-protected sites for origin IP leaks and misconfigurations.

#pentest#ip-leak-detection#command-line-tool
Stars145
Forks49
Last commit7 years ago
mailspoof
mailspoofPython

Scans SPF and DMARC DNS records to identify vulnerabilities that could allow email spoofing attacks.

#python-tool#spf-scanner#dns-security
Stars136
Forks24
Last commit3 years ago
Awesome CTF Cheatsheet
Awesome CTF Cheatsheet

A curated collection of tips, commands, and strategies for solving Capture the Flag (CTF) challenges and HackTheBox machines.

#hacking-tools#web-security#ctf-challenges
Stars134
Forks12
Last commit1 year ago
Capture the Flag CheatSheet
Capture the Flag CheatSheet

A curated collection of tips, commands, and strategies for solving Capture the Flag (CTF) challenges and HackTheBox machines.

#hacking-tools#web-exploitation#ctf-challenges
Stars134
Forks12
Last commit1 year ago
Android OpenDebug
Android OpenDebugJava

A Cydia Substrate tool that makes all Android applications debuggable on rooted devices.

#debugging-tools#mobile-security#security-analysis
Stars133
Forks34
Last commit12 years ago
goctopus
goctopusGo

A fast GraphQL discovery and fingerprinting toolbox for security testing and reconnaissance.

#introspection-detection#subdomain-enumeration#graphql
Stars131
Forks13
Last commit2 years ago
autocrack
autocrackPython

A Python wrapper for Hashcat that automates password cracking workflows with wordlist management and brute-force attacks.

#security-automation#penetration-testing#wordlist-management
Stars124
Forks34
Last commit
DroidGround
DroidGroundTypeScript

A custom platform for hosting controlled, realistic Android mobile hacking challenges in CTF competitions.

#exploit-development#adb#android
Stars116
Forks7
Last commit7 days ago
Vezir Project
Vezir Project

A pre-configured Ubuntu-based virtual machine for mobile application security testing and malware analysis.

#vulnerability-assessment#mobile-security#ios-security
Stars116
Forks21
Last commit10 years ago
rulesfinder
rulesfinderRust

A Rust tool that machine-learns efficient password mangling rules for John the Ripper or Hashcat from a dictionary and password list.

#penetration-testing#security-tools#offensive-security
Stars115
Forks20
Last commit2 years ago
honeydet
honeydetGo

A signature-based, multi-threaded honeypot detection tool written in Go that identifies emulated services via crafted requests.

#honeypot#honeypots#cyber-threat-intelligence
Stars112
Forks8
Last commit1 year ago
token-reverser
token-reverserPython

A wordlist generator for security testing that creates permutations of known data to crack tokens.

#python-tool#wordlist-generator#password-reset-testing
Stars110
Forks12
Last commit6 years ago
pwngitmanager
pwngitmanagerPython

A penetration testing tool for selectively downloading files from exposed .git repositories on web servers.

#web-security#penetration-testing#python
Stars109
Forks22
Last commit10 years ago
RSF
RSF

A standardized methodology for performing security assessments in robotics across physical, network, firmware, and application layers.

#robotics#vulnerability-assessment#embedded-security
Stars98
Forks17
Last commit7 years ago
nyxgeek-rules
nyxgeek-rulesShell

A collection of custom password cracking rules for Hashcat and John the Ripper to enhance brute-force attacks.

#cracking#jtr#cracking-hashes
Stars95
Forks19
Last commit1 year ago
Bypass signature and permission checks for IPCs
Bypass signature and permission checks for IPCsJava

Android security testing tool that bypasses signature and permission checks for inter-process communications.

#app-security#mobile-security#penetration-testing
Stars86
Forks28
Last commit
X-Frame-Options: All about Clickjacking?
X-Frame-Options: All about Clickjacking?

A repository containing Cure53's security audit reports, white papers, academic publications, and security tools.

#web-security#penetration-testing#vulnerability-research
Stars86
Forks10
Last commit3 years ago
Rook
RookPython

A Python tool that automates the provisioning of AWS p3 GPU instances via Terraform for high-speed password cracking with Hashcat.

#cloud-infrastructure#security-tooling#penetration-testing
Stars85
Forks12
Last commit6 years ago
VWGen
VWGenPython

A tool that generates vulnerable web applications for security testing and education, supporting multiple attack modules.

#generator#vulnerabilities#web-security
Stars85
Forks16
Last commit8 years ago
heapbytes
heapbytesShell

A Zsh theme designed for penetration testers with VPN and network interface awareness.

#oh-my-zsh-theme#ip#terminal
Stars83
Forks17
Last commit11 months ago
sshame
sshamePython

An interactive SSH public-key brute force tool for penetration testing, enabling command execution on remote hosts.

#ssh-key#authentication#network-scanning
Stars78
Forks15
Last commit1 year ago
Harness
HarnessPython

Interactive remote PowerShell payload providing native-like CLI over TCP with unmanaged and reflective injection capabilities.

#tcp-socket#command-line-interface#reflective-injection
Stars78
Forks20
Last commit10 years ago
RedHerd Framework
RedHerd FrameworkJavaScript

A collaborative serverless framework for orchestrating geographically distributed assets to simulate offensive cyberspace operations.

#collaborative-tools#serverless#distributed-systems
Stars75
Forks17
Last commit
MPT
MPTPython

A Python-based toolkit that automates Android penetration testing workflows by bundling and managing essential security tools.

#pentest-android#pentest-tool#adb
Stars74
Forks14
Last commit25 days ago
Hyperion
HyperionPython

A collection of security tools, exploits, proof-of-concept code, shellcodes, and scripts for educational purposes.

#educational-resources#penetration-testing#vulnerability-research
Stars73
Forks18
Last commit
pentest
pentestShell

An oh-my-zsh plugin providing aliases and functions for penetration testing and security auditing.

#hacktoberfest#command-line-tools#network-enumeration
Stars69
Forks12
Last commit2 years ago
Vuldroid
VuldroidJava

A vulnerable Android application demonstrating common security flaws for educational purposes.

#vulnerable-app#mobile-security#firebase-authentication
Stars68
Forks22
Last commit4 years ago
Nozzlr
NozzlrPython

A modular, script-friendly multithreaded bruteforce framework for penetration testing and security auditing.

#wordlist-attacks#ssh-bruteforce#infosec
Stars65
Forks14
Last commit3 years ago
offensive-tor-toolkit
offensive-tor-toolkitGo

A collection of Go tools for performing exploitation and post-exploitation tasks over Tor with embedded Tor instances.

#red-teaming#penetration-testing#tor
Stars63
Forks9
Last commit5 years ago
EyeWitness
EyeWitnessPython

A tool for taking screenshots of websites, gathering server headers, and identifying default credentials.

#proxy-support#kali-linux#security-reconnaissance
Stars60
Forks5
Last commit2 years ago
PreviousPage 8 of 8

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
8 years ago
12 years ago
3 years ago
1 month ago
#Security Tools69
#Security66
#Cybersecurity53
#Web Security46
#Network Security46
#Python41
#Hacking41
#Password Cracking40
#Security Testing37
#Security Tool37
#Docker37
#Security Research34