Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Penetration Testing

Penetration Testing

342 projects

Showing 36 of 342 projects

Nozzlr
NozzlrPython

A modular, script-friendly multithreaded bruteforce framework for penetration testing and security auditing.

#wordlist-attacks#ssh-bruteforce#infosec
Stars65
Forks14
Last commit3 years ago
offensive-tor-toolkit
offensive-tor-toolkitGo

A collection of Go tools for performing exploitation and post-exploitation tasks over Tor with embedded Tor instances.

#red-teaming#penetration-testing#tor
Stars64
Forks9
Last commit5 years ago
EyeWitness
EyeWitnessPython

A tool for taking screenshots of websites, gathering server headers, and identifying default credentials.

#proxy-support#kali-linux#security-reconnaissance
Stars61
Forks5
Last commit2 years ago
OWASP ZAP Node API
OWASP ZAP Node APIJavaScript

Official Node.js client library for programmatically accessing the OWASP Zed Attack Proxy (ZAP) API.

#web-security#owasp-zap#penetration-testing
Stars60
Forks18
Last commit11 days ago
msfvenom
msfvenomShell

Zsh completion plugin for msfvenom in Metasploit, providing command-line autocompletion.

#zsh-completion#autocomplete#penetration-testing
Stars59
Forks15
Last commit6 months ago
BadLibrary
BadLibraryJavaScript

A minimal vulnerable web application for security training, designed to practice finding and exploiting common web vulnerabilities.

#security-training#vulnerable-app#sql-injection
Stars59
Forks7
Last commit2 years ago
kali
kaliShell

A Bash script installer that applies a custom Kali Linux theme with Zsh shell and banner for a pure aesthetic look.

#kali#kali-linux#oh-my-zsh-theme
Stars57
Forks8
Last commit16 days ago
Hardware Hacking 101
Hardware Hacking 101Python

A collection of hardware hacking workshop materials and resources for security professionals.

#security-workshop#embedded-security#hardware-hacking
Stars56
Forks9
Last commit7 years ago
XSS.png
XSS.png

A comprehensive mind map for understanding and exploring Cross-Site Scripting (XSS) attack vectors and techniques.

#vulnerability-assessment#owasp#web-security
Stars55
Forks135
Last commit10 years ago
mqttsa
mqttsaPython

A security analysis tool that automatically detects misconfigurations and vulnerabilities in MQTT brokers.

#python-tool#broker-testing#mqtt
Stars51
Forks9
Last commit2 years ago
LazyKali
LazyKaliShell

A refreshed Kali Linux post-installation script that simplifies tool installation and system configuration for security professionals.

#kali-linux#bash-script#penetration-testing
Stars50
Forks14
Last commit10 years ago
FistBump BLE Edition
FistBump BLE EditionJava

A portable Bluetooth-controlled device for stealthy capture of WPA handshakes and PMKID hashes during penetration testing.

#red-team-tool#hashcat-compatible#wifi-security
Stars50
Forks4
Last commit7 years ago
duprule
dupruleRust

A tool to detect and remove duplicate hashcat rules by generating unique identifiers for each rule transformation.

#rust-tool#rule-deduplication#penetration-testing
Stars49
Forks10
Last commit1 year ago
lpha3cho
lpha3choShell

An Oh My Zsh theme for penetration testers that displays date, time, and IP address for logging.

#cli-productivity#pentesters#terminal
Stars48
Forks10
Last commit2 years ago
Autocrack
AutocrackShell

A client-server toolset for automated hash cracking with queue support for Hashcat.

#client-server#penetration-testing#hash-cracking
Stars45
Forks6
Last commit3 years ago
dos-over-tor
dos-over-torPython

A multi-threaded proof-of-concept tool for conducting denial-of-service stress tests over the Tor network.

#python-tool#stress-testing#penetration-testing
Stars45
Forks14
Last commit5 months ago
WikiRaider
WikiRaiderPython

Generates targeted wordlists from Wikipedia databases for faster password cracking in penetration testing.

#hash#wikipedia-parsing#crack
Stars45
Forks8
Last commit2 years ago
password-stretcher
password-stretcherPython

Generates exhaustive password mutations from wordlists, websites, or stdin for security testing and password cracking.

#cracking#python-tool#leet-mutations
Stars39
Forks7
Last commit3 years ago
CSAW Embedded Security Challenge 2019
CSAW Embedded Security Challenge 2019Python

A 2019 global student competition challenging participants to hack a custom RFID reader firmware using NSA reverse engineering tools.

#embedded-security#educational#cybersecurity-competition
Stars37
Forks5
Last commit
NetNTLM-Hashcat
NetNTLM-HashcatPython

Converts John The Ripper and Cain NTLMv1/v2 hashes to Hashcat-compatible format for password cracking.

#hash-formats#windows-authentication#hash-conversion
Stars36
Forks9
Last commit6 years ago
Finshir
FinshirRust

A coroutines-driven Low & Slow traffic generator for penetration testing, written in Rust.

#load-generator#coroutines#penetration-testing
Stars36
Forks18
Last commit7 years ago
XSSMaze
XSSMazeCrystal

An intentionally vulnerable web application for measuring and improving XSS detection in security testing tools.

#vulnerability-assessment#web-security#xss
Stars36
Forks4
Last commit1 month ago
AWSDoor: Persistence on AWS
AWSDoor: Persistence on AWSPython

A red team automation tool that simulates advanced attacker behavior in AWS environments for security testing.

#aws-security#penetration-testing#threat-simulation
Stars36
Forks1
Last commit10 months ago
wafalyzer
wafalyzerCrystal

A Crystal-based utility that detects Web Application Firewalls (WAFs) through passive analysis and active probing.

#waf#waf-detection#crystal-lang
Stars35
Forks10
Last commit3 years ago
CVE-2018-4407
CVE-2018-4407Python

Proof-of-concept exploit for CVE-2018-4407, a heap buffer overflow vulnerability in iOS/macOS networking code causing denial-of-service.

#xnu-kernel#cve#buffer-overflow
Stars35
Forks9
Last commit7 years ago
pyhashcat
pyhashcatC

Python C extension providing direct bindings to libhashcat for password recovery and hash cracking.

#python-c-extension#penetration-testing#hash-cracking
Stars33
Forks7
Last commit5 years ago
Awesome Industrial Control System Security
Awesome Industrial Control System SecurityPython

A curated collection of tools, resources, and data for Industrial Control System (ICS) and SCADA security research and testing.

#honeypot#critical-infrastructure#penetration-testing
Stars32
Forks5
Last commit
Danish Wordlists
Danish Wordlists

A collection of Danish wordlists for password cracking and security testing.

#hashcat-lists#penetration-testing#hash-cracking
Stars30
Forks5
Last commit3 years ago
charsetinspect
charsetinspectPython

A Python script that inspects multi-byte character sets to find characters with user-defined properties for security testing.

#multi-byte-characters#command-line-tool#input-validation
Stars28
Forks7
Last commit
hades
hadesElixir

An Elixir wrapper for NMAP that provides a programmatic interface for network discovery and security scanning.

#elixir#nmap#network-discovery
Stars26
Forks3
Last commit6 years ago
pentest-report
pentest-reportShell

A customizable Oh My Zsh theme for penetration testers, featuring IP display, command logging, and a clean prompt.

#workflow-automation#penetration-testing#security-tools
Stars24
Forks2
Last commit5 months ago
ykali
ykaliShell

A Zsh theme designed specifically for Kali Linux users with security-focused information display.

#kali-linux#terminal#penetration-testing
Stars19
Forks2
Last commit1 year ago
Cloudcat
CloudcatPython

A Python script that automates the creation of AWS GPU instances for high-speed password hash cracking.

#cloud-infrastructure#pentest-tool#password-cracker
Stars17
Forks8
Last commit6 years ago
simpleserver
simpleserverShell

Zsh plugin providing shortcuts for Metasploit Framework payload generation and Python HTTP server setup.

#oh-my-zsh-plugin#command-line-tools#security-automation
Stars14
Forks1
Last commit8 years ago
msf
msfShell

Zsh plugin for Metasploit Framework that simplifies starting handlers and includes a Python SimpleServer utility.

#payload-handlers#oh-my-zsh-plugin#command-line-tools
Stars14
Forks1
Last commit8 years ago
GraphQL Intruder
GraphQL IntruderPython

A plugin-based tool for performing GraphQL endpoint vulnerability assessment and security testing.

#vulnerability-assessment#pentest-tool#web-security
Stars13
Forks0
Last commit5 years ago
PreviousPage 9 of 10

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
6 years ago
10 years ago
10 years ago
Next
#Security Tools90
#Security70
#Cybersecurity61
#Network Security53
#Web Security52
#Password Cracking51
#Hacking45
#Hashcat44
#Security Testing44
#Python43
#Security Tool41
#Docker39