Showing 36 of 342 projects
A modular, script-friendly multithreaded bruteforce framework for penetration testing and security auditing.
A collection of Go tools for performing exploitation and post-exploitation tasks over Tor with embedded Tor instances.
A tool for taking screenshots of websites, gathering server headers, and identifying default credentials.
Official Node.js client library for programmatically accessing the OWASP Zed Attack Proxy (ZAP) API.
Zsh completion plugin for msfvenom in Metasploit, providing command-line autocompletion.
A minimal vulnerable web application for security training, designed to practice finding and exploiting common web vulnerabilities.
A Bash script installer that applies a custom Kali Linux theme with Zsh shell and banner for a pure aesthetic look.
A collection of hardware hacking workshop materials and resources for security professionals.
A comprehensive mind map for understanding and exploring Cross-Site Scripting (XSS) attack vectors and techniques.
A security analysis tool that automatically detects misconfigurations and vulnerabilities in MQTT brokers.
A refreshed Kali Linux post-installation script that simplifies tool installation and system configuration for security professionals.
A portable Bluetooth-controlled device for stealthy capture of WPA handshakes and PMKID hashes during penetration testing.
A tool to detect and remove duplicate hashcat rules by generating unique identifiers for each rule transformation.
An Oh My Zsh theme for penetration testers that displays date, time, and IP address for logging.
A client-server toolset for automated hash cracking with queue support for Hashcat.
A multi-threaded proof-of-concept tool for conducting denial-of-service stress tests over the Tor network.
Generates targeted wordlists from Wikipedia databases for faster password cracking in penetration testing.
Generates exhaustive password mutations from wordlists, websites, or stdin for security testing and password cracking.
A 2019 global student competition challenging participants to hack a custom RFID reader firmware using NSA reverse engineering tools.
Converts John The Ripper and Cain NTLMv1/v2 hashes to Hashcat-compatible format for password cracking.
A coroutines-driven Low & Slow traffic generator for penetration testing, written in Rust.
An intentionally vulnerable web application for measuring and improving XSS detection in security testing tools.
A red team automation tool that simulates advanced attacker behavior in AWS environments for security testing.
A Crystal-based utility that detects Web Application Firewalls (WAFs) through passive analysis and active probing.
Proof-of-concept exploit for CVE-2018-4407, a heap buffer overflow vulnerability in iOS/macOS networking code causing denial-of-service.
Python C extension providing direct bindings to libhashcat for password recovery and hash cracking.
A curated collection of tools, resources, and data for Industrial Control System (ICS) and SCADA security research and testing.
A collection of Danish wordlists for password cracking and security testing.
A Python script that inspects multi-byte character sets to find characters with user-defined properties for security testing.
An Elixir wrapper for NMAP that provides a programmatic interface for network discovery and security scanning.
A customizable Oh My Zsh theme for penetration testers, featuring IP display, command logging, and a clean prompt.
A Zsh theme designed specifically for Kali Linux users with security-focused information display.
A Python script that automates the creation of AWS GPU instances for high-speed password hash cracking.
Zsh plugin providing shortcuts for Metasploit Framework payload generation and Python HTTP server setup.
Zsh plugin for Metasploit Framework that simplifies starting handlers and includes a Python SimpleServer utility.
A plugin-based tool for performing GraphQL endpoint vulnerability assessment and security testing.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.