Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Pentesting

Pentesting

69 projects

Showing 33 of 69 projects

Injured Android - CTF
Injured Android - CTFKotlin

A vulnerable Android CTF application demonstrating real-world security vulnerabilities and exploitation techniques.

#vulnerable-app#webview-security#mobile-pentesting
Stars760
Forks162
Last commit5 years ago
Awesome Electron.js Hacking
Awesome Electron.js Hacking

A curated collection of resources for security research, vulnerability discovery, and pentesting of Electron.js applications.

#electronjs#desktop-apps#awesome-list
Stars677
Forks65
Last commit1 year ago
Awesome Bluetooth Security
Awesome Bluetooth Security

A curated list of Bluetooth security resources covering vulnerabilities, tools, research, and conference talks for BR/EDR, LE, and Mesh.

#conference-talks#bluetooth-hacking#bluetooth-security
Stars607
Forks60
Last commit9 months ago
StegCracker
StegCrackerPython

A steganography brute-force utility that uncovers hidden data inside files by trying passwords from a wordlist.

#ctf-tools#penetration-testing#steganography
Stars602
Forks106
Last commit5 years ago
rshijack
rshijackRust

A TCP connection hijacking tool written in Rust, enabling packet injection into established connections.

#tcp-hijacking#ctf-tools#tcp
Stars540
Forks44
Last commit1 year ago
dref
drefJavaScript

A framework for exploiting DNS rebinding vulnerabilities to bypass Same-Origin Policy and attack internal networks from browsers.

#iot#iot-security-testing#web-security
Stars493
Forks71
Last commit5 years ago
Juice Shop CTF
Juice Shop CTFTypeScript

A CLI tool to export OWASP Juice Shop security challenges into CTFd, RootTheBox, or FBCTF compatible formats.

#security-training#owasp#web-security
Stars474
Forks138
Last commit3 months ago
Git-Scanner
Git-ScannerShell

A bug hunting tool that scans websites for exposed .git repositories and dumps their contents for security analysis.

#hacking-tools#vulnerability-assessment#pentest-tool
Stars383
Forks93
Last commit6 years ago
V0lt
V0ltPython

A Python toolkit for security Capture The Flag (CTF) challenges, providing utilities for crypto, shellcodes, and network connections.

#security#python3#python-toolkit
Stars372
Forks101
Last commit8 years ago
GraphCrawler - The all-in-one GraphQL Security toolkit
GraphCrawler - The all-in-one GraphQL Security toolkitPython

An automated security testing toolkit for GraphQL endpoints that discovers, analyzes, and scores vulnerabilities.

#api#api-hacking#graphql
Stars335
Forks23
Last commit
French Wordlists
French Wordlists

A collection of French and English wordlists specifically curated for cracking French passwords.

#hash#french-language#passwords
Stars326
Forks48
Last commit1 day ago
WebHashCat
WebHashCatJavaScript

A web interface for Hashcat that enables distributed password cracking sessions across multiple servers with real-time results.

#cracking#penetration-testing#python
Stars324
Forks69
Last commit3 months ago
Aaia
AaiaPython

Visualizes AWS IAM and Organizations as a graph using Neo4j to identify security anomalies and privilege escalation paths.

#graph#security#anomaly-detection
Stars297
Forks40
Last commit6 months ago
Reverse-Shell-Manager
Reverse-Shell-ManagerPython

A terminal-based manager for handling multiple reverse shell sessions and clients during penetration testing.

#exploit#web-security#penetration-testing
Stars245
Forks61
Last commit3 years ago
PETEP
PETEPJava

An open-source Java proxy for penetration testing, enabling traffic analysis and modification of TCP/UDP application protocols.

#udp-proxy#pentest#traffic-analysis
Stars230
Forks23
Last commit2 years ago
cefdebug
cefdebugC

A minimal command-line utility for connecting to and exploiting exposed CEF/Electron debuggers during security assessments.

#vulnerability-assessment#debugger-exploitation#command-line-tool
Stars209
Forks19
Last commit6 years ago
GraphQLer
GraphQLerPython

A dependency-aware GraphQL API fuzzing tool that automatically generates and executes security tests based on schema introspection.

#api#graphql#api-testing-framework
Stars169
Forks16
Last commit2 days ago
Graphcat
GraphcatPython

A Python script that generates graphs and charts from password cracking results (hashcat/john potfiles) for security analysis.

#cracking#matplotlib#security-analysis
Stars166
Forks14
Last commit3 years ago
Cloud Buster
Cloud BusterPython

A pentest tool that checks Cloudflare-protected sites for origin IP leaks and misconfigurations.

#pentest#ip-leak-detection#command-line-tool
Stars146
Forks49
Last commit7 years ago
goctopus
goctopusGo

A fast GraphQL discovery and fingerprinting toolbox for security testing and reconnaissance.

#introspection-detection#subdomain-enumeration#graphql
Stars134
Forks13
Last commit2 years ago
Cognito Scanner
Cognito ScannerPython

A Python script that implements security testing attacks against AWS Cognito, including account oracle and privilege escalation.

#vulnerability-assessment#audit#security-tools
Stars113
Forks8
Last commit2 years ago
CakeFuzzer
CakeFuzzerPython

An automated IAST fuzzer for discovering vulnerabilities in CakePHP web applications with minimal false positives.

#cakephp#iast#fuzzing
Stars104
Forks9
Last commit1 year ago
RSF
RSF

A standardized methodology for performing security assessments in robotics across physical, network, firmware, and application layers.

#robotics#vulnerability-assessment#embedded-security
Stars98
Forks17
Last commit10 days ago
twisted-honeypots
twisted-honeypotsShell

A Python-based honeypot suite for SSH, FTP, and Telnet that captures credentials to build attack dictionaries.

#honeypot#credential-capture#python
Stars87
Forks20
Last commit6 years ago
Nozzlr
NozzlrPython

A modular, script-friendly multithreaded bruteforce framework for penetration testing and security auditing.

#wordlist-attacks#ssh-bruteforce#infosec
Stars65
Forks14
Last commit3 years ago
sherlock
sherlockRust

A Rust command-line tool to find social media accounts by username across 400+ networks.

#digital-footprint#hacktoberfest#social-media
Stars58
Forks1
Last commit4 days ago
Hashcat-Stuffs
Hashcat-StuffsPowerShell

A collection of optimized hashcat masks, rules, and PowerShell scripts for efficient password cracking.

#rules#hashcat-lists#hashcat-masks
Stars51
Forks7
Last commit6 years ago
NullKia
NullKiaGo

A comprehensive mobile security framework for device exploitation, bootloader unlocking, firmware analysis, and cellular security research across 18 manufacturers.

#mobile-security#ios-jailbreak#cellular-security
Stars30
Forks4
Last commit3 months ago
SababaSec
SababaSecPython

A collection of Capture The Flag (CTF) competition challenge write-ups from the SababaSec cybersecurity team.

#educational#vulnerability-analysis#ctf-writeups
Stars23
Forks8
Last commit3 months ago
gohashmob
gohashmobGo

A CLI tool to quickly look up hash plaintexts using the HashMob API directly from your terminal.

#terminal-utility#osint#hashes
Stars15
Forks0
Last commit3 years ago
Danish Phone Wordlist Generator
Danish Phone Wordlist GeneratorPython

Generates wordlists of Danish phone numbers filtered by area code and line type for security testing.

#python-tool#wordlist-generator#osint
Stars8
Forks3
Last commit4 years ago
nobility
nobilityShell

A Zsh-based pentesting framework with shell integrations for workflow automation, featuring 50+ modules and 500+ commands.

#shell-integration#workflow-automation#red-teaming
Stars4
Forks1
Last commit1 year ago
SecTester
SecTesterC#

Integrates Bright's DAST security scan engine directly into .NET unit tests to find vulnerabilities early.

#unit-testing#e2e#security
Stars3
Forks3
Last commit9 days ago
PreviousPage 2 of 2

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
2 years ago
#Penetration Testing33
#Security Tools25
#Security25
#Cybersecurity21
#Hacking18
#Python14
#Security Testing14
#Docker14
#Network Security13
#Security Tool9
#Password Cracking9
#Vulnerability Assessment8