Showing 21 of 57 projects
A steganography brute-force utility that uncovers hidden data inside files by trying passwords from a wordlist.
A TCP connection hijacking tool written in Rust, enabling packet injection into established connections.
A framework for exploiting DNS rebinding vulnerabilities to bypass Same-Origin Policy and attack internal networks from browsers.
A CLI tool to export OWASP Juice Shop security challenges into CTFd, RootTheBox, or FBCTF compatible formats.
A bug hunting tool that scans websites for exposed .git repositories and dumps their contents for security analysis.
A Python toolkit for security Capture The Flag (CTF) challenges, providing utilities for crypto, shellcodes, and network connections.
An automated security testing toolkit for GraphQL endpoints that discovers, analyzes, and scores vulnerabilities.
A web interface for Hashcat that enables distributed password cracking sessions across multiple servers with real-time results.
A collection of French and English wordlists specifically curated for cracking French passwords.
Visualizes AWS IAM and Organizations as a graph using Neo4j to identify security anomalies and privilege escalation paths.
A terminal-based manager for handling multiple reverse shell sessions and clients during penetration testing.
An open-source Java proxy for penetration testing, enabling traffic analysis and modification of TCP/UDP application protocols.
A minimal command-line utility for connecting to and exploiting exposed CEF/Electron debuggers during security assessments.
A Python script that generates graphs and charts from password cracking results (hashcat/john potfiles) for security analysis.
A dependency-aware GraphQL API fuzzing tool that automatically generates and executes security tests based on schema introspection.
A pentest tool that checks Cloudflare-protected sites for origin IP leaks and misconfigurations.
A fast GraphQL discovery and fingerprinting toolbox for security testing and reconnaissance.
A Python script that implements security testing attacks against AWS Cognito, including account oracle and privilege escalation.
An automated IAST fuzzer for discovering vulnerabilities in CakePHP web applications with minimal false positives.
A standardized methodology for performing security assessments in robotics across physical, network, firmware, and application layers.
A Python-based honeypot suite for SSH, FTP, and Telnet that captures credentials to build attack dictionaries.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.