Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Security Testing

Security Testing

143 projects

Showing 36 of 143 projects

PayloadsAllTheThings
PayloadsAllTheThingsPython

A comprehensive collection of payloads and bypass techniques for web application security testing and penetration testing.

#vulnerability-exploitation#vulnerability#pentest
Stars79.4k
Forks17.2k
Last commit
SecLists
SecListsPHP

A comprehensive collection of security testing wordlists and payloads for penetration testers and security researchers.

#vulnerability-assessment#fuzzing-payloads#web-security
Stars72.4k
Forks25.1k
Last commit21 hours ago
Big List of Naughty Strings
Big List of Naughty StringsPython

A curated list of strings likely to cause issues when used as user-input data, for automated and manual QA testing.

#software-testing#unicode#input-validation
Stars47.7k
Forks2.2k
Last commit
SQLMap
SQLMapPython

An open-source penetration testing tool that automates SQL injection detection and database takeover.

#security testing tool#python-tool#vulnerability-assessment
Stars38.0k
Forks6.3k
Last commit21 hours ago
setoolkit
setoolkitPython

An open-source penetration testing framework for social engineering with custom attack vectors to create believable attacks quickly.

#attack-framework#social-engineering#kali-linux
Stars15.1k
Forks3.4k
Last commit1 month ago
OWASP Mobile Security Testing Guide
OWASP Mobile Security Testing GuidePython

A comprehensive manual for mobile app security testing and reverse engineering, aligned with OWASP MASVS and MASWE.

#ios-app#runtime-analysis#mobile-security
Stars13.1k
Forks2.8k
Last commit2 days ago
Scapy
ScapyPython

A Python-based interactive packet manipulation program and library for network analysis, scanning, and security testing.

#pcap#python-library#network-scanner
Stars12.4k
Forks2.2k
Last commit1 day ago
Atomic Red Team
Atomic Red TeamC

A library of portable detection tests mapped to the MITRE ATT&CK framework for security testing.

#mitre#command-line-tools#detection-validation
Stars12.3k
Forks3.2k
Last commit3 days ago
webshell
webshellPHP

A collection of webshell scripts in various languages for security testing and research purposes.

#webshell-sniper#aspx#cybersecurity-research
Stars10.8k
Forks5.6k
Last commit1 year ago
FuzzDB
FuzzDBPHP

The most comprehensive open dictionary of attack patterns, predictable resource locations, and regex for black-box application security testing.

#resource-discovery#vulnerability-discovery#attack-patterns
Stars9.0k
Forks2.1k
Last commit2 years ago
Garak
GarakPython

A command-line tool for red-teaming and vulnerability scanning of large language models (LLMs).

#ai#vulnerability-assessment#ai-safety
Stars8.6k
Forks1.1k
Last commit9 hours ago
Caldera
CalderaPython

An automated cyber security platform for adversary emulation, red teaming, and incident response built on the MITRE ATT&CK framework.

#mitre#caldera#security-automation
Stars7.1k
Forks1.4k
Last commit7 hours ago
al-khaser
al-khaserC++

A proof-of-concept malware application that implements common anti-analysis techniques to test security tools and sandbox environments.

#anti-debugging#windows-security#evasion-techniques
Stars7.1k
Forks1.3k
Last commit23 days ago
Infection Monkey
Infection MonkeyPython

An open-source adversary emulation platform that simulates malware attacks to test and improve network security defenses.

#vulnerability-assessment#infection-monkey#malware-simulation
Stars7.0k
Forks823
Last commit1 year ago
AFL++
AFL++C

AFL++ is a community-enhanced, high-performance fork of the AFL fuzzer with advanced instrumentation, mutators, and speed improvements.

#software-testing#fuzzer#fuzzer-afl
Stars6.7k
Forks1.3k
Last commit17 hours ago
syzkaller
syzkallerGo

An unsupervised coverage-guided kernel fuzzer for finding bugs in operating system kernels like Linux, Windows, and BSD variants.

#fuzzer#operating-systems#bug-discovery
Stars6.3k
Forks1.4k
Last commit16 hours ago
go-fuzz
go-fuzzGo

A coverage-guided fuzzing solution for testing Go packages, especially those parsing complex or untrusted inputs.

#randomized-testing#input-parsing#fuzzing
Stars4.9k
Forks276
Last commit1 year ago
Drozer
DrozerPython

A security testing framework for Android that identifies vulnerabilities by interacting with apps, IPC endpoints, and the OS.

#vulnerability-assessment#mobile-security#android-framework
Stars4.6k
Forks842
Last commit3 months ago
Invoke-Obfuscation
Invoke-ObfuscationPowerShell

A PowerShell v2.0+ compatible command and script obfuscation framework for security testing.

#windows-security#obfuscation#scripting
Stars4.3k
Forks816
Last commit2 years ago
Pafish
PafishC

A testing tool that detects virtual machines and malware analysis environments using techniques observed in real malware.

#sandbox#windows-security#anti-analysis
Stars3.9k
Forks495
Last commit2 years ago
Honggfuzz
HonggfuzzC

A security-oriented, feedback-driven, evolutionary software fuzzer that uses hardware and software code coverage to find bugs.

#software-testing#vulnerability-discovery#oss-fuzz
Stars3.4k
Forks536
Last commit1 month ago
fuzz.txt
fuzz.txt

A collection of potentially dangerous file names and paths for security testing and fuzzing.

#vulnerability#vulnerability-discovery#files
Stars3.3k
Forks525
Last commit11 months ago
Runtime Mobile Security (RMS)
Runtime Mobile Security (RMS)JavaScript

A web interface powered by FRIDA for runtime manipulation, analysis, and security testing of Android and iOS applications.

#runtime-analysis#mobile-security#ios
Stars3.1k
Forks411
Last commit
Bad SSL
Bad SSLHTML

A collection of test subdomains with intentionally broken SSL configurations for testing client security behavior.

#certificate-validation#ssl-testing#web-security
Stars3.0k
Forks204
Last commit1 month ago
Nogotofail
NogotofailPython

An on-path blackbox network traffic security testing tool for detecting weak TLS/SSL connections and cleartext traffic.

#traffic-analysis#ssl-testing#vulnerability-scanning
Stars3.0k
Forks410
Last commit3 years ago
H5SC
H5SCJavaScript

A comprehensive collection of HTML5-related XSS attack vectors and testing resources for web security professionals.

#web-security#xss#vulnerability-database
Stars2.9k
Forks415
Last commit4 years ago
RESTler
RESTlerPython

A stateful REST API fuzzing tool that automatically tests cloud services to find security and reliability bugs.

#rest-api#api-fuzzing#automated-testing
Stars2.9k
Forks329
Last commit1 month ago
OneFuzz
OneFuzzC#

A self-hosted Fuzzing-As-A-Service platform for continuous developer-driven fuzzing to harden software prior to release.

#software-hardening#fuzzing#ci-cd-integration
Stars2.8k
Forks202
Last commit2 years ago
APTSimulator
APTSimulatorBatchfile

A Windows Batch script toolset that simulates Advanced Persistent Threat (APT) attack indicators to test security monitoring and detection capabilities.

#apt-simulation#red-team-tool#detection-validation
Stars2.8k
Forks452
Last commit
LibAFL
LibAFLRust

A modular Rust library for building fast, scalable, and customizable fuzzers that work across multiple platforms and instrumentation backends.

#fuzzing-framework#binary-only#embedded-fuzzing
Stars2.6k
Forks476
Last commit11 days ago
Some-PoC-oR-ExP
Some-PoC-oR-ExPPython

A collection of proof-of-concept (PoC) and exploit (Exp) scripts for various security vulnerabilities.

#exploit-development#vulnerability-analysis#penetration-testing
Stars2.5k
Forks966
Last commit1 year ago
OWASP MASVS
OWASP MASVSPython

The OWASP Mobile Application Security Verification Standard (MASVS) is the industry standard for mobile app security.

#app-security#mobile-security#standard
Stars2.4k
Forks708
Last commit7 months ago
Testing
Testing

A curated collection of software testing tools, frameworks, books, blogs, and resources for testers and developers.

#software-testing#naughty-strings#qa-resources
Stars2.3k
Forks385
Last commit1 day ago
Awesome Testing
Awesome Testing

A curated collection of software testing tools, frameworks, books, blogs, and resources for testers and developers.

#software-testing#naughty-strings#qa-resources
Stars2.3k
Forks385
Last commit1 day ago
HTTPLeaks
HTTPLeaksHTML

A comprehensive HTML file enumerating all possible ways a website can leak HTTP requests for security testing.

#web-security#http-leaks#html-security
Stars2.1k
Forks204
Last commit6 months ago
PEzor
PEzorC

An open-source packer that converts executables and shellcode into stealthy, evasive payloads for Windows.

#red-team-tool#hacktoberfest#anti-debug
Stars2.1k
Forks326
Last commit2 years ago
Page 1 of 4

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
17 hours ago
2 years ago
2 days ago
10 months ago
Next
#Penetration Testing44
#Fuzzing30
#Cybersecurity22
#Security17
#Python16
#Automated Testing14
#Pentesting14
#Password Cracking14
#Hashcat13
#Web Security13
#Docker12
#Vulnerability Discovery11