Penetration Open Source Projects

Browse 193 Penetration open source projects, ranked by GitHub stars. Find the most popular Penetration tools and libraries.

Share your experience:✍️ Write a Post❓ Ask a Question
1-60 of 193 projects
44,382 stars

mitmproxy/mitmproxy

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

Metrics details
Stars44,382
37,951 stars

sqlmapproject/sqlmap

Automatic SQL injection and database takeover tool

Metrics details
Stars37,951
34,138 stars

ehang-io/nps

一款轻量级、高性能、功能强大的内网穿透代理服务器。支持tcp、udp、socks5、http等几乎所有流量转发,可用来访问内网网站、本地支付接口调试、ssh访问、远程桌面,内网dns解析、内网socks5代理等等……,并带有功能强大的web管理端。a lightweight, high-performance, powerful intranet penetration proxy server, with a powerful web management terminal.

Metrics details
Stars34,138
28,537 stars

The-Art-of-Hacking/h4cker

This repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security, vulnerability research, exploit development, reverse engineering, and more. 🔥 Also check: https://hackertraining.org

Metrics details
Stars28,537
26,672 stars

enaqx/awesome-pentest

A collection of awesome penetration testing resources, tools and other shiny things

Metrics details
Stars26,672
18,064 stars

Micropoor/Micro8

Gitbook

Metrics details
Stars18,064
16,030 stars

CISOfy/lynis

Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.

Metrics details
Stars16,030
14,642 stars

sbilly/awesome-security

A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.

Metrics details
Stars14,642
14,043 stars

projectdiscovery/subfinder

Fast passive subdomain enumeration tool.

Metrics details
Stars14,043
12,198 stars

Manisso/fsociety

fsociety Hacking Tools Pack – A Penetration Testing Framework

Metrics details
Stars12,198
11,682 stars

apsdehal/awesome-ctf

A curated list of CTF frameworks, libraries, resources and softwares

Metrics details
Stars11,682
10,946 stars

beefproject/beef

The Browser Exploitation Framework Project

Metrics details
Stars10,946
7,115 stars

infoslack/awesome-web-hacking

A list of web application security

Metrics details
Stars7,115
6,660 stars

infobyte/faraday

Open Source Vulnerability Management Platform

Metrics details
Stars6,660
5,580 stars

OlivierLaflamme/Cheatsheet-God

Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet

Metrics details
Stars5,580
5,547 stars

trustedsec/ptf

The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.

Metrics details
Stars5,547
5,432 stars

OWASP/Nettacker

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Metrics details
Stars5,432
5,368 stars

drk1wi/Modlishka

Modlishka. Reverse Proxy.

Metrics details
Stars5,368
4,709 stars

cdk-team/CDK

📦 Make security testing of K8s, Docker, and Containerd easier.

Metrics details
Stars4,709
4,685 stars

may215/awesome-termux-hacking

⚡️An awesome list of the best Termux hacking tools

Metrics details
Stars4,685
3,745 stars

nixawk/pentest-wiki

PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others.

Metrics details
Stars3,745
3,447 stars

0x4D31/awesome-oscp

A curated list of awesome OSCP resources

Metrics details
Stars3,447
3,432 stars

BlackArch/blackarch

An ArchLinux based distribution for penetration testers and security researchers.

Metrics details
Stars3,432
2,989 stars

mgeeky/Penetration-Testing-Tools

A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security audits purposes.

Metrics details
Stars2,989
2,654 stars

netbiosX/Checklists

Red Teaming & Pentesting checklists for various engagements

Metrics details
Stars2,654
2,323 stars

ssl/ezXSS

ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.

Metrics details
Stars2,323
2,085 stars

13o-bbr-bbq/machine_learning_security

Source code about machine learning and security.

Metrics details
Stars2,085
1,948 stars

owtf/owtf

Offensive Web Testing Framework (OWTF), is a framework which tries to unite great tools and make pen testing more efficient http://owtf.org https://twitter.com/owtfp

Metrics details
Stars1,948
1,926 stars

ReAbout/web-sec

WEB安全手册(红队安全技能栈),漏洞理解,漏洞利用,代码审计和渗透测试总结。【持续更新】

Metrics details
Stars1,926
1,906 stars

fabionoth/awesome-cyber-security

A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.

Metrics details
Stars1,906
1,717 stars

1ndianl33t/Bug-Bounty-Roadmaps

Bug Bounty Roadmaps

Metrics details
Stars1,717
1,615 stars

wwong99/pentest-notes

Metrics details
Stars1,615
1,584 stars

ffffffff0x/AboutSecurity

Everything for pentest. | 用于渗透测试的 payload 和 bypass 字典.

Metrics details
Stars1,584
1,465 stars

inguardians/peirates

Peirates - Kubernetes Penetration Testing tool

Metrics details
Stars1,465
1,389 stars

andrewjkerr/security-cheatsheets

🔒 A collection of cheatsheets for various infosec tools and topics.

Metrics details
Stars1,389
1,358 stars

kaiiyer/awesome-vulnerable

A curated list of VULNERABLE APPS and SYSTEMS which can be used as PENETRATION TESTING PRACTICE LAB.

Metrics details
Stars1,358
1,329 stars

infobyte/evilgrade

Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates.

Metrics details
Stars1,329
1,264 stars

screetsec/Brutal

Payload for teensy like a rubber ducky but the syntax is different. this Human interfaes device ( HID attacks ). Penetration With Teensy . Brutal is a toolkit to quickly create various payload,powershell attack , virus attack and launch listener for a Human Interface Device ( Payload Teensy )

Metrics details
Stars1,264
1,261 stars

Jack-Liang/kalitools

Kali Linux工具清单

Metrics details
Stars1,261
1,119 stars

jhaddix/pentest-bookmarks

a collection of handy bookmarks

Metrics details
Stars1,119
1,099 stars

prateek147/DVIA-v2

Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security enthusiasts/professionals or students to test their iOS penetration testing skills in a legal environment. This project is developed and maintained by @prateekg147. The vulnerabilities and solutions covered in this app are tested up to iOS 11. The current version is writen in Swift and has the following vulnerabilities.

Metrics details
Stars1,099
1,067 stars

iphelix/dnschef

DNSChef - DNS proxy for Penetration Testers and Malware Analysts

Metrics details
Stars1,067
1,048 stars

rastating/wordpress-exploit-framework

A Ruby framework designed to aid in the penetration testing of WordPress systems.

Metrics details
Stars1,048
985 stars

secureCodeBox/secureCodeBox

secureCodeBox (SCB) - continuous secure delivery out of the box

Metrics details
Stars985
980 stars

RustyShackleford221/OSCP-Prep

A comprehensive guide/material for anyone looking to get into infosec or take the OSCP exam

Metrics details
Stars980
977 stars

tcostam/awesome-command-control

A collection of awesome Command & Control (C2) frameworks, tools and resources for post-exploitation and red teaming assignments.

Metrics details
Stars977
941 stars

sh377c0d3/Payloads

Payload Arsenal for Pentration Tester and Bug Bounty Hunters

Metrics details
Stars941
931 stars

knownsec/404StarLink-Project

Focus on promoting the evolution of tools in different aspects of security research.专注于推动安全研究各个领域工具化.(项目收录逐步迁移至 https://github.com/knownsec/404StarLink)

Metrics details
Stars931
866 stars

0xdea/tactical-exploitation

Modern tactical exploitation toolkit.

Metrics details
Stars866
834 stars

sinfulz/JustTryHarder

JustTryHarder, a cheat sheet which will aid you through the PWK course & the OSCP Exam. (Inspired by PayloadAllTheThings)

Metrics details
Stars834
834 stars

ivan-sincek/penetration-testing-cheat-sheet

Work in progress...

Metrics details
Stars834
792 stars

monkeylord/XServer

A Xposed Module for Android Penetration Test, with NanoHttpd.

Metrics details
Stars792
775 stars

bahaabdelwahed/killshot

A Penetration Testing Framework, Information gathering tool & Website Vulnerability Scanner

Metrics details
Stars775
670 stars

theLSA/CS-checklist

PC客户端(C-S架构)渗透测试checklist / Client side(C-S) penetration checklist

Metrics details
Stars670
646 stars

scooderic/exhentai-tags-chinese-translation

E-Hentai/ExHentai 全部 TAGs 中文翻译

Metrics details
Stars646
645 stars

danfis/libccd

Library for collision detection between two convex shapes

Metrics details
Stars645
546 stars

emilyanncr/Windows-Post-Exploitation

Windows post-exploitation tools, resources, techniques and commands to use during post-exploitation phase of penetration test. Contributions are appreciated. Enjoy!

Metrics details
Stars546
541 stars

p3nt4/Nuages

A modular C2 framework

Metrics details
Stars541
540 stars

Aptive/penetration-testing-tools

Penetration Testing tools - one repo to clone them all... containing latest pen testing tools

Metrics details
Stars540
534 stars

x3omdax/PenBox

PenBox - A Penetration Testing Framework - The Tool With All The Tools , The Hacker's Repo

Metrics details
Stars534
1-60 of 193 projects
Get A Weekly Email With Trending Penetration Projects
Stay updated on Penetration plus related topics you pick below.

Copyright 2018-2026 Awesome Open Source.  All rights reserved.