There are 493 repositories under penetration-testing topic.
A collection of various awesome lists for hackers, pentesters and security researchers
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
This repository is primarily maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking / penetration testing, digital forensics and incident response (DFIR), vulnerability research, exploit development, reverse engineering, and more.
A collection of hacking / penetration testing resources to make you better!
A collection of hacking tools, resources and references to practice ethical hacking.
🐶 A curated list of Web Security materials and resources.
Web path scanner
hydra
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname
Infection Monkey - An open-source adversary emulation platform
Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.
A list of web application security
A curated list of awesome infosec courses and training resources.
Next generation web scanner
Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet
Top 100 Hacking & Security E-Books (Free Download)
🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩💻
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
All about bug bounty (bypasses, payloads, and etc)
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
Free Security and Hacking eBooks
The LAZY script will make your life easier, and of course faster.
The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
Tools and Techniques for Red Team / Penetration Testing