There are 59 repositories under penetration-testing-tools topic.
Next generation web scanner
Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).
一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。
SSH based reverse shell
Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).
Statically-linked ssh server with reverse shell functionality for CTFs and such
Dangerously fast DNS/network/port scanner
JustTryHarder, a cheat sheet which will aid you through the PWK course & the OSCP Exam. (Inspired by PayloadAllTheThings)
An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
✨ Fully autonomous AI Agents system capable of performing complex penetration testing tasks
Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.
A rapid API for the Project Sonar dataset
新一代Webshell管理器,兼容蚁剑与冰蝎的PHP webshell
A command-line utility designed to discover URLs for a given domain in a simple, efficient way. It works by gathering information from a variety of passive sources, meaning it doesn't interact directly with the target but instead gathers data that is already publicly available.
A repository of tools for pentesting of restricted and isolated environments.
Pen Test Report Generation and Assessment Collaboration
Pentesting and Bug Bounty Notes, Cheetsheets and Guide for Ethical Hacker, Whitehat Pentesters and CTF Players.
Collection of cheat sheets useful for pentesting
Redeye is a tool intended to help you manage your data during a pentest operation
A Golang implant that uses Slack as a command and control server
Nimbo-C2 is yet another (simple and lightweight) C2 framework
Cervantes is an open-source, collaborative platform designed specifically for pentesters and red teams. It serves as a comprehensive management tool, streamlining the organization of projects, clients, vulnerabilities, and reports in a single, centralized location.
Penetration Testing and Hacking CTF's Swiss Army Knife with: Reverse Shell Handling - Encoding/Decoding - Encryption/Decryption - Cracking Hashes / Hashing
Second-order subdomain takeover scanner
Collection of Pentest Notes and Cheatsheets
Little Bug Bounty & Hacking Tools⚔️
A Security Tool for Enumerating WebSockets