There are 696 repositories under pentesting topic.
Hunt down social media accounts by username across social networks
Automatic SQL injection and database takeover tool
⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡
API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
A collection of hacking tools, resources and references to practice ethical hacking.
Web path scanner
The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
hydra
Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
The recursive internet scanner for hackers. 🧡
Test your prompts, agents, and RAGs. AI Red teaming, pentesting, and vulnerability scanning for LLMs. Compare performance of GPT, Claude, Gemini, Llama, and more. Simple declarative configs with command line and CI/CD integration.
A swiss army knife for pentesting networks
Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.
You Know, For WEB Fuzzing ! 日站用的字典。
The most powerful Android RPA agent framework, next generation of mobile automation robots.
This is a multi-use bash script for Linux systems to audit wireless networks.
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩💻
A list of web application security
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
Next generation web scanner
RogueMaster Flipper Zero Firmware