17 projects
Metasploit Framework
Metasploit Framework is an open-source penetration testing and exploitation framework that provides tools and resources for security professionals to test system vulnerabilities, develop and execute exploit code, and perform security assessments. It includes a collection of tested exploits, auxiliary modules, and post-exploitation tools.
6,706
587
$86M
BeEF
The Browser Exploitation Framework Project
BlackArch Linux
An ArchLinux based distribution for penetration testers and security researchers.
CALDERA
Automated Adversary Emulation Platform
Hashcat
World's fastest and most advanced password recovery utility
Impacket
Impacket is a collection of Python classes for working with network protocols.
John the Ripper Jumbo
John the Ripper jumbo - advanced offline password cracker, which supports hundreds of hash and cipher types, and runs on many operating systems, CPUs, GPUs, and even some FPGAs
MobSF
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
Nikto
Nikto web server scanner
OpenVAS
This repository contains the scanner component for Greenbone Community Edition.
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Pwnagotchi
(⌐■_■) - Raspberry Pi instrumenting Bettercap for Wi-Fi pwning.
Pwntools
CTF framework and exploit development library
SecLists
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
The Social-Engineer Toolkit
The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.
mitmproxy
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
reNgine
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.