Skip to main content
Github-star-radar
Topic · penetration-testing

penetration-testing

Tracked open-source repos tagged penetration-testing, sorted by stars.

Repos
215
Total stars
944,994
Avg. stars
4,395
Share
0.05%

Topics that frequently appear alongside penetration-testing on the same repo.

Recent risers

Repos created in the last 90 days, tagged penetration-testing.

  • AutoCVE@larlarua

    Agent-driven automated CVE discovery platform for source code auditing, vulnerability verification, and report generation.

    1,347
  • recon-skills@uphiago

    Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh

    1,206
  • dianxing@tianchong-zerotemp

    DianXing - AI-Driven End-to-End Code Security Auditing

    871
  • Cybermes@Zyrexnn

    Autonomous Offensive Security, Bug Bounty & Red Teaming Agent Framework powered by Hermes Agent, specialized reasoning skills, and multi-model LLM orchestration.

    656
  • pentestcode@s0ld13rr

    PentestCode - Multi-agent AI penetration testing system with persistent engagement state, strategic coordination, and parallel autonomous operations.

    513
  • Awesome-Hacking@Hack-with-Github

    A collection of various awesome lists for hackers, pentesters and security researchers

    119,322+539Star change over the last 7 days
  • PayloadsAllTheThings@swisskyrepo

    A list of useful payloads and bypass for Web Application Security and Pentest/CTF

    80,484+226Star change over the last 7 days
  • strix@usestrix

    Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

    59,293+2,514Star change over the last 7 days
  • shannon@KeygraphHQ

    Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

    47,285+285Star change over the last 7 days
  • 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

    31,614+1,069Star change over the last 7 days
  • h4cker@The-Art-of-Hacking

    This repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security, vulnerability research, exploit development, reverse engineering, and more. 🔥 Also check: https://hackertraining.org

    29,190+123Star change over the last 7 days
  • pentagi@vxcontrol

    Fully autonomous AI Agents system capable of performing complex penetration testing tasks

    22,169+220Star change over the last 7 days
  • A collection of hacking / penetration testing resources to make you better!

    17,364+26Star change over the last 7 days
  • PentestGPT@GreyDGL

    Automated Penetration Testing Agentic Framework Powered by Large Language Models

    15,139+138Star change over the last 7 days
  • dirsearch@maurosoria

    Web path scanner

    14,671+17Star change over the last 7 days
  • Osintgram@Datalux

    Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname

    14,173+102Star change over the last 7 days
  • awesome-web-security@qazbnm456

    🐶 A curated list of Web Security materials and resources.

    13,740+23Star change over the last 7 days
  • thc-hydra@vanhauser-thc

    hydra

    12,215+38Star change over the last 7 days
  • Sn1per@1N3

    Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

    11,166+373Star change over the last 7 days
  • nishang@samratashok

    Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

    10,074+11Star change over the last 7 days
  • wstg@OWASP

    The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

    9,763+42Star change over the last 7 days
  • Tools and Techniques for Red Team / Penetration Testing

    9,672+27Star change over the last 7 days
  • A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑

    9,029+7Star change over the last 7 days
  • rengine@yogeshojha

    reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.

    8,800+13Star change over the last 7 days
  • reconftw@six2dez

    reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

    8,032+24Star change over the last 7 days
  • cve@trickest

    Gather and update all available and newest CVEs with their PoC.

    8,030+11Star change over the last 7 days
  • commando-vm@mandiant

    Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com

    7,794+7Star change over the last 7 days
  • 🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩‍💻

    7,681+21Star change over the last 7 days
  • 渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms

    7,477+12Star change over the last 7 days
  • A list of web application security

    7,249+8Star change over the last 7 days
  • monkey@guardicore

    Infection Monkey - An open-source adversary emulation platform

    7,079+5Star change over the last 7 days
  • WhatWeb@urbanadventurer

    Next generation web scanner

    6,803+11Star change over the last 7 days
  • A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

    6,720+9Star change over the last 7 days
  • faraday@infobyte

    Open Source Vulnerability Management Platform

    6,698+7Star change over the last 7 days
  • osmedeus@j3ssie

    A Modern Orchestration Engine for Security

    6,540+11Star change over the last 7 days
← Back to topics