pentest
Tracked open-source repos tagged pentest, sorted by stars.
- #31
A curated list of awesome OSCP resources
★ 3,471+0Star change over the last 7 days - #32★ 3,438+0Star change over the last 7 days
- #33
Awesome Node.js Security resources
★ 3,036+0Star change over the last 7 days - #34
🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.
★ 2,975+0Star change over the last 7 days - #35★ 2,886+0Star change over the last 7 days
- #36
List of Github repositories and articles with list of dorks for different search engines
★ 2,739+0Star change over the last 7 days - #37
Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network
★ 2,682+0Star change over the last 7 days - #38
SSRF (Server Side Request Forgery) testing resources
★ 2,507+0Star change over the last 7 days - #39
A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific misconfiguration or flaw in sudo to gain elevated privileges on the system, essentially allowing a regular user to execute commands as the root user.
★ 2,482+0Star change over the last 7 days - #40
LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)
★ 2,450+0Star change over the last 7 days - #41
Guia de Cyber Security: trilhas, cursos, livros, canais, ferramentas e comunidades para você entrar e evoluir na área.
★ 2,442+0Star change over the last 7 days - #42
Active Directory and Internal Pentest Cheatsheets
★ 2,393+0Star change over the last 7 days - #43★ 2,334+0Star change over the last 7 days
- #44
linWinPwn is a bash script that streamlines the use of a number of Active Directory tools
★ 2,201+0Star change over the last 7 days - #45
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.
★ 2,189+0Star change over the last 7 days - #46
Collection of quality safety articles. Awesome articles.
★ 2,116+0Star change over the last 7 days - #47
Notes about attacking Jenkins servers
★ 2,095+0Star change over the last 7 days - #48
Offensive Web Testing Framework (OWTF), is a framework which tries to unite great tools and make pen testing more efficient http://owtf.org https://twitter.com/owtfp
★ 1,952+0Star change over the last 7 days - #49
🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise. Effective.
★ 1,869+0Star change over the last 7 days - #50★ 1,783+0Star change over the last 7 days
- #51
RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact
★ 1,780+0Star change over the last 7 days - #52
jSQL Injection is a Java application for automatic SQL database injection.
★ 1,777+0Star change over the last 7 days - #53★ 1,776+0Star change over the last 7 days
- #54
Everything for pentest. | 渗透测试知识库,以 AI Agent 可执行的格式沉淀安全方法论。
★ 1,710+0Star change over the last 7 days - #55
GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)
★ 1,689+0Star change over the last 7 days - #56
ESP32-DIV HaleHound Edition for Cheap Yellow Display - Multi-protocol offensive security toolkit
★ 1,658+0Star change over the last 7 days - #57
A next generation version of enum4linux (a Windows/Samba enumeration tool) with additional features like JSON/YAML export. Aimed for security professionals and CTF players.
★ 1,647+0Star change over the last 7 days - #58★ 1,625+0Star change over the last 7 days
- #59
A curated list of awesome privilege escalation
★ 1,598+0Star change over the last 7 days - #60★ 1,553+0Star change over the last 7 days