Skip to main content
buildradar
Sign in
Topic · pentest

pentest

Tracked open-source repos tagged pentest, sorted by stars.

125 repos
  • A curated list of awesome OSCP resources

    3,471+0Star change over the last 7 days
  • BypassAV@matro7sh

    This map lists the essential techniques to bypass anti-virus and EDR

    3,438+0Star change over the last 7 days
  • Awesome Node.js Security resources

    3,036+0Star change over the last 7 days
  • CloudFlair@christophetd

    🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.

    2,975+0Star change over the last 7 days
  • pwndoc@pwndoc

    Pentest Report Generator

    2,886+0Star change over the last 7 days
  • List of Github repositories and articles with list of dorks for different search engines

    2,739+0Star change over the last 7 days
  • CloudFail@m0rtem

    Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network

    2,682+0Star change over the last 7 days
  • SSRF-Testing@cujanovic

    SSRF (Server Side Request Forgery) testing resources

    2,507+0Star change over the last 7 days
  • SUDO_KILLER@TH3xACE

    A tool designed to exploit a privilege escalation vulnerability in the sudo program on Unix-like systems. It takes advantage of a specific misconfiguration or flaw in sudo to gain elevated privileges on the system, essentially allowing a regular user to execute commands as the root user.

    2,482+0Star change over the last 7 days
  • LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)

    2,450+0Star change over the last 7 days
  • Guia de Cyber Security: trilhas, cursos, livros, canais, ferramentas e comunidades para você entrar e evoluir na área.

    2,442+0Star change over the last 7 days
  • InternalAllTheThings@swisskyrepo

    Active Directory and Internal Pentest Cheatsheets

    2,393+0Star change over the last 7 days
  • medusa@Ch0pin

    Mobile Edge-Dynamic Unified Security Analysis

    2,334+0Star change over the last 7 days
  • linWinPwn@lefayjey

    linWinPwn is a bash script that streamlines the use of a number of Active Directory tools

    2,201+0Star change over the last 7 days
  • Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.

    2,189+0Star change over the last 7 days
  • Collection of quality safety articles. Awesome articles.

    2,116+0Star change over the last 7 days
  • pwn_jenkins@gquere

    Notes about attacking Jenkins servers

    2,095+0Star change over the last 7 days
  • owtf@owtf

    Offensive Web Testing Framework (OWTF), is a framework which tries to unite great tools and make pen testing more efficient http://owtf.org https://twitter.com/owtfp

    1,952+0Star change over the last 7 days
  • nomore403@devploit

    🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise. Effective.

    1,869+0Star change over the last 7 days
  • metlo@metlo-labs

    Metlo is an open-source API security platform.

    1,783+0Star change over the last 7 days
  • pyrdp@GoSecure

    RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

    1,780+0Star change over the last 7 days
  • jSQL Injection is a Java application for automatic SQL database injection.

    1,777+0Star change over the last 7 days
  • odat@quentinhardy

    ODAT: Oracle Database Attacking Tool

    1,776+0Star change over the last 7 days
  • AboutSecurity@wgpsec

    Everything for pentest. | 渗透测试知识库,以 AI Agent 可执行的格式沉淀安全方法论。

    1,710+0Star change over the last 7 days
  • GraphQLmap@swisskyrepo

    GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)

    1,689+0Star change over the last 7 days
  • HaleHound-CYD@JesseCHale

    ESP32-DIV HaleHound Edition for Cheap Yellow Display - Multi-protocol offensive security toolkit

    1,658+0Star change over the last 7 days
  • enum4linux-ng@cddmp

    A next generation version of enum4linux (a Windows/Samba enumeration tool) with additional features like JSON/YAML export. Aimed for security professionals and CTF players.

    1,647+0Star change over the last 7 days
  • SSTImap@vladko312

    Automatic SSTI detection tool with interactive interface

    1,625+0Star change over the last 7 days
  • A curated list of awesome privilege escalation

    1,598+0Star change over the last 7 days
  • sx@v-byte-cpu

    :vulcan_salute: Fast, modern, easy-to-use network scanner

    1,553+0Star change over the last 7 days
← Back to topics