Topic: penetration-testing

7,402 repositories

usestrix/strix

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

★ 65,881PythonForks 7,220

KeygraphHQ/shannon

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

★ 48,515TypeScriptForks 5,556

mukul975/Anthropic-Cybersecurity-Skills

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

★ 33,648PythonForks 4,079

The-Art-of-Hacking/h4cker

This repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security, vulnerability research, exploit development, reverse engineering, and more. 🔥 Also check: https://hackertraining.org

★ 29,584Jupyter NotebookForks 5,391

vxcontrol/pentagi

Fully autonomous AI Agents system capable of performing complex penetration testing tasks

★ 25,171GoForks 3,238

GreyDGL/PentestGPT

Automated Penetration Testing Agentic Framework Powered by Large Language Models

★ 15,658PythonForks 2,723

sundowndev/hacker-roadmap

A collection of hacking tools, resources and references to practice ethical hacking.

★ 15,626Forks 1,716

Datalux/Osintgram

Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname

★ 14,734PythonForks 3,145

1N3/Sn1per

Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

★ 11,291ShellForks 2,195

samratashok/nishang

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

★ 10,124PowerShellForks 2,542

OWASP/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

★ 9,927PythonForks 1,692

We5ter/Scanners-Box

The Ultimate Open-Source Security Arsenal for Hackers, Enterprises, and AI Agents——面向极客、企业与 AI 智能体的全域开源网络安全工具矩阵

★ 9,077Forks 2,420

yogeshojha/rengine

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.

★ 8,866HTMLForks 1,344

six2dez/reconftw

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

★ 8,163ShellForks 1,238

trickest/cve

Gather and update all available and newest CVEs with their PoC.

★ 8,116HTMLForks 979

mandiant/commando-vm

Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. [email protected]

★ 7,811PowerShellForks 1,372

Mr-xn/Penetration_Testing_POC

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms

★ 7,501HTMLForks 2,036

guardicore/monkey

Infection Monkey - An open-source adversary emulation platform

★ 7,096PythonForks 826

infobyte/faraday

Open-source and AI-powered cybersecurity tools for offensive security, vulnerability management, and autonomous pentesting. Built by hackers in Latin America, used worldwide.

★ 6,761PythonForks 1,074