Highlights
Stars
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.
Automatic SQL injection and database takeover tool
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
E-mails, subdomains and names Harvester - OSINT
Exploitation Framework for Embedded Devices
Incredibly fast crawler designed for OSINT.
Fast subdomains enumeration tool for penetration testers
Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C
Rewrite of the popular wireless network auditor, "wifite"
Game Agent Framework. Helping you create AIs / Bots that learn to play any game you own!
Infection Monkey - An open-source adversary emulation platform
Automated All-in-One OS Command Injection Exploitation Tool.
w3af: web application attack and audit framework, the open source web vulnerability scanner.
Email OSINT & Password breach hunting tool, locally or using premium services. Supports chasing down related email
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
The Leading Security Assessment Framework for Android.
Continuously jam all wifi clients/routers
Printer Exploitation Toolkit - The tool that made dumpster diving obsolete.
Server-Side Template Injection and Code Injection Detection and Exploitation Tool
Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique present…
Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, co…
Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.
PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others.
A DNS meta-query spider that enumerates DNS records, and subdomains.
Detect and bypass web application firewalls and protection systems