GitHub repo leaderboard by stars, growth rate and activity.
The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
🕵️♂️ (2-in-1) Email & Username OSINT suite featuring native MCP support for deep data extraction just from a single Email/Username. Analyzes 550+ actively maintained scan vectors (175+ email / 375+ username) for security research, investigations, and digital footprinting.
💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
Create a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab
Useful Techniques, Tactics, and Procedures for red teamers and defenders, alike!
🔐 Lockdoor Framework : A Penetration Testing framework with Cyber Security Resources
Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows machines. It tracks the user activity using screen capture and sends it to an attacker as an e-mail attachment.
| # | Repo | Language | Stars | 30-day trend | Last updated |
|---|---|---|---|---|---|
| 1 | The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks. | Go | 19,952 | last pushed 4 weeks ago | |
| 2 | A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more | Shell | 11,148 | last pushed 1 week ago | |
| 3 | 🕵️♂️ (2-in-1) Email & Username OSINT suite featuring native MCP support for deep data extraction just from a single Email/Username. Analyzes 550+ actively maintained scan vectors (175+ email / 375+ username) for security research, investigations, and digital footprinting. | Python | 4,742 | last pushed 2 days ago | |
| 4 | 💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh | Python | 4,303 | last pushed 2 weeks ago | |
| 5 | ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting. | PHP | 2,336 | last pushed 2 months ago | |
| 6 | Create a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab | PowerShell | 2,329 | last pushed 2 years ago | |
| 7 | Useful Techniques, Tactics, and Procedures for red teamers and defenders, alike! | Ruby | 1,903 | last pushed Yesterday | |
| 8 | 🔐 Lockdoor Framework : A Penetration Testing framework with Cyber Security Resources | Python | 1,550 | last pushed 1 year ago | |
| 9 | OffSec OSINT Pentest/RedTeam Tools | — | 1,272 | last pushed 1 month ago | |
| 10 | Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows machines. It tracks the user activity using screen capture and sends it to an attacker as an e-mail attachment. | Python | 1,206 | last pushed 4 years ago |
All · 11,474