GitHub repo leaderboard by stars, growth rate and activity.
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.
Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation improves the next.
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh
A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.
| # | Repo | Language | Stars | 30-day trend | Last updated |
|---|---|---|---|---|---|
| 1 | Open-source AI penetration testing tool to find and fix your app’s vulnerabilities. | Python | 61,565 | last pushed Yesterday | |
| 2 | Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production. | TypeScript | 47,886 | last pushed 2 days ago | |
| 3 | HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities. | Python | 11,760 | last pushed 1 month ago | |
| 4 | Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections. | Shell | 11,218 | last pushed 2 months ago | |
| 5 | A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑 | — | 9,041 | last pushed 4 weeks ago | |
| 6 | Next generation web scanner | Ruby | 6,829 | last pushed 5 months ago | |
| 7 | The system of action for AI-native cybersecurity—where intent becomes governed execution, evidence becomes operational memory, and every operation improves the next. | Go | 6,492 | last pushed 3 days ago | |
| 8 | Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management | Python | 5,558 | last pushed Yesterday | |
| 9 | 💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh | Python | 4,303 | last pushed 2 weeks ago | |
| 10 | A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell. | Python | 3,489 | last pushed 2 years ago |
All · 11,474