A collection of various awesome lists for hackers, pentesters and security researchers
Penetration Testing GitHub Repositories
Explore popular GitHub repositories tagged “penetration-testing”.
Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.
Trending Repositories
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
This repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security, vulnerability research, exploit development, reverse engineering, and more. 🔥 Also check: https://hackertraining.org
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Fully autonomous AI Agents system capable of performing complex penetration testing tasks
A collection of hacking / penetration testing resources to make you better!
Automated Penetration Testing Agentic Framework Powered by Large Language Models
Web path scanner
Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname
🐶 A curated list of Web Security materials and resources.
Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
Tools and Techniques for Red Team / Penetration Testing
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.
Gather and update all available and newest CVEs with their PoC.
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com
🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩💻
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
A list of web application security
Infection Monkey - An open-source adversary emulation platform
All about bug bounty (bypasses, payloads, and etc)
Next generation web scanner
A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
Open Source Vulnerability Management Platform