Skip to main content
buildradar
Topic · pentesting

pentesting

Tracked open-source repos tagged pentesting, sorted by stars.

Repos
286
Total stars
1,080,742
Avg. stars
3,779
Share
0.06%

Topics that frequently appear alongside pentesting on the same repo.

Recent risers

Repos created in the last 90 days, tagged pentesting.

  • pentest-harness@S1N6H

    Pentest Harness — Heaven for Hackers. A self-hosted AI agent harness for authorized pentests, bug bounty, security labs, and CTFs. Bring your own AI model API; sessions stay local.

    297
  • Claude-AD@ADScanPro

    Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-team work (Kerberoasting, ADCS ESC1-17, DCSync, ACL abuse, NTLM relay, delegation), with per-technique OPSEC/telemetry notes. Drives netexec, impacket, certipy, bloodyAD, BloodHound CE.

    138
  • sherlock@sherlock-project

    Hunt down social media accounts by username across social networks

    90,598+647Star change over the last 7 days
  • shannon@KeygraphHQ

    Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

    47,285+285Star change over the last 7 days
  • sqlmap@sqlmapproject

    Automatic SQL injection and database takeover tool

    38,308+72Star change over the last 7 days
  • maigret@soxoj

    🕵️‍♂️ Collect a dossier on a person by username from 3000+ sites

    37,143+196Star change over the last 7 days
  • promptfoo@promptfoo

    Test your prompts, agents, and RAGs. Red teaming/pentesting/vulnerability scanning for AI. Compare performance of GPT, Claude, Gemini, DeepSeek, and more. Simple declarative configs with command line and CI/CD integration. Used by OpenAI and Anthropic.

    24,664+215Star change over the last 7 days
  • social-analyzer@qeeqbox

    API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites

    23,882+77Star change over the last 7 days
  • Ciphey@bee-san

    ⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡

    21,586+5Star change over the last 7 days
  • spiderfoot@smicallef

    SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

    21,504+176Star change over the last 7 days
  • RustScan@bee-san

    🤖 The Modern Port Scanner 🤖

    20,342+37Star change over the last 7 days
  • ffuf@ffuf

    Fast web fuzzer written in Go

    16,604+42Star change over the last 7 days
  • GhostTrack@HunxByts

    Useful tool to track location or mobile number

    14,957+61Star change over the last 7 days
  • dirsearch@maurosoria

    Web path scanner

    14,671+17Star change over the last 7 days
  • Directory/File, DNS and VHost busting tool written in Go

    14,052+46Star change over the last 7 days
  • juice-shop@juice-shop

    OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

    13,740+36Star change over the last 7 days
  • mastg@OWASP

    The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.

    13,143+17Star change over the last 7 days
  • thc-hydra@vanhauser-thc

    hydra

    12,215+38Star change over the last 7 days
  • hacktricks@HackTricks-wiki

    Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

    12,189+42Star change over the last 7 days
  • hetty@dstotijn

    An HTTP toolkit for security research.

    12,009+5Star change over the last 7 days
  • hexstrike-ai@0x4m4

    HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug bounty automation, and security research. Seamlessly bridge LLMs with real-world offensive security capabilities.

    11,433+161Star change over the last 7 days
  • Sn1per@1N3

    Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

    11,166+373Star change over the last 7 days
  • This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

    10,662+21Star change over the last 7 days
  • bbot@blacklanternsecurity

    The recursive internet scanner for hackers. 🧡

    10,515+37Star change over the last 7 days
  • wstg@OWASP

    The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

    9,763+42Star change over the last 7 days
  • rengine@yogeshojha

    reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.

    8,800+13Star change over the last 7 days
  • lamda@firerpa

    Android Full-Stack Device Control Platform: WebRTC/H.264 remote desktop, UI/OCR/image-matching automation, one-click MITM, built-in Frida, proxy/VPN/frp/P2P networking, MCP/Agent, 160+ APIs, designed for multi-device clusters and engineered deployments.

    8,258+39Star change over the last 7 days
  • reconftw@six2dez

    reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

    8,032+24Star change over the last 7 days
  • cve@trickest

    Gather and update all available and newest CVEs with their PoC.

    8,030+11Star change over the last 7 days
  • airgeddon@v1s1t0r1sh3r3

    This is a multi-use bash script for Linux systems to audit wireless networks.

    7,955+23Star change over the last 7 days
  • blackbird@p1ngul1n0

    An OSINT tool to search for accounts by username and email in social networks.

    7,894+101Star change over the last 7 days
  • 🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩‍💻

    7,681+21Star change over the last 7 days
← Back to topics