Automatic SQL injection and database takeover tool
Python
Updated Apr 30, 2019
Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool…
Python
Updated Mar 30, 2019
The Mobile Security Testing Guide (MSTG) is a comprehensive manual for mobile app security testing and reverse engin…
hydra
A swiss army knife for pentesting networks
Automated pentest framework for offensive security experts
Web path scanner
Python
Updated Apr 7, 2019
Collaborative Penetration Test and Vulnerability Management Platform
Python
Updated Apr 22, 2019
A collection of open source and commercial tools that aid in red team operations.
Updated Apr 14, 2019
巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。
Python
Updated Mar 20, 2019
An Information Security Reference That Doesn't Suck
Python
Updated Apr 10, 2019
Automated All-in-One OS command injection and exploitation tool.
Python
Updated Apr 25, 2019
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mo…
Updated Nov 12, 2018
The Leading Security Assessment Framework for Android.
Python
Updated Dec 10, 2018
Directory/file & DNS busting tool written in Go
Go
Updated Apr 29, 2019
Wiki to collect Red Team infrastructure hardening resources
Updated Mar 25, 2019
Cameradar hacks its way into RTSP videosurveillance cameras
The LAZY script will make your life easier, and of course faster.
Shell
Updated Mar 12, 2019
This is a multi-use bash script for Linux systems to audit wireless networks.
A high performance offensive security tool for reconnaissance and vulnerability scanning
Know the dangers of credential reuse attacks.
Python
Updated Mar 28, 2019
📡 A python program to create a fake AP and sniff data.
Python
Updated Feb 6, 2018
SubFinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework…
File upload vulnerability scanner and exploitation tool.
Python
Updated Feb 27, 2019
The cheat sheet about Java Deserialization vulnerabilities
Updated Mar 11, 2019
Abusing Certificate Transparency logs for getting HTTPS websites subdomains.
Python
Updated Mar 2, 2019
An evil RAT (Remote Administration Tool) for macOS / OS X.
Python
Updated Jan 18, 2019
Penetration Testing / OSCP Biggest Reference Bank / Cheatsheet
Updated Jan 15, 2019
Centralize Vulnerability Assessment and Management for DevSecOps Team
HTML
Updated Apr 27, 2019