Showing 65 open source projects for "pentesting"

View related business solutions
  • Veeam Data Platform v13.1 - Get Your Free Trial Icon
    Veeam Data Platform v13.1 - Get Your Free Trial

    Secure by design, portable by default. Recover clean, fast, anywhere. Start a free trial.

    Try Veeam Data Platform today. Experience the unified platform that's secure by design, portable by default, and proven to recover clean, fast, and anywhere.
    Try it Free
  • Build Agents and Models on One Platform Icon
    Build Agents and Models on One Platform

    Everything you need to build production-ready agents and models. Access 200+ Google and third-party AI models and tools.

    Gemini Enterprise Agent Platform is Google Cloud's comprehensive platform for developers to build, scale, govern, and optimize agents and models. Choose from Google's most advanced models and third-party models like Anthropic's Claude Model Family.
    Start Free
  • 1
    Awesome Stars

    Awesome Stars

    A curated collection of top-tier penetration testing tools

    ...Because it aggregates rather than authors tooling, it serves as a navigation hub for both learners and seasoned testers. Actively starred and forked, signaling ongoing maintenance. Topic pages and GitHub listings surface it among popular pentesting resources, reinforcing its role as a go-to index.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 2
    PEASS-ng

    PEASS-ng

    Privilege Escalation Awesome Scripts SUITE

    These tools search for possible local privilege escalation paths that you could exploit and print them to you with nice colors so you can recognize the misconfigurations easily. All the scripts/binaries of the PEAS suite should be used for authorized penetration testing and/or educational purposes only. Any misuse of this software will not be the responsibility of the author or of any other collaborator. Use it at your own machines and/or with the owner's permission. Here you will find...
    Downloads: 42 This Week
    Last Update:
    See Project
  • 3
    secator

    secator

    Automated framework for running pentesting tools and workflows

    Secator is a task and workflow runner designed to streamline security assessments by integrating many well-known penetration testing and reconnaissance tools into a unified framework. It acts as a centralized automation platform that helps security professionals run tasks, workflows, and scans more efficiently from a single command-line interface. It supports dozens of established security tools and organizes them into structured workflows, enabling users to perform complex reconnaissance...
    Downloads: 12 This Week
    Last Update:
    See Project
  • 4
    OWASP Juice Shop

    OWASP Juice Shop

    Probably the most modern and sophisticated insecure web application

    ...The hacking progress is tracked on a scoreboard. Finding this scoreboard is actually one of the (easy) challenges! Apart from the hacker and awareness training use case, pentesting proxies or security scanners can use Juice Shop as a “guinea pig”-application to check how well their tools cope with JavaScript-heavy application frontends and REST APIs.
    Downloads: 0 This Week
    Last Update:
    See Project
  • Paessler: Easy to Use With Enterprise Power. Free Trial Icon
    Paessler: Easy to Use With Enterprise Power. Free Trial

    A low-code dashboard makes monitoring intuitive for any admin, while scripting and custom sensors give experts full control.

    You shouldn't have to choose between a monitoring tool that's easy to use and one that's powerful enough for a complex environment. PRTG's low-code interface lets any admin build dashboards, set alerts and monitor devices without scripting, while custom sensors and full API access are there when your team needs deeper control. One platform, no compromise. Download a free 30-day trial now.
    Get Free Download
  • 5
    OWASP Juice Shop

    OWASP Juice Shop

    Probably the most modern and sophisticated insecure web application

    ...The hacking progress is tracked on a score board. Finding this score board is actually one of the (easy) challenges! Apart from the hacker and awareness training use case, pentesting proxies or security scanners can use Juice Shop as a "guinea pig"-application to check how well their tools cope with JavaScript-heavy application frontends and REST APIs.
    Leader badge
    Downloads: 241 This Week
    Last Update:
    See Project
  • 6
    API-Sniffer-OS (ASOS)

    API-Sniffer-OS (ASOS)

    Local Kali OS wrapper for zero-latency browser pentesting.

    ...This gives bug bounty hunters a full hacking environment right next to their Network tab. Why ASOS? • Zero Latency: Runs on 127.0.0.1 for real-time, lag-free performance. • 100% Data Privacy: Your pentesting data never goes to a third-party cloud. • Offline Access: Perform local network testing without internet. • Seamless Setup: Run the .exe and background services initialize automatically. Requires Windows 10/11 with Virtual Machine & Hypervisor Platforms enabled.
    Downloads: 0 This Week
    Last Update:
    See Project
  • 7

    Hullu Vulnerable System

    Pentesting OVA, suits VMware or VirtualBox

    Hullu is a lightweight vulnerable Alpine Linux VM for cybersecurity education, ethical hacking practice, and isolated lab/CTF-style scenarios. It includes DVWA, FlaskVA, DNS Lab, BIND 9, Apache, MariaDB/MySQL, phpMyAdmin, SSH/SFTP, and optional FTP/Samba practice. Hullu 3 adds DNS Lab, BIND 9 interface, FTP/Samba server support, and separate service accounts for Flask-based services compared with Hullu 2. Use only in an isolated lab network. Do not expose this VM to the...
    Downloads: 1 This Week
    Last Update:
    See Project
  • 8
    Null-CLi

    Null-CLi

    Secure The Unknown

    NullSquare is an AI-powered security platform that can do both penetration testing and compliance auditing.
    Downloads: 2 This Week
    Last Update:
    See Project
  • 9
    ScaNetOS

    ScaNetOS

    Entorno funcional para auditoría web y pentesting

    ScaNetOS : Entorno de Auditoría Web Automatizada (v1.0) ScaNetOS es una Máquina Virtual en formato .OVA, diseñada para ser una máquina de análisis web y pentesting preconfigurada. Su objetivo es proporcionar un entorno de trabajo rápido y eficiente para pentesters éticos y analistas de seguridad enfocados en la auditoría de aplicaciones web y APIs. El corazón de esta MV es el ScaNet Panel (Script Bash v1.0), un menú centralizado que orquesta herramientas avanzadas y automatiza los flujos de trabajo más comunes, minimizando el tiempo de configuración. ...
    Downloads: 0 This Week
    Last Update:
    See Project
  • Fully Managed MySQL, PostgreSQL, and SQL Server Icon
    Fully Managed MySQL, PostgreSQL, and SQL Server

    Automatic backups, patching, replication, and failover. Focus on your app, not your database.

    Cloud SQL handles your database ops end to end, so you can focus on your app.
    Start Free
  • 10
    PVPLE
    VPLE (Linux) Vulnerable Pentesting Lab Environment VPLE is an Intentionally Vulnerable Linux Virtual Machine. This VM can be used to conduct security training, test security tools, and practice common penetration testing Labs. In VPLE bunch of labs are Available. NOTE:- "Only run in VMWare Pls Don’t run in VirtualBox" Will also run on the ProxMox server to understand how to do it pls refer to the doc in the zip named "Cybersecurity Lab Deployment on Proxmox" The default login and password is administrator: password. ...
    Downloads: 28 This Week
    Last Update:
    See Project
  • 11
    HunterX Offensive Security Engine
    HunterX AI-Assisted Offensive Security Engine Discover. Validate. Prove. Report. HunterX is not merely a vulnerability scanner. It is an open-source, AI-assisted offensive security engine for planning and running authorized security-assessment missions. It combines reconnaissance, security-tool orchestration, AI-assisted reasoning, hypothesis-driven investigation, vulnerability validation, evidence collection, proof / PoC engineering, replay / reproducibility, correlation, impact...
    Downloads: 8 This Week
    Last Update:
    See Project
  • 12
    T-PHANTOM OS

    T-PHANTOM OS

    Saudi cybersecurity Linux distro for DFIR and authorized pentesting

    T-PHANTOM OS is a Saudi cybersecurity Linux distribution developed by Eng. Talal Fawaz Al-Sohimiy. It is designed for DFIR, lawful digital-forensics investigations, incident response, authorized penetration testing, network analysis, reverse engineering, OSINT, security research, and cybersecurity training. T-PHANTOM OS 5.3 provides an organized KDE Plasma environment for cybersecurity professionals, DFIR specialists, researchers, students, and system administrators. The platform supports...
    Leader badge
    Downloads: 13 This Week
    Last Update:
    See Project
  • 13
    SnoopGod

    SnoopGod

    The #1 Linux CyberSecurity Operating System

    SnoopGod Linux is more than an operating system, it is a Free Open Source Community Project with the aim of promoting the culture of security in IT environment and give its contribution to make it better and safer. For more information feel free to visit our website https://snoopgod.com
    Downloads: 0 This Week
    Last Update:
    See Project
  • 14
    TinyPaw-Linux

    TinyPaw-Linux

    Passive & Aggressive WiFi attack distro

    Linux WiFi pentesting distribution built off Tiny Core Linux and inspired by the Xiaopan OS project. Lightweight with some new tools and updates to tools that have stood the test of time. Unfortunately at this time the TinyPaw-Linux project has been retired. This SourceForge will remain up, thank you for all the support and communities this project drew inspiration from.
    Leader badge
    Downloads: 40 This Week
    Last Update:
    See Project
  • 15
    CrackMapExec

    CrackMapExec

    A swiss army knife for pentesting networks

    CrackMapExec (CME) is a versatile post-exploitation and enumeration tool designed for pentesters and red teams to assess Active Directory environments. It supports credential spraying, command execution, file transfers, and module-based extensions across SMB, RDP, LDAP, and other protocols. CME provides automation and insight into Windows networks and is commonly used during lateral movement and domain enumeration phases.
    Downloads: 6 This Week
    Last Update:
    See Project
  • 16
    Pentest-Tools

    Pentest-Tools

    A collection of custom security tools for quick needs.

    ...It includes a wide range of tools for tasks like web scraping, reconnaissance, data extraction, and network analysis. The suite is modular, allowing users to choose the tools that best fit their specific pentesting needs, from web application analysis to network penetration testing.
    Downloads: 2 This Week
    Last Update:
    See Project
  • 17
    DroneSploit

    DroneSploit

    Drone pentesting framework console

    DroneSploit is a Python command-line framework for authorized security testing of drones and related wireless systems. Its interface is modeled after Metasploit to provide a familiar module-oriented workflow for security researchers. The framework gathers drone-specific assessment techniques and security modules in one console. Individual modules activate only when their required external tools and dependencies are available. Its architecture is built on the SploitKit framework and can be...
    Downloads: 5 This Week
    Last Update:
    See Project
  • 18
    IoT-PT

    IoT-PT

    A new pentesting virtual environment for IoT Devices

    OS info and Requirements Base OS : Lubuntu 18.04 LTS Processors : 2 (By default 4) RAM : 3GB (By default 8) VirtualBox 6+ username : iotpt ; password : iot1
    Downloads: 0 This Week
    Last Update:
    See Project
  • 19
    CyphyOS

    CyphyOS

    CyphyOS is Debian-based Distro for Cyber Physical System Hackers

    CyphyOS is Debian 10 x86_64 Based Distro Flavor, specifically for Cyber Physical System penetration testing. Powered with XFCE4. Out-Of-The-Box Dedicated to All Hardware Hackers. Especially for those who are still using the common pentesting tools and in need of hardware, Embedded System, IoT and SCADA tools as well. Also SDR tools are in place and configurations are made for HackRF, RTL-SDR and BladeRF. Tools Are Listed In Discussion Tab. Default Username : hackerman Default Password : cyphy
    Downloads: 3 This Week
    Last Update:
    See Project
  • 20
    ...IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES !!! ONLY FOR PENTESTING PURPOSES !!!
    Downloads: 13 This Week
    Last Update:
    See Project
  • 21
    VPLE

    VPLE

    Vulnerable Pentesting Lab Environment

    VPLE (Linux) Vulnerable Pentesting Lab Environment VPLE is an Intentionally Vulnerable Linux Virtual Machine. This VM can be used to conduct security training, test security tools, and practice common penetration testing Labs. In VPLE bunch of labs are Available. NOTE:- "Only run in VMWare Pls Don’t run in VirtualBox" The default login and password is administrator: password.
    Downloads: 17 This Week
    Last Update:
    See Project
  • 22
    cynuxsecurity

    cynuxsecurity

    Arch Linux Based Pentesting Distro

    Cynux Security is arch based pentesting distribution comes with 200+ most recommended tools by professionals. The current release is testing so it have some bugs. The creds are cynux:cynux To install cynux 0.1 cli installer is available @ https://github.com/cynuxsecurity/cynux-installer To install cynux v2021.0.1 Type `sudo install_cynux` in terminal
    Downloads: 6 This Week
    Last Update:
    See Project
  • 23
    Parrot Project

    Parrot Project

    Security, Development and Privacy Defense, all in one place.

    Parrot is a cloud friendly operating system designed for Pentesting, Computer Forensic, Reverse engineering, Hacking, Cloud pentesting, privacy/anonimity and cryptography. Based on Debian and developed by Frozenbox network.
    Leader badge
    Downloads: 77 This Week
    Last Update:
    See Project
  • 24
    WinPwn

    WinPwn

    Automation for internal Windows Penetrationtest / AD-Security

    WinPwn is a PowerShell-based toolkit for automating internal Windows penetration testing and Active Directory reconnaissance. It streamlines many manual steps by integrating reconnaissance modules like Seatbelt, Inveigh, Rubeus, and PrivescCheck. With proxy auto‑detection, endpoint enumeration, and exploitation routines, it's widely used in red team and blue team tool chains.
    Downloads: 1 This Week
    Last Update:
    See Project
  • 25
    mongoaudit

    mongoaudit

    A powerful MongoDB auditing and pentesting tool

    mongoaudit is a CLI tool for auditing MongoDB servers, detecting poor security settings and performing automated penetration testing. It is widely known that there are quite a few holes in MongoDB's default configuration settings. This fact, combined with abundant lazy system administrators and developers, has led to what the press has called the MongoDB apocalypse. mongoaudit not only detects misconfigurations, known vulnerabilities and bugs but also gives you advice on how to fix them,...
    Downloads: 0 This Week
    Last Update:
    See Project
  • Previous
  • You're on page 1
  • 2
  • 3
  • Next