The OWASP ZAP core project
The Pentester’s Companion
Privilege Escalation Awesome Scripts SUITE
Find vulnerabilities, misconfigurations, secrets, SBOM in containers
Security- and exploitation-oriented utilities and proof-of-concepts
Lightweight service virtualization/ API simulation / API mocking tool
Automatic SQL injection and database takeover tool
Gateway service providing dynamic routing, monitoring and more
Complete Mandiant Offensive VM (Commando VM)
API automation and load testing framework
Gives you one-liners that aids in penetration testing operations
Make security testing of K8s, Docker, and Containerd easier
Fully featured and community-driven hacking environment
Santetin is a website stress test and DDOS simulation tool
Wapiti is a web-application vulnerability scanner
A minimalistic, lean and fast HTTP REST API test application
Infection Monkey is a automated security testing tool for networks
ISB (I'm so bored) is a network stress-testing application for Windows
powerful SSH BruteForce tool
Best tools for 404 WebApp stress
Static Application Security Testing (SAST) engine
Advanced Network Packet Generator
Open-Source intelligence tracking and analysis tool.