awesome-repositories.com
المدونة
MCP
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعخادم MCPحولكيفية ترتيب النتائجالصحافة
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

56 مستودعات

Awesome GitHub RepositoriesVulnerability Exploitation Frameworks

Specialized frameworks for detecting and exploiting specific vulnerabilities in CMS, middleware, and applications.

Explore 56 awesome GitHub repositories matching part of an awesome list · Vulnerability Exploitation Frameworks. Refine with filters or upvote what's useful.

Awesome Vulnerability Exploitation Frameworks GitHub Repositories

اعثر على أفضل المستودعات باستخدام الذكاء الاصطناعي.سنبحث عن أفضل المستودعات المطابقة باستخدام الذكاء الاصطناعي.
  • manisso/fsocietyالصورة الرمزية لـ Manisso

    Manisso/fsociety

    12,136عرض على GitHub↗

    fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits. It functions as a wrapper that integrates external security binaries into a unified, menu-driven interface, providing a centralized system for command-line parameter mapping and execution. The project distinguishes itself by organizing specialized utilities into domain-specific collections for structured navigation. It automates the transition between different phases of an audit by chaining reconnaissance and exploitation tools through sequential workflow automation. The fram

    Launches automated exploits against web applications and services to confirm unauthorized access.

    Pythonbrute-force-attacksdesktopexploitation
    عرض على GitHub↗12,136
  • liamg/traitorالصورة الرمزية لـ liamg

    liamg/traitor

    7,144عرض على GitHub↗

    Traitor is a Linux privilege escalation framework and automated root exploit suite. It provides specialized utilities for scanning system misconfigurations and deploying automated exploit scripts on local Linux hosts to elevate user privileges to the root level. The tool identifies insecure system setups and binary vulnerabilities, such as GTFOBins, to map potential routes for gaining root access. It automates the process of discovering and exploiting these local vulnerabilities through targeted exploit execution and the deployment of sequential scripts. The system covers vulnerability asses

    Runs a predetermined sequence of vulnerability triggers to automatically establish a root shell.

    Gocve-2021-3560cve-2022-0847dirtypipe
    عرض على GitHub↗7,144
  • guardicore/monkeyالصورة الرمزية لـ guardicore

    guardicore/monkey

    7,014عرض على GitHub↗

    Monkey is an adversary emulation platform and breach and attack simulation tool designed to test network defenses through automated lateral movement and exploit delivery. It functions as a network security testing system that evaluates security posture by attempting to propagate through vulnerabilities and extract sensitive system credentials. The platform distinguishes itself by simulating specific real-world attacker behaviors, such as ransomware encryption, cryptojacking, and the theft of browser-stored credentials and secure shell keys. It utilizes binary hash randomization to evade antiv

    Uses a library of plugins to propagate through known network vulnerabilities and test security perimeters.

    Python
    عرض على GitHub↗7,014
  • k8gege/k8toolsالصورة الرمزية لـ k8gege

    k8gege/K8tools

    6,167عرض على GitHub↗

    K8tools is a multi-stage attack framework that combines memory-only payload execution, credential testing, port forwarding, privilege escalation, and physical USB-based keystroke injection for comprehensive system compromise. At its core, the Ladon PowerShell module loads a multi-function scanner directly into memory, enabling command execution without writing files to disk, while supporting memory-only payload delivery that downloads and runs obfuscated shellcode or PowerShell commands to evade antivirus detection. The framework distinguishes itself through its breadth of integrated capabili

    Launches pre-built exploits against web applications, operating systems, and services.

    PowerShell0daybrute-forcebypass
    عرض على GitHub↗6,167
  • commixproject/commixالصورة الرمزية لـ commixproject

    commixproject/commix

    5,757عرض على GitHub↗

    Commix is an automated tool for detecting and exploiting OS command injection vulnerabilities in web applications. It probes user-supplied input vectors with heuristic test payloads, analyzes response differences to identify injection points, and then automates the execution of arbitrary operating system commands on the target server. The tool distinguishes itself through a multi-layer filter bypass engine that evaluates input constraints independently per filter type and composes tailored evasion strategies into a single payload. A modular payload tamper pipeline transforms raw injection str

    Automates the detection and exploitation of OS command injection vulnerabilities to execute arbitrary commands on target servers.

    Python
    عرض على GitHub↗5,757
  • nullarray/autosploitالصورة الرمزية لـ NullArray

    NullArray/AutoSploit

    5,240عرض على GitHub↗

    AutoSploit هو إطار عمل استغلال مؤتمت مصمم لاكتشاف المضيفين البعيدين وتنفيذ وحدات الاستغلال على نطاق واسع لإنشاء قذائف عكسية (reverse shells). يعمل كأداة لاستطلاع الشبكة ومنسق لتنفيذ الكود عن بُعد، ويدير نشر وحدات الهجوم ضد أهداف متعددة. يتميز النظام بقناع حركة مرور قائم على الوكيل يوجه طلبات الشبكة عبر خوادم خارجية ويدور رؤوس HTTP ووكلاء المستخدم لإخفاء مصدر النشاط. ويسمح بتنسيق الاستغلال المخصص من خلال دمج وحدات الهجوم الخارجية وإدارة معلمات اتصال مساحة العمل. يغطي إطار العمل اكتشاف الأهداف عبر استعلامات محركات البحث وتكاملات API، بالإضافة إلى إدارة قائمة الأهداف باستخدام ملفات خارجية وقوائم بيضاء. كما يتضمن قدرات لتكوين المستمع القائم على الجلسة لالتقاط الاتصالات البعيدة الواردة.

    Automates the execution of multiple exploit modules against targets to achieve remote code execution at scale.

    Python
    عرض على GitHub↗5,240
  • andresriancho/w3afالصورة الرمزية لـ andresriancho

    andresriancho/w3af

    4,850عرض على GitHub↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    Tests the viability of discovered security holes to confirm if they permit unauthorized access or data extraction.

    Pythonappseccross-site-scriptingscanner
    عرض على GitHub↗4,850
  • zhzyker/exphubالصورة الرمزية لـ zhzyker

    zhzyker/exphub

    4,282عرض على GitHub↗

    Exphub is a CVE exploit script library and enterprise software vulnerability suite designed to verify and exploit known security flaws in server environments such as WebLogic, Struts2, Tomcat, and JBoss. It functions as a remote code execution toolkit and a web shell deployment framework for triggering unauthorized command execution and establishing persistent access on remote systems. The project includes specialized utilities for internal network reconnaissance, specifically using server-side request forgery to scan for open ports and services. It further provides mechanisms for bypassing a

    Provides a framework for detecting and exploiting security flaws in middleware and application frameworks.

    Pythoncve-2020-10199cve-2020-10204cve-2020-11444
    عرض على GitHub↗4,282
  • jtesta/ssh-auditالصورة الرمزية لـ jtesta

    jtesta/ssh-audit

    4,218عرض على GitHub↗

    هذا المشروع عبارة عن أداة تدقيق أمان SSH مصممة لتحليل تهيئات الخادم والعميل. تعمل كمحلل تشفيري يقيم تبادل المفاتيح، و MAC، وخوارزميات التشفير لتحديد البدائيات الضعيفة أو القديمة وضمان الامتثال الأمني. تتميز الأداة بتوفير دليل تقوية مع تعليمات تهيئة خاصة بالمنصة وتوصيات خوارزمية لمعالجة الثغرات المكتشفة. كما تتضمن مختبراً لهجمات حجب الخدمة (DoS) يقيس مرونة الخادم ضد استنفاد وحدة المعالجة المركزية وهجمات اتصال المقبس المتزامنة. تغطي القدرات الواسعة تدقيق الأمان واختبار الثغرات، بما في ذلك التحقق من سياسات الأمان وتحديد إصدارات البرمجيات. يقوم المشروع أيضاً بإجراء تحقق تشفيري من خلال اختبار حجم معامل Diffie-Hellman ويقيم سلوك برمجيات العميل عبر تحليل قائم على المستمع (listener-based).

    Identifies the specific SSH software version by matching supported algorithms and banner strings against a known database.

    Python
    عرض على GitHub↗4,218
  • epinna/tplmapالصورة الرمزية لـ epinna

    epinna/tplmap

    4,169عرض على GitHub↗

    tplmap هي أداة أمنية مصممة لاكتشاف واستغلال ثغرات حقن القوالب من جانب الخادم (Server-Side Template Injection). تعمل كماسح آلي لتحديد سياقات محركات القوالب المعرضة للخطر وتوفر إطار عمل لتحقيق تنفيذ الأوامر عن بُعد. تركز الأداة على ترجمة الطلبات عالية المستوى إلى صيغة برمجية خاصة بالمحرك لتنفيذ أوامر نظام التشغيل وتجاوز بيئات الحماية (sandboxes) الخاصة بالتطبيقات. كما تتيح الوصول إلى نظام الملفات عن بُعد، مما يسمح للمستخدمين بقراءة وكتابة ونقل الملفات بين الجهاز المحلي والخادم المستهدف. تشمل القدرات الإضافية إمكانية تشغيل خوادم محلية مصابة لمحاكاة بيئات معيبة للتحقق من الحمولات (payloads). يدعم المشروع أيضاً التكامل مع وكلاء أمن الويب (web security proxies) لأتمتة حقن حمولات الاختبار في حركة المرور المعترضة.

    Detects and exploits server-side template injection.

    Python
    عرض على GitHub↗4,169
  • retirejs/retire.jsالصورة الرمزية لـ RetireJS

    RetireJS/retire.js

    4,141عرض على GitHub↗

    Retire.js هو ماسح ضوئي للثغرات الأمنية في JavaScript ومحلل لأمن التبعيات. يقوم بتحديد مكتبات JavaScript القديمة أو غير الآمنة التي تحتوي على ثغرات أمنية معروفة داخل تطبيقات الويب والمشاريع المحلية. تعمل الأداة كأداة تدقيق لأمن الويب يمكن استخدامها أثناء اختبار الاختراق لاكتشاف النصوص البرمجية الضعيفة على المواقع الحية. كما تدعم إنشاء قائمة مواد البرمجيات (SBOM) باستخدام تنسيق CycloneDX لتوثيق تبعيات المشروع. يستخدم النظام الكشف عن المكتبات القائم على التوقيع ومطابقة الأنماط لمقارنة الإصدارات المحددة بقاعدة بيانات أمنية تعتمد على JSON. تشمل إمكانيات المسح استخدام متصفحات بدون واجهة رسومية (headless browsers) لتحليل النصوص البرمجية التي يتم تحميلها بواسطة التطبيقات الحية.

    Detects vulnerable JavaScript libraries.

    JavaScriptbuild-toolchrome-extensionfirefox-extension
    عرض على GitHub↗4,141
  • knownsec/pocsuite3الصورة الرمزية لـ knownsec

    knownsec/pocsuite3

    3,853عرض على GitHub↗

    Pocsuite3 is a modular vulnerability testing framework designed for the development and execution of security assessment scripts. It provides a comprehensive toolkit for remote vulnerability verification and exploitation, enabling users to automate the identification of security flaws across network targets. The framework is built on an object-oriented scripting architecture that allows for the creation of custom security modules and plugins. It distinguishes itself through a highly extensible design that supports asynchronous task execution for large-scale infrastructure assessments, alongsi

    Provides a modular framework for developing and executing security assessment scripts to identify and exploit vulnerabilities across network targets.

    Pythonpentestingpythonsecurity
    عرض على GitHub↗3,853
  • cloudsploit/scansالصورة الرمزية لـ cloudsploit

    cloudsploit/scans

    3,748عرض على GitHub↗

    This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr

    Security scanning checks for AWS environments.

    JavaScript
    عرض على GitHub↗3,748
  • mbechler/marshalsecالصورة الرمزية لـ mbechler

    mbechler/marshalsec

    3,691عرض على GitHub↗

    Marshalsec is a toolkit designed for generating malicious serialized Java objects to achieve remote code execution during the unmarshalling process. It functions as a Java deserialization exploit tool and a framework for triggering Java Naming and Directory Interface lookups to remote servers. The project provides a JNDI redirector service that intercepts lookups and points targets toward a remote codebase. It includes utilities for crafting payloads that force Java applications to download and execute arbitrary classes from a remote URL. The toolset covers security analysis activities inclu

    Generates payloads to trigger remote code execution by forcing Java applications to perform external JNDI lookups.

    Java
    عرض على GitHub↗3,691
  • lijiejie/githackالصورة الرمزية لـ lijiejie

    lijiejie/GitHack

    3,550عرض على GitHub↗

    GitHack is a .git folder disclosure exploit.

    Exploits .git folder disclosures.

    Python
    عرض على GitHub↗3,550
  • jaykali/maskphishالصورة الرمزية لـ jaykali

    jaykali/maskphish

    3,020عرض على GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Provides a framework to apply predefined exploits against targets identified through network scanning.

    Shellhackhackinghacking-tool
    عرض على GitHub↗3,020
  • tuhinshubhra/cmseekالصورة الرمزية لـ Tuhinshubhra

    Tuhinshubhra/CMSeeK

    2,543عرض على GitHub↗

    CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 180 other CMSs

    Suite for CMS detection and exploitation.

    Pythonbruteforcecmscms-bruteforce
    عرض على GitHub↗2,543
  • joaomatosf/jexbossالصورة الرمزية لـ joaomatosf

    joaomatosf/jexboss

    2,512عرض على GitHub↗

    jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit deserialization flaws to achieve remote code execution on target servers. It functions as a suite of tools for delivering payloads and executing system commands on vulnerable remote applications. The project includes a reverse shell orchestrator to establish and maintain persistent remote command connections from exploited targets back to a listener. It also provides post-exploitation automation for managing remote access and updating software on compromised systems. The fra

    Provides a framework to deliver specialized Java deserialization payloads to achieve remote code execution.

    Pythondeserializationexploitexploiting-vulnerabilities
    عرض على GitHub↗2,512
  • lijiejie/bbscanالصورة الرمزية لـ lijiejie

    lijiejie/BBScan

    2,372عرض على GitHub↗

    BBScan 是一个高并发的、轻量级的Web漏洞扫描工具。它帮助安全工程师从大量目标中,快速发现,定位可能存在弱点的目标,辅助半自动化测试。

    Batch web vulnerability scanner.

    Python
    عرض على GitHub↗2,372
  • anouarbensaad/vulnxالصورة الرمزية لـ anouarbensaad

    anouarbensaad/vulnx

    2,074عرض على GitHub↗

    Automated CMS injection and vulnerability scanner.

    Pythonauto-exploiterbotcloudflare-detection
    عرض على GitHub↗2,074
السابق123التالي
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Vulnerability Exploitation Frameworks

استكشف الوسوم الفرعية

  • Batch Exploit Execution2 وسوم فرعيةAutomated systems for running multiple exploit payloads against a set of compatible vulnerabilities. **Distinct from Vulnerability Exploitation Frameworks:** Distinct from Vulnerability Exploitation Frameworks: focuses on the batch processing and conditional execution of multiple exploits
  • Router Exploit ExecutionExecution of specific exploit modules against router vulnerabilities for unauthorized access. **Distinct from Vulnerability Exploitation Frameworks:** Focuses on the target device (routers) rather than general CMS or middleware frameworks.
  • Web Application Exploits1 وسم فرعيSpecialized techniques and payloads for verifying vulnerabilities in web applications to confirm unauthorized access or data extraction. **Distinct from Vulnerability Exploitation Frameworks:** Focuses specifically on web-layer vulnerabilities rather than general CMS or middleware frameworks.