awesome-repositories.com
المدونة
MCP
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعحولكيفية ترتيب النتائجالصحافةخادم MCP
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

أدوات الهجوم والفريق الأحمر

تم تحديث الترتيب في 23 يونيو 2026

For أدوات الهجوم والفريق الأحمر (Red Teaming), the strongest matches are z4nzu/hackingtool (This project is a comprehensive cybersecurity tool collection designed), swisskyrepo/payloadsallthethings (This project is a comprehensive, community-sourced knowledge base designed) and fireeye/commando-vm (Commando-VM is a Windows penetration testing distribution and offensive). samratashok/nishang and rapid7/metasploit-framework round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

استكشف إطارات العمل، وحمولات الاستغلال (exploits)، وأدوات التقييم الأمني المستخدمة في اختبار الاختراق وفريق الهجوم (Red Teaming).

أدوات الهجوم والفريق الأحمر

اعثر على أفضل المستودعات باستخدام الذكاء الاصطناعي.سنبحث عن أفضل المستودعات المطابقة باستخدام الذكاء الاصطناعي.
  • z4nzu/hackingtoolالصورة الرمزية لـ Z4nzu

    Z4nzu/hackingtool

    77,515عرض على GitHub↗

    This project is a comprehensive cybersecurity tool collection designed to support security research, penetration testing, and vulnerability assessment. It functions as a unified penetration testing suite, providing a centralized environment where professionals can access a wide range of offensive security utilities to identify system weaknesses and study attack vectors. The platform distinguishes itself through a modular architecture that aggregates disparate security scripts into a single, hierarchical command-line interface. It simplifies the management of these utilities by integrating ext

    PythonExploit FrameworksHash Cracking ToolsPenetration Testing Suites
    عرض على GitHub↗77,515
  • swisskyrepo/payloadsallthethingsالصورة الرمزية لـ swisskyrepo

    swisskyrepo/PayloadsAllTheThings

    78,434عرض على GitHub↗

    This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers. It functions as a centralized repository of offensive security techniques, providing a structured collection of exploit payloads, attack vectors, and methodologies for conducting vulnerability assessments and penetration testing. The repository distinguishes itself through a cross-platform payload taxonomy that categorizes exploitation methods by vulnerability type and target environment, enabling rapid lookup during security assessments. It maintains high standards of data i

    PythonCommunity-Sourced Knowledge BasesOffensive Security CheatsheetsRemote File Inclusion Payloads
    عرض على GitHub↗78,434
  • fireeye/commando-vmالصورة الرمزية لـ fireeye

    fireeye/commando-vm

    7,668عرض على GitHub↗

    Commando-VM is a Windows penetration testing distribution and offensive security toolkit. It provides a specialized virtual machine environment loaded with a curated suite of security auditing and exploitation tools designed for red teaming operations. The project facilitates the creation of red team infrastructure and security audit environments. It focuses on windows security auditing and penetration testing to help simulate adversary behavior and identify exploitable security flaws. The environment is established through script-based provisioning and modular toolset deployment. This proce

    PowerShellOffensive & Red Team OperationsInstallation ScriptsOffensive Security Operations
    عرض على GitHub↗7,668
  • samratashok/nishangالصورة الرمزية لـ samratashok

    samratashok/nishang

    9,951عرض على GitHub↗

    Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows targets. It functions as a post-exploitation toolkit and payload generator to automate attacks and manage remote targets. The project provides specialized capabilities for bypassing security controls, such as disabling the Antimalware Scan Interface and employing in-memory execution to avoid disk-based detection. It includes a variety of stealthy command and control mechanisms, utilizing non-standard channels like DNS TXT records, ICMP traffic, and webmail for communication a

    PowerShellOffensive & Red Team OperationsPost-Exploitation ToolkitsAMSI Bypasses
    عرض على GitHub↗9,951
  • rapid7/metasploit-frameworkالصورة الرمزية لـ rapid7

    rapid7/metasploit-framework

    38,415عرض على GitHub↗

    The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures. The platform distinguishes itself through a modular architecture that supports reflective payload injection, allowing for the execution of code directly in memory without writing to disk. It utilizes an asynchronous event loop to

    RubyPenetration Testing PlatformsExploit FrameworksExploitation Frameworks
    عرض على GitHub↗38,415
  • kgretzky/evilginx2الصورة الرمزية لـ kgretzky

    kgretzky/evilginx2

    14,627عرض على GitHub↗

    Evilginx2 is a man-in-the-middle phishing framework designed to proxy authentication traffic between a user and a target web service. By acting as a reverse proxy, the tool intercepts and relays web requests to capture credentials and session tokens in real time, enabling the bypass of multi-factor authentication mechanisms through session cookie hijacking. The platform distinguishes itself by integrating infrastructure orchestration with modular template-driven content injection. It automates the deployment of proxy servers, manages the lifecycle of encryption certificates, and applies conte

    GoMan-in-the-Middle FrameworksSession-Based Authentication ProxiesPhishing Attack Tools
    عرض على GitHub↗14,627
  • sqlmapproject/sqlmapالصورة الرمزية لـ sqlmapproject

    sqlmapproject/sqlmap

    37,676عرض على GitHub↗

    This project is an automated security testing suite designed to detect and exploit database vulnerabilities. It functions as a command-line utility that streamlines the identification, verification, and exploitation of web application flaws by automating the injection of malicious payloads into input parameters. The tool provides a comprehensive framework for database enumeration, allowing users to extract schema information, user data, and system configurations from identified injection points. What distinguishes this tool is its sophisticated engine for dynamic payload adaptation and heuris

    PythonInjection TestersSQL Injection ToolsDatabase Enumerators
    عرض على GitHub↗37,676
  • powershellmafia/powersploitالصورة الرمزية لـ PowerShellMafia

    PowerShellMafia/PowerSploit

    12,880عرض على GitHub↗

    PowerSploit is a collection of PowerShell modules designed for security assessment, penetration testing, and red team operations. It provides a framework for auditing Windows system configurations and evaluating the effectiveness of security defenses within an enterprise environment. The framework focuses on techniques that leverage native system administration tools and scripting environments to perform operations. It includes capabilities for executing arbitrary commands, escalating user privileges, and maintaining system persistence through event subscriptions. By utilizing in-memory execu

    PowerShellPenetration Testing SuitesOffensive & Red Team OperationsArbitrary
    عرض على GitHub↗12,880
  • apsdehal/awesome-ctfالصورة الرمزية لـ apsdehal

    apsdehal/awesome-ctf

    11,614عرض على GitHub↗

    This project is a comprehensive directory of software utilities, frameworks, and educational resources designed for cybersecurity competitions and offensive security research. It serves as a centralized index for tools used in cryptography, forensics, reverse engineering, and web exploitation, while providing structured materials for training and skill development. The repository distinguishes itself through a community-driven maintenance model that aggregates and organizes technical resources into a searchable, hierarchical structure. It facilitates knowledge transfer by cataloging expert pr

    JavaScriptCapture The Flag CompetitionsAwesome ListCTF Hosting Platforms
    عرض على GitHub↗11,614
  • valdikss/goodbyedpiالصورة الرمزية لـ ValdikSS

    ValdikSS/GoodbyeDPI

    27,936عرض على GitHub↗

    GoodbyeDPI is a censorship circumvention utility designed to bypass deep packet inspection and restrictive network filtering. It functions as a background engine that intercepts and modifies network traffic at the kernel level, allowing users to maintain connectivity in environments where specific protocols or web content are blocked. The tool employs active manipulation techniques to confuse inspection hardware, including TCP stream fragmentation, HTTP header obfuscation, and the injection of out-of-order packets. By altering packet structures and dropping specific redirection patterns, it m

    CCensorship Circumvention ToolsDPI Evasion ToolsActive DPI Circumvention
    عرض على GitHub↗27,936
  • mxrch/ghuntالصورة الرمزية لـ mxrch

    mxrch/GHunt

    19,089عرض على GitHub↗

    GHunt is a Google account investigator and open-source intelligence framework designed to retrieve publicly available information and metadata associated with Google accounts. It functions as an OSINT data extractor and offensive security framework used to identify user identities and uncover hidden metadata. The tool extracts public profile data from various Google services and exports the findings into structured JSON formats. This allows for the collection and analysis of digital footprints to support security research and reconnaissance.

    PythonGoogle Account OSINTAccount DiscoveryOffensive Security Frameworks
    عرض على GitHub↗19,089
  • huiyadanli/revokemsgpatcherالصورة الرمزية لـ huiyadanli

    huiyadanli/RevokeMsgPatcher

    37,926عرض على GitHub↗

    RevokeMsgPatcher is a binary patching utility designed to modify the execution logic of desktop messaging applications. By applying low-level changes to compiled executable files and libraries, the tool enables functionality not natively supported by the original software, specifically focusing on message persistence and process management. The utility distinguishes itself through targeted binary instrumentation and control flow redirection. It identifies specific function patterns and memory offsets within proprietary software to inject custom assembly instructions. These modifications allow

    C#Message Recall Prevention ToolsReverse Engineering ToolsMessaging Client Enhancers
    عرض على GitHub↗37,926
  • princeton-nlp/swe-agentالصورة الرمزية لـ princeton-nlp

    princeton-nlp/SWE-agent

    19,540عرض على GitHub↗

    SWE-agent is a collection of autonomous agents designed for software engineering, competitive programming, and offensive cybersecurity operations. These agents utilize large language models to navigate codebases, interact with file systems, and use terminal interfaces to resolve GitHub issues or complete technical challenges. The system employs specialized agent modes that switch prompting strategies based on whether the task is a software bug, an algorithmic programming problem, or a security vulnerability. It includes dedicated capabilities for automated repository maintenance and offensive

    PythonAutomated Fix VerifiersAutomated Issue ResolversAutomated Software Engineering Agents
    عرض على GitHub↗19,540
  • trimstray/the-book-of-secret-knowledgeالصورة الرمزية لـ trimstray

    trimstray/the-book-of-secret-knowledge

    228,641عرض على GitHub↗

    This project serves as a centralized, community-driven repository of technical knowledge and administrative resources. It provides a structured taxonomy that aggregates disparate information into a searchable framework, supporting continuous learning and rapid problem-solving for system administrators and cybersecurity practitioners. By mapping resources across offensive security, infrastructure management, and software development, it offers a unified path for skill acquisition and professional reference. The project is defined by a command-line-first design philosophy, prioritizing terminal

    Awesome ListHyperlink-Centric Knowledge MapsSystem Administration Operations
    عرض على GitHub↗228,641
  • revanced/revanced-managerالصورة الرمزية لـ ReVanced

    ReVanced/revanced-manager

    25,932عرض على GitHub↗

    ReVanced Manager is an Android application patcher designed to modify compiled mobile binaries. It enables users to inject custom features, alter runtime behavior, and remove interface elements without requiring access to original source code. The utility distinguishes itself by performing all operations locally on the user device, ensuring privacy by avoiding external server dependencies. It automates the entire modification lifecycle, including the retrieval of application files, the application of bytecode-level patches, and the generation of new cryptographic signatures to ensure the resu

    DartBinary PatchersMobile Device Control UtilitiesBehavior Modifiers
    عرض على GitHub↗25,932
  • orange-cyberdefense/arsenalالصورة الرمزية لـ Orange-Cyberdefense

    Orange-Cyberdefense/arsenal

    3,686عرض على GitHub↗

    Arsenal is a terminal command inventory and launcher designed to manage curated libraries of shell syntax and markdown-based cheatsheets. It functions as a searchable repository for complex terminal operations, allowing users to import structured text files and execute commands within a managed environment. The tool integrates with terminal multiplexers to launch commands in separate panes, decoupling execution from the main interface. It features a variable manager that defines global arguments, such as target addresses, which are automatically mapped into command templates to eliminate repe

    PythonCommand Library ManagementCLI Parameter ManagersCommand Injection Tools
    عرض على GitHub↗3,686
  • dnspy/dnspyالصورة الرمزية لـ dnSpy

    dnSpy/dnSpy

    28,993عرض على GitHub↗

    dnSpy is a desktop application designed for the analysis, debugging, and modification of compiled .NET assemblies. It functions as an assembly analysis suite and decompiler, translating binary instruction streams back into readable source code to facilitate reverse engineering when original source files are unavailable. The tool distinguishes itself through an integrated binary patching engine and metadata editor, which allow for the direct modification of executable logic and internal metadata tables. It supports in-process debugging instrumentation, enabling users to inject runtime hooks, s

    C#DebuggersDecompilersReverse Engineering Tools
    عرض على GitHub↗28,993
  • peass-ng/peass-ngالصورة الرمزية لـ peass-ng

    peass-ng/PEASS-ng

    19,337عرض على GitHub↗

    PEASS-ng is an automated penetration testing framework designed to identify privilege escalation vectors on local systems. It functions as a security assessment utility that scans environments for misconfigurations, sensitive files, and insecure permissions to uncover paths for unauthorized privilege elevation. The project distinguishes itself through a modular script-based enumeration engine that adapts to the target environment. It utilizes environment-aware capability detection and cross-platform shell abstraction to normalize data collection across diverse operating systems, while operati

    C#Penetration Testing SuitesPrivilege Escalation ToolsLinux Enumeration
    عرض على GitHub↗19,337
  • danielmiessler/seclistsالصورة الرمزية لـ danielmiessler

    danielmiessler/SecLists

    71,596عرض على GitHub↗

    SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities. The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution log

    PHPSecurity WordlistsVulnerability Assessment and TestingAwesome List
    عرض على GitHub↗71,596
  • topjohnwu/magiskالصورة الرمزية لـ topjohnwu

    topjohnwu/Magisk

    60,989عرض على GitHub↗

    Magisk is an Android rooting framework designed to manage system-level modifications and grant administrative access to mobile devices. It functions by patching boot and recovery images to inject custom code into the operating system initialization sequence, allowing for system-wide control while maintaining compatibility with the underlying hardware. The project distinguishes itself through a systemless modification layer that overlays a virtual file system on top of read-only partitions, enabling changes without altering core system files. It includes a policy daemon to manage security cont

    KotlinAndroid Rooting FrameworksDevice Modification ManagersFirmware Customization Tools
    عرض على GitHub↗60,989
  • shadow1ng/fscanالصورة الرمزية لـ shadow1ng

    shadow1ng/fscan

    13,421عرض على GitHub↗

    Fscan is an automated penetration testing tool designed for internal network reconnaissance and vulnerability assessment. It functions as a comprehensive security framework that maps network infrastructure, identifies active hosts and services, and detects security weaknesses across internal environments. The tool distinguishes itself through a modular plugin architecture that allows for extensible security checks and a stateful asset tracking system that maintains an in-memory registry of discovered infrastructure. It incorporates a dedicated credential brute-force engine for testing passwor

    GoNetwork Reconnaissance ToolsPenetration Testing ToolsVulnerability Assessment Frameworks
    عرض على GitHub↗13,421
  • gitleaks/gitleaksالصورة الرمزية لـ gitleaks

    gitleaks/gitleaks

    24,973عرض على GitHub↗

    Gitleaks is a security scanning engine designed to identify hardcoded credentials, API keys, and other sensitive information within version control systems and local file structures. It functions as a static analysis tool that automates the detection of secrets, helping to prevent the accidental exposure of sensitive data during the development lifecycle. The tool distinguishes itself through its ability to perform deep forensic analysis of git history, allowing users to audit entire project timelines or enforce security gates within continuous integration pipelines. It supports complex detec

    GoSecret DetectionSecret Scanning EnginesAutomated Code Review
    عرض على GitHub↗24,973
  • gtfobins/gtfobins.github.ioالصورة الرمزية لـ GTFOBins

    GTFOBins/GTFOBins.github.io

    12,669عرض على GitHub↗

    GTFOBins is a curated knowledge base documenting security-related techniques for Unix-based system binaries. It serves as a reference for offensive security research, detailing how standard, pre-installed system utilities can be repurposed to facilitate privilege escalation, restricted environment escapes, and post-exploitation workflows. The project distinguishes itself by cataloging insecure execution paths and misconfigured permissions inherent in common system tools. By identifying legitimate binary functions that can be leveraged to bypass security controls, the repository provides a str

    YAMLBinary Security ReferencesPrivilege Escalation ToolsPost-Exploitation Tools
    عرض على GitHub↗12,669
  • robertdavidgraham/masscanالصورة الرمزية لـ robertdavidgraham

    robertdavidgraham/masscan

    25,355عرض على GitHub↗

    Masscan is a command-line network scanner designed for large-scale discovery and infrastructure reconnaissance. It identifies open ports across specific network segments or the entire internet by probing vast address ranges with high efficiency. The tool functions as an asynchronous packet engine, bypassing standard operating system kernel networking stacks to transmit raw packets directly from application memory. The project distinguishes itself through a specialized architecture that manages millions of concurrent connections by separating packet transmission and reception into independent

    CNetwork Discovery ToolsPacket EnginesPort Scanners
    عرض على GitHub↗25,355
  • screetsec/thefatratالصورة الرمزية لـ screetsec

    screetsec/TheFatRat

    11,038عرض على GitHub↗

    TheFatRat is a security exploitation framework designed to automate the creation, obfuscation, and deployment of payloads for penetration testing. It functions as a comprehensive toolkit that streamlines the exploitation lifecycle, enabling users to generate malicious executables, manage network listeners, and execute post-exploitation tasks through a unified command-line interface. The framework distinguishes itself by integrating various third-party exploitation utilities into a single, orchestrated workflow. It provides specialized capabilities for embedding code into legitimate binaries a

    CEvasive Payload GeneratorsPenetration Testing SuitesSecurity Payload Generators
    عرض على GitHub↗11,038
  • mitmproxy/mitmproxyالصورة الرمزية لـ mitmproxy

    mitmproxy/mitmproxy

    43,943عرض على GitHub↗

    Mitmproxy is an interactive, programmable network proxy engine designed for traffic analysis and protocol manipulation. It functions as a gateway that intercepts, inspects, and modifies network traffic in real-time, supporting HTTP, HTTPS, WebSocket, DNS, and generic TCP or UDP streams. By acting as a trusted certificate authority, the proxy can dynamically generate and sign certificates to decrypt and analyze secure TLS-encrypted connections. The project distinguishes itself through a highly extensible, event-driven architecture that allows users to automate traffic transformation using cust

    PythonCertificate AuthoritiesCertificate Authority ManagementHTTP Proxies
    عرض على GitHub↗43,943
  • alessandroz/lazagneالصورة الرمزية لـ AlessandroZ

    AlessandroZ/LaZagne

    10,867عرض على GitHub↗

    LaZagne is a cross-platform credential recovery tool designed to extract passwords and secrets from operating systems, browsers, and applications. It functions as a security utility for retrieving stored credentials from compromised systems during penetration testing. The tool provides capabilities for decrypting domain credentials and extracting sensitive data from system storage, including memory dumps, credential managers, keychains, and password hashes. It recovers stored passwords from common software by accessing plaintext files, APIs, and local databases. The project supports digital

    PythonCredential RecoveryCredential Extraction UtilitiesCross-Platform Credential Extractors
    عرض على GitHub↗10,867
  • x64dbg/x64dbgالصورة الرمزية لـ x64dbg

    x64dbg/x64dbg

    48,652عرض على GitHub↗

    This project is a graphical Windows debugger designed for the analysis and manipulation of compiled binary applications. It functions as a comprehensive binary analysis suite, providing a real-time environment for inspecting CPU registers, monitoring memory states, and tracing instruction execution to investigate system-level software behavior. The tool distinguishes itself through an event-driven debugging loop that allows for precise process control and state modification during runtime. It supports advanced analysis techniques, including hardware-breakpoint injection for monitoring memory

    C++Binary Analysis ToolsDebuggersSystem Debugging
    عرض على GitHub↗48,652
  • greydgl/pentestgptالصورة الرمزية لـ GreyDGL

    GreyDGL/PentestGPT

    11,697عرض على GitHub↗

    PentestGPT is an autonomous security testing framework that leverages large language models to plan, execute, and coordinate end-to-end penetration testing engagements. By functioning as an autonomous agent, the system automates the entire testing lifecycle, from initial reconnaissance and vulnerability analysis to the generation of custom exploits and the execution of post-exploitation tasks. The platform distinguishes itself through a multi-agent orchestration system that coordinates specialized AI agents to collaborate on complex, multi-stage attack chains. It integrates multimodal context

    PythonPenetration Testing PlatformsAutonomous Penetration TestingAutonomous Task Execution
    عرض على GitHub↗11,697
  • nationalsecurityagency/ghidraالصورة الرمزية لـ NationalSecurityAgency

    NationalSecurityAgency/ghidra

    69,740عرض على GitHub↗

    Ghidra is a software reverse engineering suite designed to analyze compiled binaries and reconstruct program logic without access to original source code. It provides an interactive environment for disassembly and decompilation, utilizing a platform-independent intermediate representation to maintain consistency across diverse hardware architectures. The framework supports automated binary analysis through programmatic routines, enabling the investigation of complex code patterns and security indicators. The platform distinguishes itself through a modular architecture that allows for extensiv

    JavaBinary Analysis FrameworksBinary DisassemblyBytecode
    عرض على GitHub↗69,740
  • sundowndev/hacker-roadmapالصورة الرمزية لـ sundowndev

    sundowndev/hacker-roadmap

    15,081عرض على GitHub↗

    Hacker Roadmap is a community-driven repository that functions as a structured learning path and resource directory for cybersecurity and ethical hacking. It organizes complex security concepts into sequential modules, guiding users from fundamental knowledge to advanced technical exploitation skills through a curated collection of educational materials and professional development resources. The project distinguishes itself by acting as a centralized index that maps specialized third-party security software and isolated training environments to specific operational use cases. By aggregating

    Awesome ListCurated Learning PathsLearning Roadmaps
    عرض على GitHub↗15,081
  • zbezj/heu_kms_activatorالصورة الرمزية لـ zbezj

    zbezj/HEU_KMS_Activator

    41,965عرض على GitHub↗

    HEUKMSActivator is a software license management tool designed to automate the registration and validation of product keys for operating systems and productivity software suites. It functions as a system configuration manager, modifying registry settings and service states to align software licensing status with specific deployment requirements. The utility distinguishes itself through low-level system manipulation, including the injection of signed drivers into memory to intercept license verification routines. It employs memory patching to bypass security checks without altering files on

    License Management SystemsHardware DriversBinary Patchers
    عرض على GitHub↗41,965
  • bishopfox/sliverالصورة الرمزية لـ BishopFox

    BishopFox/sliver

    10,707عرض على GitHub↗

    Sliver is a command and control framework designed for adversary emulation and security assessment operations. It provides a centralized platform for managing remote systems, enabling security professionals to coordinate multi-operator sessions and maintain persistent, secure communication channels across diverse network environments. The framework distinguishes itself through its focus on stealth and infrastructure flexibility. It utilizes dynamic payload obfuscation to generate unique binaries and supports in-memory execution to minimize disk artifacts. Communication is secured through mutu

    GoCommand and Control PlatformsAdversary Emulation FrameworksCommand and Control Frameworks
    عرض على GitHub↗10,707
  • skylot/jadxالصورة الرمزية لـ skylot

    skylot/jadx

    49,088عرض على GitHub↗

    Jadx is a comprehensive Java decompilation suite designed to transform compiled binary application files into readable source code. It functions as a static analysis workbench, providing a graphical interface for navigating, searching, and inspecting the internal logic of complex software packages. By utilizing a bytecode-to-Java pipeline, the project reconstructs high-level logical structures from low-level binary instructions, making it a primary tool for Android application reverse engineering. The project distinguishes itself through a sophisticated control flow reconstruction engine and

    JavaDecompilersStatic Analysis WorkbenchesControl Flow Analysis Engines
    عرض على GitHub↗49,088
  • gophish/gophishالصورة الرمزية لـ gophish

    gophish/gophish

    13,938عرض على GitHub↗

    Gophish is an open-source phishing toolkit and simulation framework designed to test organizational security awareness and evaluate vulnerability to social engineering attacks. It provides a core engine for sending deceptive emails to targets and tracking their interactions to identify gaps in security training. The platform functions as a comprehensive campaign manager for deploying lures and monitoring email delivery and click-through rates. It allows for the design and execution of simulated email threats to track how targets interact with malicious-looking content or provide credentials i

    GoPhishing Attack ToolsPhishing Campaign OrchestratorsAdmin API Control Planes
    عرض على GitHub↗13,938
  • starship/starshipالصورة الرمزية لـ starship

    starship/starship

    58,310عرض على GitHub↗

    Starship is a cross-shell prompt engine that provides a unified, context-aware command line interface. It functions as a terminal customization tool, allowing users to modify the appearance and behavior of their shell prompts through a centralized, configuration-driven utility. The project operates as a compiled, statically linked binary that integrates directly into shell startup sequences to ensure consistent performance across different operating systems. By utilizing shell-agnostic hooks, it injects dynamically generated strings into the prompt regardless of the underlying command interpr

    RustCross-ShellCross-Platform Shell ExtensionsTerminal Customization Tools
    عرض على GitHub↗58,310
  • trustedsec/social-engineer-toolkitالصورة الرمزية لـ trustedsec

    trustedsec/social-engineer-toolkit

    14,984عرض على GitHub↗

    The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate human-centric security attacks. It serves as a phishing simulation tool and credential harvesting utility to evaluate personnel awareness and organizational resilience. The toolkit provides specialized tooling for phishing campaign testing and credential theft simulation. It enables the creation of deceptive emails and landing pages to identify vulnerabilities in how users handle sensitive account information. The system includes capabilities for security awareness training and br

    PythonCredential Harvesting SimulationsPenetration Testing SuitesPhishing Attack Tools
    عرض على GitHub↗14,984
  • nvbn/thefuckالصورة الرمزية لـ nvbn

    nvbn/thefuck

    97,358عرض على GitHub↗

    This tool is a rule-based engine designed to automate the correction of failed terminal commands. By integrating directly into the shell environment, it intercepts command execution errors, analyzes exit codes and output streams, and applies corrective logic to resolve typos or syntax mistakes. It functions as a persistent background utility that monitors command history to provide immediate remediation for input failures. The system distinguishes itself through a modular, plugin-oriented architecture that allows for extensive customization. Users can define their own correction rules via scr

    PythonCommand Error Correction EnginesCommand-Line Correction EnginesTerminal Error Recovery Tools
    عرض على GitHub↗97,358
  • wifiphisher/wifiphisherالصورة الرمزية لـ wifiphisher

    wifiphisher/wifiphisher

    14,631عرض على GitHub↗

    Wifiphisher is a modular security framework designed for wireless penetration testing and social engineering auditing. It functions as a platform for security professionals to assess the resilience of Wi-Fi networks by simulating unauthorized access, performing man-in-the-middle interceptions, and executing credential-harvesting scenarios. The tool distinguishes itself through its ability to combine rogue access point deployment with dynamic phishing interfaces. By forcing wireless clients to associate with deceptive infrastructure, the framework can capture network metadata and inject it int

    PythonRogue Access PointsWireless Attack ToolsWireless Security Auditing
    عرض على GitHub↗14,631
  • beyonddimension/steamtoolsالصورة الرمزية لـ BeyondDimension

    BeyondDimension/SteamTools

    25,938عرض على GitHub↗

    SteamTools is a desktop utility designed to enhance the experience of using digital gaming platforms. It functions as a centralized management tool that provides account switching, network optimization, and feature extensions for various gaming storefronts. The application distinguishes itself through a modular plugin architecture that allows users to customize or disable specific functional components at runtime. It utilizes a local reverse proxy to intercept and redirect network traffic, which facilitates faster access to gaming services and enables the real-time injection of custom scripts

    C#Gaming UtilitiesAccount ManagersAccount Switchers
    عرض على GitHub↗25,938
  • htr-tech/zphisherالصورة الرمزية لـ htr-tech

    htr-tech/zphisher

    15,416عرض على GitHub↗

    Zphisher is a security testing framework designed for conducting authorized social engineering assessments and penetration testing. It functions as a credential harvesting simulator that enables security professionals to evaluate organizational defenses and user awareness by deploying deceptive login interfaces. The platform automates the creation of realistic web pages through dynamic template rendering and provides tools to mask destination addresses. It integrates reverse proxy tunneling to expose local testing services to the public internet, allowing for remote access during security aud

    HTMLAttack SimulationsPenetration Testing PlatformsPhishing Attack Tools
    عرض على GitHub↗15,416
  • aquasecurity/trivyالصورة الرمزية لـ aquasecurity

    aquasecurity/trivy

    36,462عرض على GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    GoContainer Security ScannersVulnerability ScannersInfrastructure as Code Scanners
    عرض على GitHub↗36,462
  • jaykali/maskphishالصورة الرمزية لـ jaykali

    jaykali/maskphish

    3,020عرض على GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    ShellPenetration Testing FrameworksPhishing Attack ToolsSocial Engineering Phishing
    عرض على GitHub↗3,020
  • massgravel/microsoft-activation-scriptsالصورة الرمزية لـ massgravel

    massgravel/Microsoft-Activation-Scripts

    178,586عرض على GitHub↗

    This project is a collection of batch-based automation tools designed for managing software licensing, system configuration, and deployment. It provides a comprehensive toolkit for authorizing operating systems and productivity suites through various methods, including digital licensing, volume activation, and key management service emulation. The toolkit distinguishes itself by offering specialized routines for both modern and legacy software environments. It employs advanced techniques such as hardware identity generation, dynamic memory hooking, and registry-level state manipulation to mai

    BatchfileActivation AutomatorsPermanent Digital LicensingWindows Configuration Management
    عرض على GitHub↗178,586
  • mishakorzik/allhackingtoolsالصورة الرمزية لـ mishakorzik

    mishakorzik/AllHackingTools

    5,186عرض على GitHub↗

    AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of third-party hacking and security utilities from a single command interface. It functions as a centralized hub for network analysis, open source intelligence, penetration testing, and social engineering tools. The project provides specialized frameworks for gathering open source intelligence and searching for user profiles across social platforms. It includes toolkits for network reconnaissance, vulnerability scanning, and the execution of security exploits, as well as a social eng

    ShellPenetration Testing SuitesTool Orchestration MenusEnvironment Setup Tools
    عرض على GitHub↗5,186
  • ungoogled-software/ungoogled-chromiumالصورة الرمزية لـ ungoogled-software

    ungoogled-software/ungoogled-chromium

    26,944عرض على GitHub↗

    Ungoogled Chromium is a desktop web browser derived from the open-source Chromium codebase, modified to remove all background communication with external services and proprietary dependencies. It functions as a privacy-focused distribution that ensures user data remains local by eliminating telemetry hooks and data collection integrations. The project distinguishes itself through extensive source-code pruning and domain-substitution patching, which replace hardcoded service URLs with non-functional placeholders to prevent unauthorized data transmission. It further hardens the browser runtime

    PythonPrivacy-Focused Web BrowsersDe-Googled Browser DistributionsPrivacy-Focused Browsing
    عرض على GitHub↗26,944
  • trufflesecurity/trufflehogالصورة الرمزية لـ trufflesecurity

    trufflesecurity/trufflehog

    24,630عرض على GitHub↗

    Trufflehog is a security tool designed to continuously monitor code repositories and cloud environments to detect, verify, and remediate exposed sensitive credentials and API keys. It functions as a comprehensive secret scanning engine that integrates directly into deployment pipelines and version control systems to intercept sensitive data before it is committed or pushed. By utilizing read-only operations and volatile memory processing, the system ensures that discovered credentials are never stored persistently, maintaining strict data privacy throughout the scanning lifecycle. The platfor

    GoAutomated Secret RotationCredential VerificationSecret Scanning
    عرض على GitHub↗24,630
  • termux/termux-appالصورة الرمزية لـ termux

    termux/termux-app

    56,464عرض على GitHub↗

    Termux is a mobile terminal emulator and Linux environment runtime that provides a full command-line interface directly on Android devices. It functions as a comprehensive platform for executing native binaries and scripts, featuring an integrated package management system that allows users to download, install, and manage open-source software repositories to extend device functionality. The project distinguishes itself by acting as an embedded execution library, enabling third-party applications to integrate terminal and package management capabilities into their own interfaces without requi

    JavaEmbedded Terminal EnvironmentsTerminal EmulatorsPackage Management Systems
    عرض على GitHub↗56,464
قارن بين أفضل 10 في لمحة
المستودعالنجوماللغةالترخيصآخر تحديث
z4nzu/hackingtool77.5KPythonMIT15 مارس 2026
swisskyrepo/payloadsallthethings78.4KPythonMIT6 يونيو 2026
fireeye/commando-vm7.7KPowerShellApache-2.016 أكتوبر 2025
samratashok/nishang10KPowerShellNOASSERTION25 أبريل 2024
rapid7/metasploit-framework38.4KRubyNOASSERTION16 يونيو 2026
kgretzky/evilginx214.6KGobsd-3-clause6 أكتوبر 2025
sqlmapproject/sqlmap37.7KPythonNOASSERTION15 يونيو 2026
powershellmafia/powersploit12.9KPowerShellother17 أغسطس 2020
apsdehal/awesome-ctf11.6KJavaScriptCC0-1.022 يوليو 2024
valdikss/goodbyedpi27.9KCapache-2.019 يناير 2026

Related searches

  • إطار عمل مفتوح المصدر لاختبار الاختراق
  • إطار عمل للتحكم والقيادة (C2) لفريق Red Team
  • إطار عمل أمني لعمليات اختبار الاختراق
  • مجموعة أدوات لمحاكاة الخصوم
  • مجموعة أدوات لمرحلة ما بعد الاستغلال
  • أداة لإنشاء الحمولات (Payloads) لفريق Red Team
  • إطار عمل لاختبار الاختراق لتدقيق الأمان
  • مجموعة أدوات لاختبار اختراق Active Directory