awesome-repositories.com
المدونة
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعحولكيفية ترتيب النتائجالصحافةخادم MCP
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

اختبار الاختراق

تم تحديث الترتيب في 23 يونيو 2026

For an open source toolkit for penetration testing, the strongest matches are shadow1ng/fscan (Fscan is a comprehensive penetration testing and security auditing), rapid7/metasploit-framework (This is a comprehensive penetration testing platform that provides) and usestrix/strix (Strix is a comprehensive penetration testing and security auditing). beefproject/beef and greydgl/pentestgpt round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

استكشف أطر عمل مفتوحة المصدر، وماسحات الثغرات، وأدوات الاستغلال المستخدمة لتقييم أمن الشبكات والتطبيقات.

اختبار الاختراق

اعثر على أفضل المستودعات باستخدام الذكاء الاصطناعي.سنبحث عن أفضل المستودعات المطابقة باستخدام الذكاء الاصطناعي.
  • shadow1ng/fscanالصورة الرمزية لـ shadow1ng

    shadow1ng/fscan

    13,421عرض على GitHub↗

    Fscan is an automated penetration testing tool designed for internal network reconnaissance and vulnerability assessment. It functions as a comprehensive security framework that maps network infrastructure, identifies active hosts and services, and detects security weaknesses across internal environments. The tool distinguishes itself through a modular plugin architecture that allows for extensible security checks and a stateful asset tracking system that maintains an in-memory registry of discovered infrastructure. It incorporates a dedicated credential brute-force engine for testing passwor

    Fscan is a comprehensive penetration testing and security auditing framework that provides network reconnaissance, vulnerability scanning, credential testing, and post-exploitation capabilities through a modular command-line and web-based interface.

    GoNetwork Reconnaissance ToolsVulnerability ScannersVulnerability Assessment Frameworks
    عرض على GitHub↗13,421
  • rapid7/metasploit-frameworkالصورة الرمزية لـ rapid7

    rapid7/metasploit-framework

    38,415عرض على GitHub↗

    The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures. The platform distinguishes itself through a modular architecture that supports reflective payload injection, allowing for the execution of code directly in memory without writing to disk. It utilizes an asynchronous event loop to

    This is a comprehensive penetration testing platform that provides the full suite of required features, including vulnerability scanning, exploit development, network reconnaissance, and reporting, all accessible through a command-line interface.

    RubyExploit FrameworksExploitation FrameworksExploit Development
    عرض على GitHub↗38,415
  • usestrix/strixالصورة الرمزية لـ usestrix

    usestrix/strix

    20,138عرض على GitHub↗

    Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno

    Strix is a comprehensive penetration testing and security auditing framework that integrates vulnerability scanning, network reconnaissance, and automated exploit research through an AI-orchestrated, containerized environment.

    PythonInfrastructure ReconnaissanceSecurity Reporting ToolsVulnerability Scanners
    عرض على GitHub↗20,138
  • beefproject/beefالصورة الرمزية لـ beefproject

    beefproject/beef

    10,728عرض على GitHub↗

    BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It functions as a platform for security professionals to evaluate client-side defenses by injecting persistent scripts into web browsers, establishing a bidirectional communication channel for remote command execution and data exfiltration. The framework distinguishes itself through its ability to use compromised browser sessions as proxies to conduct internal network reconnaissance, effectively bypassing perimeter security controls. It utilizes an event-driven control interface and

    BeEF is a specialized penetration testing framework focused on browser-based exploitation and client-side security auditing, providing essential reconnaissance and command execution capabilities for web application assessments.

    JavaScriptExploitation FrameworksNetwork Reconnaissance ToolsWeb Application Penetration Testing
    عرض على GitHub↗10,728
  • greydgl/pentestgptالصورة الرمزية لـ GreyDGL

    GreyDGL/PentestGPT

    11,697عرض على GitHub↗

    PentestGPT is an autonomous security testing framework that leverages large language models to plan, execute, and coordinate end-to-end penetration testing engagements. By functioning as an autonomous agent, the system automates the entire testing lifecycle, from initial reconnaissance and vulnerability analysis to the generation of custom exploits and the execution of post-exploitation tasks. The platform distinguishes itself through a multi-agent orchestration system that coordinates specialized AI agents to collaborate on complex, multi-stage attack chains. It integrates multimodal context

    PentestGPT is an autonomous penetration testing framework that uses LLMs to orchestrate reconnaissance, vulnerability analysis, and exploitation tasks, fitting the category of an automated security auditing tool.

    PythonExploit FrameworksExploitation FrameworksInfrastructure Reconnaissance
    عرض على GitHub↗11,697
  • projectdiscovery/nucleiالصورة الرمزية لـ projectdiscovery

    projectdiscovery/nuclei

    29,189عرض على GitHub↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Nuclei is a powerful, template-driven security scanning framework that provides robust vulnerability detection, network reconnaissance, and web application testing capabilities through a command-line interface.

    GoVulnerability ScannersAutomated Security ScannersVulnerability Assessment Frameworks
    عرض على GitHub↗29,189
  • ffuf/ffufالصورة الرمزية لـ ffuf

    ffuf/ffuf

    15,618عرض على GitHub↗

    This tool is a command-line utility designed for automated web resource discovery, fuzzing, and application structure mapping. It functions as a security-focused scanner that identifies hidden files, directories, parameters, and virtual hosts by injecting payloads into HTTP requests. By systematically testing how servers handle various inputs, it assists in mapping the architecture of web applications and uncovering potential security vulnerabilities. The tool distinguishes itself through a highly concurrent engine that manages asynchronous request execution and recursive job orchestration. I

    This tool is a specialized fuzzer and web resource discovery utility that serves as a core component for web application security auditing and reconnaissance.

    GoSecurity Reporting ToolsWeb Application Penetration TestingAutomated Security Scanners
    عرض على GitHub↗15,618
  • 1n3/sn1perالصورة الرمزية لـ 1N3

    1N3/Sn1per

    10,049عرض على GitHub↗

    Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan

    Sn1per is a comprehensive penetration testing and vulnerability management platform that integrates reconnaissance, scanning, and exploit validation into an automated pipeline, fulfilling all the requirements for a security auditing framework.

    ShellExploit FrameworksSecurity Report GenerationSecurity Reporting Tools
    عرض على GitHub↗10,049
  • bettercap/bettercapالصورة الرمزية لـ bettercap

    bettercap/bettercap

    18,855عرض على GitHub↗

    Bettercap is a modular framework designed for network reconnaissance, security testing, and the execution of man-in-the-middle attacks. It functions as a comprehensive utility for surveying wired and wireless network segments, identifying connected devices, and analyzing communication protocols through real-time traffic interception and manipulation. The platform distinguishes itself through an event-driven architecture that coordinates network state changes and packet-level data through a centralized message pipeline. It provides a programmable scripting engine and an API for orchestrating s

    Bettercap is a powerful network reconnaissance and security testing framework that excels at traffic interception and protocol analysis, though it focuses more on network-level attacks than full-stack web application vulnerability scanning.

    GoNetwork Reconnaissance ToolsSecurity Reconnaissance Tools
    عرض على GitHub↗18,855
  • jasonxtn/argusالصورة الرمزية لـ jasonxtn

    jasonxtn/Argus

    3,254عرض على GitHub↗

    Argus is a modular network reconnaissance framework designed for gathering network intelligence, mapping infrastructure, and assessing security postures through automated discovery tasks. It operates as a containerized security toolset that allows for the consistent execution of specialized information-gathering modules across different operating systems. The system functions as an infrastructure audit tool and a web application security scanner, performing tasks such as DNS lookups, port scanning, and the inspection of HTTP headers to detect vulnerabilities. It also serves as a threat intell

    Argus is a modular reconnaissance and infrastructure auditing framework that provides automated scanning and security assessment capabilities, fitting the category well despite lacking built-in exploit development features.

    PythonInfrastructure ReconnaissanceWeb Vulnerability Scanners
    عرض على GitHub↗3,254
  • google/tsunami-security-scannerالصورة الرمزية لـ google

    google/tsunami-security-scanner

    8,584عرض على GitHub↗

    Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity flaws across network assets. It functions as an asynchronous security probe engine that utilizes automated probes and specialized detection logic to find critical weaknesses and prioritize remediation efforts. The project is distinguished by a plugin-based scanning engine, which uses a modular architecture of interchangeable detection plugins to identify vulnerabilities. This extensibility allows for the development and integration of custom security plugins to expand the variet

    This is a specialized network vulnerability scanner that provides automated reconnaissance and detection capabilities, though it focuses more on scanning and auditing than on the exploit development or manual web application testing features requested.

    JavaNetwork Reconnaissance ToolsVulnerability ReportingVulnerability Scanners
    عرض على GitHub↗8,584
  • mishakorzik/allhackingtoolsالصورة الرمزية لـ mishakorzik

    mishakorzik/AllHackingTools

    5,186عرض على GitHub↗

    AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of third-party hacking and security utilities from a single command interface. It functions as a centralized hub for network analysis, open source intelligence, penetration testing, and social engineering tools. The project provides specialized frameworks for gathering open source intelligence and searching for user profiles across social platforms. It includes toolkits for network reconnaissance, vulnerability scanning, and the execution of security exploits, as well as a social eng

    This repository acts as a centralized manager and installer for a wide collection of penetration testing and security auditing utilities, providing a command-line interface to access tools for reconnaissance, scanning, and exploitation.

    ShellNetwork Reconnaissance ToolsWeb Attack ToolsReconnaissance
    عرض على GitHub↗5,186
  • sullo/niktoالصورة الرمزية لـ sullo

    sullo/nikto

    10,104عرض على GitHub↗

    Nikto is an open-source HTTP security auditing tool and web server vulnerability scanner. It functions as a reconnaissance engine designed to identify insecure server options, outdated software, and common vulnerabilities by analyzing HTTP responses. The project differentiates itself through capabilities for intrusion detection evasion and web server fingerprinting. It uses request-level encoding and timing spacers to bypass security filters and employs signature-based identification to determine specific server software versions and misconfigurations. The scanner covers broad capability are

    Nikto is a specialized web server vulnerability scanner that provides robust reconnaissance and auditing capabilities, though it focuses specifically on web infrastructure rather than being a comprehensive penetration testing framework that includes exploit development.

    PerlVulnerability Scanners
    عرض على GitHub↗10,104
  • yogeshojha/rengineالصورة الرمزية لـ yogeshojha

    yogeshojha/rengine

    8,472عرض على GitHub↗

    Rengine is an automated reconnaissance framework and vulnerability management platform designed for attack surface monitoring. It functions as a centralized hub for discovering subdomains and open ports, gathering open-source intelligence, and tracking security flaws across target networks. The system integrates large language models to analyze reconnaissance data and generate vulnerability descriptions and insights. It distinguishes itself through a plugin-based tool integration that wraps external security scanning binaries and a target mapping system that tracks changes to assets over time

    This is an automated reconnaissance and vulnerability management platform that excels at network discovery and security tracking, though it functions more as an orchestration hub for external scanning tools rather than a standalone exploit development framework.

    HTMLInfrastructure ReconnaissanceSecurity Report Generation
    عرض على GitHub↗8,472
  • andresriancho/w3afالصورة الرمزية لـ andresriancho

    andresriancho/w3af

    4,850عرض على GitHub↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    This is a comprehensive web penetration testing framework that provides vulnerability scanning, exploit development, and automated auditing capabilities through both a command-line and graphical interface.

    PythonPenetration Testing FrameworksSecurity Auditing ToolsTraffic Interception Tools
    عرض على GitHub↗4,850
  • aquasecurity/trivyالصورة الرمزية لـ aquasecurity

    aquasecurity/trivy

    36,462عرض على GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Trivy is a specialized security scanner focused on vulnerability detection and infrastructure auditing, which serves as a powerful component for the reconnaissance and scanning phases of a penetration testing workflow.

    GoVulnerability Scanners
    عرض على GitHub↗36,462
  • techarohq/anubisالصورة الرمزية لـ TecharoHQ

    TecharoHQ/anubis

    17,067عرض على GitHub↗

    Anubis is a command-line security reconnaissance framework designed for subdomain enumeration and attack surface mapping. It functions as a utility for security professionals to identify, catalog, and visualize the external digital footprint of an organization by discovering all subdomains associated with a target domain. The tool distinguishes itself through a modular resolver pipeline that integrates passive reconnaissance from third-party security APIs and public certificate transparency logs. It combines this data with active discovery methods, including recursive DNS brute-forcing and al

    Anubis is a specialized reconnaissance utility for subdomain enumeration and attack surface mapping, but it lacks the broader vulnerability scanning, exploit development, and reporting capabilities required for a full penetration testing framework.

    GoInfrastructure ReconnaissanceSecurity Reconnaissance Tools
    عرض على GitHub↗17,067
  • hahwul/dalfoxالصورة الرمزية لـ hahwul

    hahwul/dalfox

    4,846عرض على GitHub↗

    Dalfox is an automated web application security tool specifically designed for discovering and verifying cross-site scripting vulnerabilities. It functions as an XSS vulnerability scanner that analyzes HTTP parameters and DOM structures to identify reflected, stored, and blind injection points. The project distinguishes itself by providing a Model Context Protocol server and a REST API, allowing artificial intelligence agents and remote interfaces to trigger and manage security scans programmatically. It utilizes a payload mutation engine and fingerprinting strategies to execute WAF evasion t

    This is a specialized web application security scanner focused on XSS detection and verification, which serves as a powerful component for vulnerability testing within a broader security auditing workflow.

    GoVulnerability ScannersWeb Application Penetration Testing
    عرض على GitHub↗4,846
  • infinition/bjornالصورة الرمزية لـ infinition

    infinition/Bjorn

    5,656عرض على GitHub↗

    Bjorn is a penetration testing framework that automates network scanning, credential brute-forcing, vulnerability assessment, and data exfiltration, all coordinated through an event-driven task pipeline and controlled via a web-based dashboard. Its modular plugin architecture allows independent security modules to be loaded and chained together, with an asynchronous network scanner discovering live hosts and open ports without blocking the main execution flow. The framework distinguishes itself by integrating a credential brute-force engine that systematically attempts login combinations agai

    Bjorn is a penetration testing framework that provides automated network scanning, vulnerability assessment, and post-exploitation capabilities, though it relies on a web-based dashboard rather than the command-line interface requested.

    PythonVulnerability Assessment Frameworks
    عرض على GitHub↗5,656
  • sqlmapproject/sqlmapالصورة الرمزية لـ sqlmapproject

    sqlmapproject/sqlmap

    37,676عرض على GitHub↗

    This project is an automated security testing suite designed to detect and exploit database vulnerabilities. It functions as a command-line utility that streamlines the identification, verification, and exploitation of web application flaws by automating the injection of malicious payloads into input parameters. The tool provides a comprehensive framework for database enumeration, allowing users to extract schema information, user data, and system configurations from identified injection points. What distinguishes this tool is its sophisticated engine for dynamic payload adaptation and heuris

    This is a specialized penetration testing tool focused on automating the detection and exploitation of database-related vulnerabilities, providing a robust command-line interface for web application security auditing.

    PythonVulnerability Assessment Tools
    عرض على GitHub↗37,676
  • bee-san/rustscanالصورة الرمزية لـ bee-san

    bee-san/RustScan

    19,969عرض على GitHub↗

    RustScan is a high-speed network reconnaissance tool designed for automated port discovery and service enumeration. It functions as an automated vulnerability scanner that identifies open ports and active services across network environments, providing a foundation for mapping attack surfaces and gathering intelligence on target systems. The tool distinguishes itself through its ability to dynamically adjust scanning parameters and concurrency in real-time based on system feedback, ensuring efficient performance while preventing network congestion. It features an extensible architecture that

    This is a specialized network reconnaissance and port scanning utility that serves as a building block for security workflows rather than a comprehensive penetration testing framework that includes exploit development or reporting features.

    RustNetwork Reconnaissance ToolsVulnerability Scanners
    عرض على GitHub↗19,969
  • six2dez/reconftwالصورة الرمزية لـ six2dez

    six2dez/reconftw

    7,226عرض على GitHub↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    This is a comprehensive reconnaissance and attack surface management framework that automates vulnerability scanning and intelligence gathering, serving as a specialized component within a broader penetration testing workflow.

    ShellInfrastructure ReconnaissanceSecurity Report GenerationReconnaissance
    عرض على GitHub↗7,226
  • jaykali/maskphishالصورة الرمزية لـ jaykali

    jaykali/maskphish

    3,020عرض على GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    This framework provides a command-line interface for network reconnaissance, vulnerability scanning, and penetration testing, though its primary focus on social engineering and payload generation makes it a specialized tool rather than a general-purpose auditing suite.

    ShellInfrastructure ReconnaissanceNetwork Reconnaissance ToolsVulnerability Scanners
    عرض على GitHub↗3,020
  • z4nzu/hackingtoolالصورة الرمزية لـ Z4nzu

    Z4nzu/hackingtool

    77,515عرض على GitHub↗

    This project is a comprehensive cybersecurity tool collection designed to support security research, penetration testing, and vulnerability assessment. It functions as a unified penetration testing suite, providing a centralized environment where professionals can access a wide range of offensive security utilities to identify system weaknesses and study attack vectors. The platform distinguishes itself through a modular architecture that aggregates disparate security scripts into a single, hierarchical command-line interface. It simplifies the management of these utilities by integrating ext

    This repository is a collection and installer for various third-party security scripts rather than a unified penetration testing framework that provides its own vulnerability scanning or exploit development engine.

    PythonExploit FrameworksWeb Attack ToolsVulnerability Assessment Frameworks
    عرض على GitHub↗77,515
  • anchore/grypeالصورة الرمزية لـ anchore

    anchore/grype

    12,423عرض على GitHub↗

    Grype is a command-line security scanner designed to identify known vulnerabilities within container images, filesystems, and software manifests. It functions as a software composition analysis tool that detects security flaws in application components and open-source libraries to support supply chain security. The tool distinguishes itself by reconstructing the final state of container images through layered filesystem inspection and normalizing diverse package formats into a unified dependency graph. It maintains a local cache of security advisories synchronized from multiple upstream sourc

    This tool is a specialized software composition analysis scanner for container images and dependencies, which serves as a building block for supply chain security rather than a comprehensive penetration testing framework for active network or application exploitation.

    GoSecurity Reporting ToolsSecurity Vulnerability ReportingAutomated Security Scanners
    عرض على GitHub↗12,423
قارن بين أفضل 10 في لمحة
المستودعالنجوماللغةالترخيصآخر تحديث
shadow1ng/fscan13.4KGomit31 يناير 2026
rapid7/metasploit-framework38.4KRubyNOASSERTION16 يونيو 2026
usestrix/strix20.1KPythonapache-2.019 فبراير 2026
beefproject/beef10.7KJavaScript—19 فبراير 2026
greydgl/pentestgpt11.7KPythonmit18 فبراير 2026
projectdiscovery/nuclei29.2KGoMIT15 يونيو 2026
ffuf/ffuf15.6KGomit24 أبريل 2025
1n3/sn1per10KShellother29 أبريل 2026
bettercap/bettercap18.9KGoother31 ديسمبر 2025
jasonxtn/argus3.3KPythonmit10 ديسمبر 2025

Related searches

  • إطار عمل أمني لعمليات اختبار الاختراق
  • إطار عمل مستقل لاختبار الاختراق
  • إطار عمل لاختبار الاختراق لتدقيق الأمان
  • إطار عمل مفتوح المصدر لاختبار الاختراق
  • أمن تطبيقات الويب والاستغلال
  • أدوات الهجوم والفريق الأحمر (Red Teaming)
  • أداة لاختبار ثغرات حقن SQL
  • a professional certification for breach and attack simulation