awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

56 Repos

Awesome GitHub RepositoriesVulnerability Exploitation Frameworks

Specialized frameworks for detecting and exploiting specific vulnerabilities in CMS, middleware, and applications.

Explore 56 awesome GitHub repositories matching part of an awesome list · Vulnerability Exploitation Frameworks. Refine with filters or upvote what's useful.

Awesome Vulnerability Exploitation Frameworks GitHub Repositories

Finde die besten Repos mit KI.Wir suchen mit KI nach den am besten passenden Repositories.
  • manisso/fsocietyAvatar von Manisso

    Manisso/fsociety

    12,136Auf GitHub ansehen↗

    fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits. It functions as a wrapper that integrates external security binaries into a unified, menu-driven interface, providing a centralized system for command-line parameter mapping and execution. The project distinguishes itself by organizing specialized utilities into domain-specific collections for structured navigation. It automates the transition between different phases of an audit by chaining reconnaissance and exploitation tools through sequential workflow automation. The fram

    Launches automated exploits against web applications and services to confirm unauthorized access.

    Pythonbrute-force-attacksdesktopexploitation
    Auf GitHub ansehen↗12,136
  • liamg/traitorAvatar von liamg

    liamg/traitor

    7,144Auf GitHub ansehen↗

    Traitor is a Linux privilege escalation framework and automated root exploit suite. It provides specialized utilities for scanning system misconfigurations and deploying automated exploit scripts on local Linux hosts to elevate user privileges to the root level. The tool identifies insecure system setups and binary vulnerabilities, such as GTFOBins, to map potential routes for gaining root access. It automates the process of discovering and exploiting these local vulnerabilities through targeted exploit execution and the deployment of sequential scripts. The system covers vulnerability asses

    Runs a predetermined sequence of vulnerability triggers to automatically establish a root shell.

    Gocve-2021-3560cve-2022-0847dirtypipe
    Auf GitHub ansehen↗7,144
  • guardicore/monkeyAvatar von guardicore

    guardicore/monkey

    7,014Auf GitHub ansehen↗

    Monkey is an adversary emulation platform and breach and attack simulation tool designed to test network defenses through automated lateral movement and exploit delivery. It functions as a network security testing system that evaluates security posture by attempting to propagate through vulnerabilities and extract sensitive system credentials. The platform distinguishes itself by simulating specific real-world attacker behaviors, such as ransomware encryption, cryptojacking, and the theft of browser-stored credentials and secure shell keys. It utilizes binary hash randomization to evade antiv

    Uses a library of plugins to propagate through known network vulnerabilities and test security perimeters.

    Python
    Auf GitHub ansehen↗7,014
  • k8gege/k8toolsAvatar von k8gege

    k8gege/K8tools

    6,167Auf GitHub ansehen↗

    K8tools is a multi-stage attack framework that combines memory-only payload execution, credential testing, port forwarding, privilege escalation, and physical USB-based keystroke injection for comprehensive system compromise. At its core, the Ladon PowerShell module loads a multi-function scanner directly into memory, enabling command execution without writing files to disk, while supporting memory-only payload delivery that downloads and runs obfuscated shellcode or PowerShell commands to evade antivirus detection. The framework distinguishes itself through its breadth of integrated capabili

    Launches pre-built exploits against web applications, operating systems, and services.

    PowerShell0daybrute-forcebypass
    Auf GitHub ansehen↗6,167
  • commixproject/commixAvatar von commixproject

    commixproject/commix

    5,757Auf GitHub ansehen↗

    Commix is an automated tool for detecting and exploiting OS command injection vulnerabilities in web applications. It probes user-supplied input vectors with heuristic test payloads, analyzes response differences to identify injection points, and then automates the execution of arbitrary operating system commands on the target server. The tool distinguishes itself through a multi-layer filter bypass engine that evaluates input constraints independently per filter type and composes tailored evasion strategies into a single payload. A modular payload tamper pipeline transforms raw injection str

    Automates the detection and exploitation of OS command injection vulnerabilities to execute arbitrary commands on target servers.

    Python
    Auf GitHub ansehen↗5,757
  • nullarray/autosploitAvatar von NullArray

    NullArray/AutoSploit

    5,240Auf GitHub ansehen↗

    AutoSploit ist ein automatisiertes Exploitation-Framework zur Entdeckung von Remote-Hosts und zur Ausführung von Exploit-Modulen in großem Maßstab, um Reverse-Shells zu etablieren. Es fungiert als Tool zur Netzwerkaufklärung und als Orchestrator für Remote-Code-Execution, der die Bereitstellung von Angriffsmodulen gegen mehrere Ziele verwaltet. Das System bietet einen Proxy-basierten Traffic-Masker, der Netzwerkanfragen über externe Server leitet und HTTP-Header sowie User-Agents rotiert, um den Ursprung der Aktivität zu verschleiern. Es ermöglicht die Orchestrierung benutzerdefinierter Exploits durch die Integration externer Angriffsmodule und das Management von Workspace-Verbindungsparametern. Das Framework deckt die Zielentdeckung via Suchmaschinen-Queries und API-Integrationen ab sowie das Management von Ziellisten mittels externer Dateien und Whitelists. Zudem enthält es Funktionen für die sitzungsbasierte Listener-Konfiguration, um eingehende Remote-Verbindungen zu erfassen.

    Automates the execution of multiple exploit modules against targets to achieve remote code execution at scale.

    Python
    Auf GitHub ansehen↗5,240
  • andresriancho/w3afAvatar von andresriancho

    andresriancho/w3af

    4,850Auf GitHub ansehen↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    Tests the viability of discovered security holes to confirm if they permit unauthorized access or data extraction.

    Pythonappseccross-site-scriptingscanner
    Auf GitHub ansehen↗4,850
  • zhzyker/exphubAvatar von zhzyker

    zhzyker/exphub

    4,282Auf GitHub ansehen↗

    Exphub ist eine Bibliothek für CVE-Exploit-Skripte und eine Suite für Unternehmenssoftware-Schwachstellen, die darauf ausgelegt ist, bekannte Sicherheitslücken in Serverumgebungen wie WebLogic, Struts2, Tomcat und JBoss zu verifizieren und auszunutzen. Es fungiert als Toolkit für Remote Code Execution und als Framework für die Bereitstellung von Web-Shells, um unbefugte Befehlsausführungen auszulösen und persistenten Zugriff auf entfernte Systeme zu etablieren. Das Projekt enthält spezialisierte Dienstprogramme für interne Netzwerkaufklärung, insbesondere durch Server-Side Request Forgery, um offene Ports und Dienste zu scannen. Zudem bietet es Mechanismen zur Umgehung von Zugriffskontrollen sowie für unbefugte Dateizugriffe und Uploads. Die Suite deckt breite Einsatzbereiche ab, darunter Schwachstellenanalyse, Penetrationstests und die Ausführung von Proof-of-Concept-Skripten zur Bestätigung von Sicherheitslücken.

    Provides a framework for detecting and exploiting security flaws in middleware and application frameworks.

    Pythoncve-2020-10199cve-2020-10204cve-2020-11444
    Auf GitHub ansehen↗4,282
  • jtesta/ssh-auditAvatar von jtesta

    jtesta/ssh-audit

    4,218Auf GitHub ansehen↗

    Dieses Projekt ist ein SSH-Sicherheitsaudit-Tool, das zur Analyse von Server- und Client-Konfigurationen entwickelt wurde. Es fungiert als kryptografischer Analysator, der Schlüsselaustausch-, MAC- und Verschlüsselungsalgorithmen bewertet, um schwache oder veraltete Primitive zu identifizieren und die Sicherheitskonformität sicherzustellen. Das Tool zeichnet sich dadurch aus, dass es einen Härtungsleitfaden mit plattformspezifischen Konfigurationsanweisungen und Algorithmus-Empfehlungen zur Behebung erkannter Schwachstellen bereitstellt. Es enthält zudem einen Denial-of-Service-Tester, der die Server-Resilienz gegen CPU-Erschöpfung und gleichzeitige Socket-Verbindungsangriffe misst. Breite Funktionen decken Sicherheitsaudits und Schwachstellentests ab, einschließlich der Validierung von Sicherheitsrichtlinien und der Identifizierung von Softwareversionen. Das Projekt führt zudem kryptografische Validierungen durch Diffie-Hellman-Modulus-Größentests durch und bewertet das Verhalten von Client-Software mittels listener-basierter Analyse.

    Identifies the specific SSH software version by matching supported algorithms and banner strings against a known database.

    Python
    Auf GitHub ansehen↗4,218
  • epinna/tplmapAvatar von epinna

    epinna/tplmap

    4,169Auf GitHub ansehen↗

    tplmap is a security tool designed for the detection and exploitation of server-side template injection vulnerabilities. It functions as an automated scanner to identify vulnerable template engine contexts and provides a framework for achieving remote code execution. The tool focuses on translating high-level requests into engine-specific syntax to execute operating system commands and bypass application sandboxes. It further enables remote file system access, allowing users to read, write, and transfer files between a local machine and a target server. Additional capabilities include the ab

    Detects and exploits server-side template injection.

    Python
    Auf GitHub ansehen↗4,169
  • retirejs/retire.jsAvatar von RetireJS

    RetireJS/retire.js

    4,141Auf GitHub ansehen↗

    Retire.js is a JavaScript vulnerability scanner and dependency security analyzer. It identifies outdated or insecure JavaScript libraries with known security flaws within web applications and local projects. The tool functions as a web security auditing utility that can be used during penetration testing to detect vulnerable scripts on live websites. It supports the generation of Software Bills of Materials using the CycloneDX format to document project dependencies. The system utilizes signature-based library detection and pattern-matching to map identified versions against a JSON-based sec

    Detects vulnerable JavaScript libraries.

    JavaScriptbuild-toolchrome-extensionfirefox-extension
    Auf GitHub ansehen↗4,141
  • knownsec/pocsuite3Avatar von knownsec

    knownsec/pocsuite3

    3,853Auf GitHub ansehen↗

    Pocsuite3 is a modular vulnerability testing framework designed for the development and execution of security assessment scripts. It provides a comprehensive toolkit for remote vulnerability verification and exploitation, enabling users to automate the identification of security flaws across network targets. The framework is built on an object-oriented scripting architecture that allows for the creation of custom security modules and plugins. It distinguishes itself through a highly extensible design that supports asynchronous task execution for large-scale infrastructure assessments, alongsi

    Provides a modular framework for developing and executing security assessment scripts to identify and exploit vulnerabilities across network targets.

    Pythonpentestingpythonsecurity
    Auf GitHub ansehen↗3,853
  • cloudsploit/scansAvatar von cloudsploit

    cloudsploit/scans

    3,748Auf GitHub ansehen↗

    This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr

    Security scanning checks for AWS environments.

    JavaScript
    Auf GitHub ansehen↗3,748
  • mbechler/marshalsecAvatar von mbechler

    mbechler/marshalsec

    3,691Auf GitHub ansehen↗

    Marshalsec is a toolkit designed for generating malicious serialized Java objects to achieve remote code execution during the unmarshalling process. It functions as a Java deserialization exploit tool and a framework for triggering Java Naming and Directory Interface lookups to remote servers. The project provides a JNDI redirector service that intercepts lookups and points targets toward a remote codebase. It includes utilities for crafting payloads that force Java applications to download and execute arbitrary classes from a remote URL. The toolset covers security analysis activities inclu

    Generates payloads to trigger remote code execution by forcing Java applications to perform external JNDI lookups.

    Java
    Auf GitHub ansehen↗3,691
  • lijiejie/githackAvatar von lijiejie

    lijiejie/GitHack

    3,550Auf GitHub ansehen↗

    GitHack is a .git folder disclosure exploit.

    Exploits .git folder disclosures.

    Python
    Auf GitHub ansehen↗3,550
  • jaykali/maskphishAvatar von jaykali

    jaykali/maskphish

    3,020Auf GitHub ansehen↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Provides a framework to apply predefined exploits against targets identified through network scanning.

    Shellhackhackinghacking-tool
    Auf GitHub ansehen↗3,020
  • tuhinshubhra/cmseekAvatar von Tuhinshubhra

    Tuhinshubhra/CMSeeK

    2,543Auf GitHub ansehen↗

    CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 180 other CMSs

    Suite for CMS detection and exploitation.

    Pythonbruteforcecmscms-bruteforce
    Auf GitHub ansehen↗2,543
  • joaomatosf/jexbossAvatar von joaomatosf

    joaomatosf/jexboss

    2,512Auf GitHub ansehen↗

    jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit deserialization flaws to achieve remote code execution on target servers. It functions as a suite of tools for delivering payloads and executing system commands on vulnerable remote applications. The project includes a reverse shell orchestrator to establish and maintain persistent remote command connections from exploited targets back to a listener. It also provides post-exploitation automation for managing remote access and updating software on compromised systems. The fra

    Provides a framework to deliver specialized Java deserialization payloads to achieve remote code execution.

    Pythondeserializationexploitexploiting-vulnerabilities
    Auf GitHub ansehen↗2,512
  • lijiejie/bbscanAvatar von lijiejie

    lijiejie/BBScan

    2,372Auf GitHub ansehen↗

    BBScan 是一个高并发的、轻量级的Web漏洞扫描工具。它帮助安全工程师从大量目标中,快速发现,定位可能存在弱点的目标,辅助半自动化测试。

    Batch web vulnerability scanner.

    Python
    Auf GitHub ansehen↗2,372
  • anouarbensaad/vulnxAvatar von anouarbensaad

    anouarbensaad/vulnx

    2,074Auf GitHub ansehen↗

    Automated CMS injection and vulnerability scanner.

    Pythonauto-exploiterbotcloudflare-detection
    Auf GitHub ansehen↗2,074
Vorherige123Nächste
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Vulnerability Exploitation Frameworks

Unter-Tags erkunden

  • Batch Exploit Execution2 Sub-TagsAutomated systems for running multiple exploit payloads against a set of compatible vulnerabilities. **Distinct from Vulnerability Exploitation Frameworks:** Distinct from Vulnerability Exploitation Frameworks: focuses on the batch processing and conditional execution of multiple exploits
  • Router Exploit ExecutionExecution of specific exploit modules against router vulnerabilities for unauthorized access. **Distinct from Vulnerability Exploitation Frameworks:** Focuses on the target device (routers) rather than general CMS or middleware frameworks.
  • Web Application Exploits1 Sub-TagSpecialized techniques and payloads for verifying vulnerabilities in web applications to confirm unauthorized access or data extraction. **Distinct from Vulnerability Exploitation Frameworks:** Focuses specifically on web-layer vulnerabilities rather than general CMS or middleware frameworks.