awesome-repositories.com
Blog
MCP
awesome-repositories.com

Entdecke die besten Open-Source-Repositories mit KI-gestützter Suche.

EntdeckenKuratierte SuchenOpen-Source-AlternativenSelf-hosted SoftwareBlogSitemap
ProjektMCP-ServerÜber unsRanking-MethodikPresse
RechtlichesDatenschutzAGB
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to assetnote/kiterunner

Open-source alternatives to Kiterunner

30 open-source projects similar to assetnote/kiterunner, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Kiterunner alternative.

  • epi052/feroxbusterAvatar von epi052

    epi052/feroxbuster

    7,522Auf GitHub ansehen↗

    Feroxbuster is an HTTP directory brute forcer and web resource enumerator designed to discover hidden files and directories on web servers. It functions as a recursive URL scanner that identifies unlinked endpoints and API resources by combining wordlist-based scanning with automated crawling. The tool operates as a proxy-aware fuzzer, allowing network requests to be routed through HTTP or SOCKS proxies for traffic interception or anonymity. It utilizes recursive directory crawling to automatically queue discovered paths and find nested content. The system includes capabilities for discovery

    Rustcontent-discoveryenumerationhacktoberfest
    Auf GitHub ansehen↗7,522
  • ffuf/ffufAvatar von ffuf

    ffuf/ffuf

    15,618Auf GitHub ansehen↗

    This tool is a command-line utility designed for automated web resource discovery, fuzzing, and application structure mapping. It functions as a security-focused scanner that identifies hidden files, directories, parameters, and virtual hosts by injecting payloads into HTTP requests. By systematically testing how servers handle various inputs, it assists in mapping the architecture of web applications and uncovering potential security vulnerabilities. The tool distinguishes itself through a highly concurrent engine that manages asynchronous request execution and recursive job orchestration. I

    Gofuzzerinfosecpentesting
    Auf GitHub ansehen↗15,618
  • sullo/niktoAvatar von sullo

    sullo/nikto

    10,104Auf GitHub ansehen↗

    Nikto is an open-source HTTP security auditing tool and web server vulnerability scanner. It functions as a reconnaissance engine designed to identify insecure server options, outdated software, and common vulnerabilities by analyzing HTTP responses. The project differentiates itself through capabilities for intrusion detection evasion and web server fingerprinting. It uses request-level encoding and timing spacers to bypass security filters and employs signature-based identification to determine specific server software versions and misconfigurations. The scanner covers broad capability are

    Perl
    Auf GitHub ansehen↗10,104

KI-Suche

Entdecke weitere awesome Repositories

Beschreibe in einfachen Worten, was du brauchst — die KI bewertet tausende kuratierte Open-Source-Projekte nach Relevanz.

Find more with AI search
  • oj/gobusterAvatar von OJ

    OJ/gobuster

    13,429Auf GitHub ansehen↗

    Gobuster is a command-line security utility designed for brute-force discovery of hidden infrastructure and content. It operates by systematically testing wordlists against target network services to identify files, directories, subdomains, and cloud storage buckets. The tool utilizes a concurrent worker pool to execute these requests in parallel, ensuring efficient scanning across various network environments. The project distinguishes itself through a modular plugin architecture that supports multiple discovery modes, including HTTP, DNS, and TFTP. This design allows for protocol-agnostic r

    Godnsgopentesting
    Auf GitHub ansehen↗13,429
  • google/syzkallerAvatar von google

    google/syzkaller

    6,232Auf GitHub ansehen↗

    Syzkaller is an unsupervised, coverage-guided kernel fuzzer that automatically generates and mutates system call sequences to find bugs in operating system kernels. It operates without human intervention, using a closed feedback loop of input generation, execution, crash detection, and corpus refinement to continuously explore kernel code paths. The fuzzer distinguishes itself by supporting multiple operating system kernels, including Linux, FreeBSD, and Windows, through per-platform syscall harnesses that abstract system call interfaces behind a common driver. It uses declarative description

    Go
    Auf GitHub ansehen↗6,232
  • alexanderyastrebov/age-vanity-keygenAvatar von AlexanderYastrebov

    AlexanderYastrebov/age-vanity-keygen

    8Auf GitHub ansehen↗

    This tool generates age X25519 identity with a recipient that has a specified prefix. The output is identical to age-keygen.

    Go
    Auf GitHub ansehen↗8
  • alebcay/awesome-shellAvatar von alebcay

    alebcay/awesome-shell

    37,110Auf GitHub ansehen↗

    This project is a community-driven directory that serves as a comprehensive index of command-line tools, frameworks, and resources. It functions as a curated knowledge base designed to help users discover software for enhancing terminal environments and streamlining daily development tasks. The collection is maintained through an open-source contribution model, where community members manually verify and organize resources into structured categories. This collaborative approach ensures the directory remains a reliable reference for finding specialized utilities, alternative shell implementati

    awesomeawesome-listbash
    Auf GitHub ansehen↗37,110
  • 1n3/sn1perAvatar von 1N3

    1N3/Sn1per

    10,049Auf GitHub ansehen↗

    Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan

    Shellattack-surfaceattack-surface-managementattacksurface
    Auf GitHub ansehen↗10,049
  • api-security/apikitAvatar von API-Security

    API-Security/APIKit

    2,270Auf GitHub ansehen↗

    APIKit:Discovery, Scan and Audit APIs Toolkit All In One.

    Java
    Auf GitHub ansehen↗2,270
  • andreiverse/vafAvatar von andreiverse

    andreiverse/vaf

    318Auf GitHub ansehen↗

    Vaf is a cross-platform very advanced and fast web fuzzer written in nim

    Nim
    Auf GitHub ansehen↗318
  • apiclarity/apiclarityAvatar von apiclarity

    apiclarity/apiclarity

    572Auf GitHub ansehen↗

    An API security tool to capture and analyze API traffic, test API endpoints, reconstruct Open API specification, and identify API security risks.

    Go
    Auf GitHub ansehen↗572
  • archerysec/archerysecAvatar von archerysec

    archerysec/archerysec

    2,461Auf GitHub ansehen↗

    ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

    JavaScript
    Auf GitHub ansehen↗2,461
  • assetnote/batchqlAvatar von assetnote

    assetnote/batchql

    412Auf GitHub ansehen↗

    GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

    Python
    Auf GitHub ansehen↗412
  • aws-samples/aws-serverless-security-workshopAvatar von aws-samples

    aws-samples/aws-serverless-security-workshop

    543Auf GitHub ansehen↗

    In this workshop, you will learn techniques to secure a serverless application built with AWS Lambda, Amazon API Gateway and RDS Aurora. We will cover AWS services and features you can leverage to improve the security of a serverless applications in 5 domains:

    JavaScript
    Auf GitHub ansehen↗543
  • akto-api-security/aktoAvatar von akto-api-security

    akto-api-security/akto

    1,486Auf GitHub ansehen↗

    Proactive, Open source API security → API discovery, API Security Posture, Testing in CI/CD, Test Library with 1000+ Tests, Add custom tests, Sensitive data exposure

    Java
    Auf GitHub ansehen↗1,486
  • berzerk0/probable-wordlistsAvatar von berzerk0

    berzerk0/Probable-Wordlists

    9,289Auf GitHub ansehen↗

    Probable-Wordlists is a collection of curated data resources providing password frequency lists, character masks, and common identity identifiers for security research. These resources serve as credential analysis tools to identify popular password trends and support the creation of secure credentials. The project provides password frequency wordlists and security research wordlists, including common usernames and top-level domains. It includes password recovery datasets featuring character masks and rule sets designed to analyze vulnerability patterns. The repository covers a broad range of

    dictionarydictionary-attackpassword
    Auf GitHub ansehen↗9,289
  • beefproject/beefAvatar von beefproject

    beefproject/beef

    10,728Auf GitHub ansehen↗

    BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It functions as a platform for security professionals to evaluate client-side defenses by injecting persistent scripts into web browsers, establishing a bidirectional communication channel for remote command execution and data exfiltration. The framework distinguishes itself through its ability to use compromised browser sessions as proxies to conduct internal network reconnaissance, effectively bypassing perimeter security controls. It utilizes an event-driven control interface and

    JavaScript
    Auf GitHub ansehen↗10,728
  • alufers/mitmproxy2swaggerAvatar von alufers

    alufers/mitmproxy2swagger

    9,530Auf GitHub ansehen↗

    mitmproxy2swagger is a tool that transforms captured mitmproxy network traffic into structured OpenAPI schemas for reverse-engineering REST APIs. It functions as an OpenAPI schema converter and network traffic documentation utility, extracting API endpoints and data structures from captured network packets to create formal technical references. The tool enables the reconstruction of undocumented APIs by converting intercepted HTTP request and response patterns into specifications. It supports merging multiple traffic capture files into a single schema to incrementally expand an API map and ut

    HTMLmitmproxyopenapireverse-engineering
    Auf GitHub ansehen↗9,530
  • biox/paAvatar von biox

    biox/pa

    562Auf GitHub ansehen↗

    pa a simple password manager https://passwordass.org

    Shell
    Auf GitHub ansehen↗562
  • bjeborn/basic-auth-potAvatar von bjeborn

    bjeborn/basic-auth-pot

    54Auf GitHub ansehen↗

    bap - http Basic Authentication honeyPot

    Python
    Auf GitHub ansehen↗54
  • blessedrebus/krawlAvatar von BlessedRebuS

    BlessedRebuS/Krawl

    545Auf GitHub ansehen↗

    Krawl is a customizable, lightweight, cloud-native web deception server and anti-crawler that creates fake web applications with low-hanging vulnerabilities using realistic, randomly generated decoy data and AI-generated HTML templates.

    Python
    Auf GitHub ansehen↗545
  • blst-security/cherrybombAvatar von blst-security

    blst-security/cherrybomb

    1,231Auf GitHub ansehen↗

    Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.

    Rust
    Auf GitHub ansehen↗1,231
  • bo0om/parampampamAvatar von Bo0oM

    Bo0oM/ParamPamPam

    277Auf GitHub ansehen↗

    This tool for brute discover GET and POST parameters.

    Python
    Auf GitHub ansehen↗277
  • bountyyfi/lonkeroAvatar von bountyyfi

    bountyyfi/lonkero

    929Auf GitHub ansehen↗

    Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.

    Rust
    Auf GitHub ansehen↗929
  • brendan-rius/c-jwt-crackerAvatar von brendan-rius

    brendan-rius/c-jwt-cracker

    2,548Auf GitHub ansehen↗

    JWT brute force cracker written in C

    Cbrute-forcecrackerjwt-authentication
    Auf GitHub ansehen↗2,548
  • c-sto/recursebusterAvatar von c-sto

    c-sto/recursebuster

    250Auf GitHub ansehen↗

    rapid content discovery tool for recursively querying webservers, handy in pentesting and web application assessments

    Go
    Auf GitHub ansehen↗250
  • centralmind/gatewayAvatar von centralmind

    centralmind/gateway

    530Auf GitHub ansehen↗

    Universal MCP-Server for your Databases optimized for LLMs and AI-Agents.

    Go
    Auf GitHub ansehen↗530
  • clong/detectionlabAvatar von clong

    clong/DetectionLab

    4,904Auf GitHub ansehen↗

    DetectionLab is a reproducible Windows Active Directory security lab designed for testing detection capabilities. It uses an automation framework based on Vagrant and Packer to provision virtualized networks across multiple hypervisors and cloud platforms. The project utilizes Ansible for the declarative installation and configuration of domain services and endpoint security tools. It incorporates a browser-based remote access interface via Apache Guacamole to manage laboratory hosts without requiring standalone remote desktop clients. The environment includes a telemetry pipeline that aggre

    HTMLansibledetectiondetectionlab
    Auf GitHub ansehen↗4,904
  • cn0xroot/rfsec-toolkitAvatar von cn0xroot

    cn0xroot/RFSec-ToolKit

    1,705Auf GitHub ansehen↗

    RFSec-ToolKit is a collection of Radio Frequency Communication Protocol Hacktools.无线通信协议相关的工具集,可借助SDR硬件+相关工具对无线通信进行研究。Collect with ♥ by HackSmith

    bladerfcommunicationfuzzing
    Auf GitHub ansehen↗1,705
  • bad-antics/nullsec-webfuzzAvatar von bad-antics

    bad-antics/nullsec-webfuzz

    6Auf GitHub ansehen↗

    Rust web fuzzer - async/await, Tokio, directory brute-force

    Makefile
    Auf GitHub ansehen↗6