awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to taviso/ctftool

Projects sharing features with Ctftool

30 open-source projects similar to taviso/ctftool, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • ionuttbara/windows-defender-removerionuttbara avatar

    ionuttbara/windows-defender-remover

    7,135View on GitHub↗

    This project is a Windows security removal tool designed to permanently disable and delete antivirus services and security monitoring components from the operating system. It functions as a system performance optimizer and policy manager to remove security mitigations and clear policy files that restrict application execution. The tool includes a Windows ISO customizer that embeds configuration files and unattended installation scripts into bootable images. This allows security features to be bypassed and services to be disabled before the initial system boot. The software covers broad capab

    Batchfiledefenderdefender-disablerdefender-remover
    View on GitHub↗7,135
  • a2u/cve-2018-7600A

    a2u/CVE-2018-7600

    0View on GitHub↗
    View on GitHub↗0
  • bishopfox/gadgetprobeBishopFox avatar

    BishopFox/GadgetProbe

    616View on GitHub↗

    Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.

    Java
    View on GitHub↗616
  • adaptivethreat/bloodhoundadaptivethreat avatar

    adaptivethreat/Bloodhound

    10,552View on GitHub↗

    Bloodhound is an Active Directory attack path mapper and security auditor designed to visualize trust relationships and permission chains. It serves as an attack surface management tool that identifies paths to domain administrator and other high-privileged accounts. The project uses a graph database analyzer to map complex identity and access relationships. It quantifies the risk of privilege escalation by identifying misconfigured permissions and trust links within Windows domains. The system provides capabilities for Active Directory security analysis, identity and access auditing, and ne

    PowerShell
    View on GitHub↗10,552

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • aemkei/jsfuckaemkei avatar

    aemkei/jsfuck

    8,596View on GitHub↗

    jsfuck is an esoteric programming language and JavaScript source obfuscator. It functions as a code encoder that transforms standard JavaScript source code into a functional equivalent composed of a minimal character set. The project restricts its source code to six specific characters to hide logic and bypass security filters that block standard alphanumeric characters. It achieves this by using type coercion to derive symbols and accessing internal language objects through prototype manipulation. The system enables arbitrary JavaScript execution by converting strings into executable functi

    JavaScript
    View on GitHub↗8,596
  • al1ex/windowselevationA

    Al1ex/WindowsElevation

    0View on GitHub↗
    View on GitHub↗0
  • alessandroz/lazagneAlessandroZ avatar

    AlessandroZ/LaZagne

    10,867View on GitHub↗

    LaZagne is a cross-platform credential recovery tool designed to extract passwords and secrets from operating systems, browsers, and applications. It functions as a security utility for retrieving stored credentials from compromised systems during penetration testing. The tool provides capabilities for decrypting domain credentials and extracting sensitive data from system storage, including memory dumps, credential managers, keychains, and password hashes. It recovers stored passwords from common software by accessing plaintext files, APIs, and local databases. The project supports digital

    Python
    View on GitHub↗10,867
  • allyomalley/dnsobserverA

    allyomalley/dnsobserver

    0View on GitHub↗
    View on GitHub↗0
  • alsidofficial/wsuspenduA

    AlsidOfficial/WSUSpendu

    0View on GitHub↗
    View on GitHub↗0
  • arturss7/tuktukA

    ArturSS7/TukTuk

    0View on GitHub↗
    View on GitHub↗0
  • asciimoo/wuzzasciimoo avatar

    asciimoo/wuzz

    10,711View on GitHub↗

    Wuzz is an interactive command line HTTP client and request inspector designed for capturing, reviewing, and analyzing outgoing network calls and their payloads. It functions as a terminal-based tool for debugging API issues and testing web endpoints. The tool provides specialized filtering for response bodies, using regular expressions and format-specific query syntaxes tailored for JSON and HTML data. It allows for the persistence of captured requests and responses to disk to facilitate the reproduction of network issues and offline analysis. User settings and default request behaviors are

    Goclicurlgo
    View on GitHub↗10,711
  • assetnote/wordlistsassetnote avatar

    assetnote/wordlists

    1,611View on GitHub↗
    CSSbruteforcebruteforce-wordlistcontent-discovery
    View on GitHub↗1,611
  • aws-samples/automated-security-helperaws-samples avatar

    aws-samples/automated-security-helper

    657View on GitHub↗

    ASH is an extensible, open source SAST, SCA, and IaC security scanner orchestration engine.

    Python
    View on GitHub↗657
  • beurtschipper/depixbeurtschipper avatar

    beurtschipper/Depix

    4,533View on GitHub↗

    Depix is a pixelation recovery tool and digital forensics utility designed to reconstruct plaintext from pixelated images. It functions as a brute-force text reconstructor that identifies original text sequences by matching pixel blocks against a library of rendered characters. The tool operates as a proof of concept for image de-pixelation, utilizing pattern analysis to reveal hidden information. It is used for digital forensic analysis and redaction security testing to evaluate the effectiveness of pixelation as a method of obscuring sensitive data. The reconstruction process involves colo

    Python
    View on GitHub↗4,533
  • adamdriscoll/snekA

    adamdriscoll/snek

    0View on GitHub↗
    View on GitHub↗0
  • blacknbunny/libssh-authentication-bypassB

    blacknbunny/libSSH-Authentication-Bypass

    0View on GitHub↗
    View on GitHub↗0
  • bountystrike/emissaryB

    BountyStrike/Emissary

    0View on GitHub↗
    View on GitHub↗0
  • byt3bl33d3r/deathstarbyt3bl33d3r avatar

    byt3bl33d3r/DeathStar

    1,618View on GitHub↗

    Uses Empire's (https://github.com/BC-SECURITY/Empire) RESTful API to automate gaining Domain and/or Enterprise Admin rights in Active Directory environments using some of the most common offensive TTPs.

    Python
    View on GitHub↗1,618
  • ccob/minhook.netC

    CCob/MinHook.NET

    0View on GitHub↗
    View on GitHub↗0
  • cfreal/exploitsC

    cfreal/exploits

    0View on GitHub↗
    View on GitHub↗0
  • coalfire-research/java-deserialization-exploitsC

    Coalfire-Research/java-deserialization-exploits

    0View on GitHub↗
    View on GitHub↗0
  • cybellum/doubleagentCybellum avatar

    Cybellum/DoubleAgent

    1,259View on GitHub↗

    Zero-Day Code Injection and Persistence Technique

    C
    View on GitHub↗1,259
  • d4vinci/cr3dov3rD4Vinci avatar

    D4Vinci/Cr3dOv3r

    2,123View on GitHub↗

    Know the dangers of credential reuse attacks.

    Pythoncredential-reuse-attackscredentialshacked-emails
    View on GitHub↗2,123
  • d4vinci/one-lin3rD4Vinci avatar

    D4Vinci/One-Lin3r

    1,776View on GitHub↗

    Gives you one-liners that aids in penetration testing operations, privilege escalation and more

    Pythondatabasehackinghacking-tool
    View on GitHub↗1,776
  • dafthack/mailsniperdafthack avatar

    dafthack/MailSniper

    3,246View on GitHub↗

    MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.

    PowerShell
    View on GitHub↗3,246
  • damianrusinek/zip-bombD

    damianrusinek/zip-bomb

    0View on GitHub↗
    View on GitHub↗0
  • danielmiessler/seclistsdanielmiessler avatar

    danielmiessler/SecLists

    71,596View on GitHub↗

    SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities. The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution log

    PHP
    View on GitHub↗71,596
  • deepzec/bad-pdfdeepzec avatar

    deepzec/Bad-Pdf

    1,150View on GitHub↗

    Steal Net-NTLM Hash using Bad-PDF

    Pythonbadpdfcve-2018-4993ntlm-hash-extraction
    View on GitHub↗1,150
  • diablohorn/yara4pentestersDiabloHorn avatar

    DiabloHorn/yara4pentesters

    127View on GitHub↗

    rules to identify files containing juicy information like usernames, passwords etc

    View on GitHub↗127
  • 1ndianl33t/urlprobe1

    1ndianl33t/urlprobe

    0View on GitHub↗
    View on GitHub↗0