awesome-repositories.com
Blog
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoAcerca deCómo clasificamosPrensaServidor MCP
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

Pruebas de penetración

Clasificación actualizada el 23 jun 2026

For an open source toolkit for penetration testing, the strongest matches are shadow1ng/fscan (Fscan is a comprehensive penetration testing and security auditing), rapid7/metasploit-framework (This is a comprehensive penetration testing platform that provides) and usestrix/strix (Strix is a comprehensive penetration testing and security auditing). beefproject/beef and greydgl/pentestgpt round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

Explora frameworks open-source, escáneres de vulnerabilidades y herramientas de explotación utilizadas para evaluar la seguridad de redes y aplicaciones.

Pruebas de penetración

Encuentra los mejores repositorios con IA.Buscaremos los repositorios que mejor coincidan usando IA.
  • shadow1ng/fscanAvatar de shadow1ng

    shadow1ng/fscan

    13,421Ver en GitHub↗

    Fscan is an automated penetration testing tool designed for internal network reconnaissance and vulnerability assessment. It functions as a comprehensive security framework that maps network infrastructure, identifies active hosts and services, and detects security weaknesses across internal environments. The tool distinguishes itself through a modular plugin architecture that allows for extensible security checks and a stateful asset tracking system that maintains an in-memory registry of discovered infrastructure. It incorporates a dedicated credential brute-force engine for testing passwor

    Fscan is a comprehensive penetration testing and security auditing framework that provides network reconnaissance, vulnerability scanning, credential testing, and post-exploitation capabilities through a modular command-line and web-based interface.

    GoNetwork Reconnaissance ToolsVulnerability ScannersVulnerability Assessment Frameworks
    Ver en GitHub↗13,421
  • rapid7/metasploit-frameworkAvatar de rapid7

    rapid7/metasploit-framework

    38,415Ver en GitHub↗

    The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures. The platform distinguishes itself through a modular architecture that supports reflective payload injection, allowing for the execution of code directly in memory without writing to disk. It utilizes an asynchronous event loop to

    This is a comprehensive penetration testing platform that provides the full suite of required features, including vulnerability scanning, exploit development, network reconnaissance, and reporting, all accessible through a command-line interface.

    RubyExploit FrameworksExploitation FrameworksExploit Development
    Ver en GitHub↗38,415
  • usestrix/strixAvatar de usestrix

    usestrix/strix

    20,138Ver en GitHub↗

    Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno

    Strix is a comprehensive penetration testing and security auditing framework that integrates vulnerability scanning, network reconnaissance, and automated exploit research through an AI-orchestrated, containerized environment.

    PythonInfrastructure ReconnaissanceSecurity Reporting ToolsVulnerability Scanners
    Ver en GitHub↗20,138
  • beefproject/beefAvatar de beefproject

    beefproject/beef

    10,728Ver en GitHub↗

    BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It functions as a platform for security professionals to evaluate client-side defenses by injecting persistent scripts into web browsers, establishing a bidirectional communication channel for remote command execution and data exfiltration. The framework distinguishes itself through its ability to use compromised browser sessions as proxies to conduct internal network reconnaissance, effectively bypassing perimeter security controls. It utilizes an event-driven control interface and

    BeEF is a specialized penetration testing framework focused on browser-based exploitation and client-side security auditing, providing essential reconnaissance and command execution capabilities for web application assessments.

    JavaScriptExploitation FrameworksNetwork Reconnaissance ToolsWeb Application Penetration Testing
    Ver en GitHub↗10,728
  • greydgl/pentestgptAvatar de GreyDGL

    GreyDGL/PentestGPT

    11,697Ver en GitHub↗

    PentestGPT is an autonomous security testing framework that leverages large language models to plan, execute, and coordinate end-to-end penetration testing engagements. By functioning as an autonomous agent, the system automates the entire testing lifecycle, from initial reconnaissance and vulnerability analysis to the generation of custom exploits and the execution of post-exploitation tasks. The platform distinguishes itself through a multi-agent orchestration system that coordinates specialized AI agents to collaborate on complex, multi-stage attack chains. It integrates multimodal context

    PentestGPT is an autonomous penetration testing framework that uses LLMs to orchestrate reconnaissance, vulnerability analysis, and exploitation tasks, fitting the category of an automated security auditing tool.

    PythonExploit FrameworksExploitation FrameworksInfrastructure Reconnaissance
    Ver en GitHub↗11,697
  • projectdiscovery/nucleiAvatar de projectdiscovery

    projectdiscovery/nuclei

    29,189Ver en GitHub↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Nuclei is a powerful, template-driven security scanning framework that provides robust vulnerability detection, network reconnaissance, and web application testing capabilities through a command-line interface.

    GoVulnerability ScannersAutomated Security ScannersVulnerability Assessment Frameworks
    Ver en GitHub↗29,189
  • ffuf/ffufAvatar de ffuf

    ffuf/ffuf

    15,618Ver en GitHub↗

    This tool is a command-line utility designed for automated web resource discovery, fuzzing, and application structure mapping. It functions as a security-focused scanner that identifies hidden files, directories, parameters, and virtual hosts by injecting payloads into HTTP requests. By systematically testing how servers handle various inputs, it assists in mapping the architecture of web applications and uncovering potential security vulnerabilities. The tool distinguishes itself through a highly concurrent engine that manages asynchronous request execution and recursive job orchestration. I

    This tool is a specialized fuzzer and web resource discovery utility that serves as a core component for web application security auditing and reconnaissance.

    GoSecurity Reporting ToolsWeb Application Penetration TestingAutomated Security Scanners
    Ver en GitHub↗15,618
  • 1n3/sn1perAvatar de 1N3

    1N3/Sn1per

    10,049Ver en GitHub↗

    Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan

    Sn1per is a comprehensive penetration testing and vulnerability management platform that integrates reconnaissance, scanning, and exploit validation into an automated pipeline, fulfilling all the requirements for a security auditing framework.

    ShellExploit FrameworksSecurity Report GenerationSecurity Reporting Tools
    Ver en GitHub↗10,049
  • bettercap/bettercapAvatar de bettercap

    bettercap/bettercap

    18,855Ver en GitHub↗

    Bettercap is a modular framework designed for network reconnaissance, security testing, and the execution of man-in-the-middle attacks. It functions as a comprehensive utility for surveying wired and wireless network segments, identifying connected devices, and analyzing communication protocols through real-time traffic interception and manipulation. The platform distinguishes itself through an event-driven architecture that coordinates network state changes and packet-level data through a centralized message pipeline. It provides a programmable scripting engine and an API for orchestrating s

    Bettercap is a powerful network reconnaissance and security testing framework that excels at traffic interception and protocol analysis, though it focuses more on network-level attacks than full-stack web application vulnerability scanning.

    GoNetwork Reconnaissance ToolsSecurity Reconnaissance Tools
    Ver en GitHub↗18,855
  • jasonxtn/argusAvatar de jasonxtn

    jasonxtn/Argus

    3,254Ver en GitHub↗

    Argus is a modular network reconnaissance framework designed for gathering network intelligence, mapping infrastructure, and assessing security postures through automated discovery tasks. It operates as a containerized security toolset that allows for the consistent execution of specialized information-gathering modules across different operating systems. The system functions as an infrastructure audit tool and a web application security scanner, performing tasks such as DNS lookups, port scanning, and the inspection of HTTP headers to detect vulnerabilities. It also serves as a threat intell

    Argus is a modular reconnaissance and infrastructure auditing framework that provides automated scanning and security assessment capabilities, fitting the category well despite lacking built-in exploit development features.

    PythonInfrastructure ReconnaissanceWeb Vulnerability Scanners
    Ver en GitHub↗3,254
  • google/tsunami-security-scannerAvatar de google

    google/tsunami-security-scanner

    8,584Ver en GitHub↗

    Tsunami Security Scanner is a network vulnerability scanner and security auditor designed to identify high-severity flaws across network assets. It functions as an asynchronous security probe engine that utilizes automated probes and specialized detection logic to find critical weaknesses and prioritize remediation efforts. The project is distinguished by a plugin-based scanning engine, which uses a modular architecture of interchangeable detection plugins to identify vulnerabilities. This extensibility allows for the development and integration of custom security plugins to expand the variet

    This is a specialized network vulnerability scanner that provides automated reconnaissance and detection capabilities, though it focuses more on scanning and auditing than on the exploit development or manual web application testing features requested.

    JavaNetwork Reconnaissance ToolsVulnerability ReportingVulnerability Scanners
    Ver en GitHub↗8,584
  • mishakorzik/allhackingtoolsAvatar de mishakorzik

    mishakorzik/AllHackingTools

    5,186Ver en GitHub↗

    AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of third-party hacking and security utilities from a single command interface. It functions as a centralized hub for network analysis, open source intelligence, penetration testing, and social engineering tools. The project provides specialized frameworks for gathering open source intelligence and searching for user profiles across social platforms. It includes toolkits for network reconnaissance, vulnerability scanning, and the execution of security exploits, as well as a social eng

    This repository acts as a centralized manager and installer for a wide collection of penetration testing and security auditing utilities, providing a command-line interface to access tools for reconnaissance, scanning, and exploitation.

    ShellNetwork Reconnaissance ToolsWeb Attack ToolsReconnaissance
    Ver en GitHub↗5,186
  • sullo/niktoAvatar de sullo

    sullo/nikto

    10,104Ver en GitHub↗

    Nikto is an open-source HTTP security auditing tool and web server vulnerability scanner. It functions as a reconnaissance engine designed to identify insecure server options, outdated software, and common vulnerabilities by analyzing HTTP responses. The project differentiates itself through capabilities for intrusion detection evasion and web server fingerprinting. It uses request-level encoding and timing spacers to bypass security filters and employs signature-based identification to determine specific server software versions and misconfigurations. The scanner covers broad capability are

    Nikto is a specialized web server vulnerability scanner that provides robust reconnaissance and auditing capabilities, though it focuses specifically on web infrastructure rather than being a comprehensive penetration testing framework that includes exploit development.

    PerlVulnerability Scanners
    Ver en GitHub↗10,104
  • yogeshojha/rengineAvatar de yogeshojha

    yogeshojha/rengine

    8,472Ver en GitHub↗

    Rengine is an automated reconnaissance framework and vulnerability management platform designed for attack surface monitoring. It functions as a centralized hub for discovering subdomains and open ports, gathering open-source intelligence, and tracking security flaws across target networks. The system integrates large language models to analyze reconnaissance data and generate vulnerability descriptions and insights. It distinguishes itself through a plugin-based tool integration that wraps external security scanning binaries and a target mapping system that tracks changes to assets over time

    This is an automated reconnaissance and vulnerability management platform that excels at network discovery and security tracking, though it functions more as an orchestration hub for external scanning tools rather than a standalone exploit development framework.

    HTMLInfrastructure ReconnaissanceSecurity Report Generation
    Ver en GitHub↗8,472
  • andresriancho/w3afAvatar de andresriancho

    andresriancho/w3af

    4,850Ver en GitHub↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    This is a comprehensive web penetration testing framework that provides vulnerability scanning, exploit development, and automated auditing capabilities through both a command-line and graphical interface.

    PythonPenetration Testing FrameworksSecurity Auditing ToolsTraffic Interception Tools
    Ver en GitHub↗4,850
  • aquasecurity/trivyAvatar de aquasecurity

    aquasecurity/trivy

    36,462Ver en GitHub↗

    Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai

    Trivy is a specialized security scanner focused on vulnerability detection and infrastructure auditing, which serves as a powerful component for the reconnaissance and scanning phases of a penetration testing workflow.

    GoVulnerability Scanners
    Ver en GitHub↗36,462
  • techarohq/anubisAvatar de TecharoHQ

    TecharoHQ/anubis

    17,067Ver en GitHub↗

    Anubis is a command-line security reconnaissance framework designed for subdomain enumeration and attack surface mapping. It functions as a utility for security professionals to identify, catalog, and visualize the external digital footprint of an organization by discovering all subdomains associated with a target domain. The tool distinguishes itself through a modular resolver pipeline that integrates passive reconnaissance from third-party security APIs and public certificate transparency logs. It combines this data with active discovery methods, including recursive DNS brute-forcing and al

    Anubis is a specialized reconnaissance utility for subdomain enumeration and attack surface mapping, but it lacks the broader vulnerability scanning, exploit development, and reporting capabilities required for a full penetration testing framework.

    GoInfrastructure ReconnaissanceSecurity Reconnaissance Tools
    Ver en GitHub↗17,067
  • hahwul/dalfoxAvatar de hahwul

    hahwul/dalfox

    4,846Ver en GitHub↗

    Dalfox is an automated web application security tool specifically designed for discovering and verifying cross-site scripting vulnerabilities. It functions as an XSS vulnerability scanner that analyzes HTTP parameters and DOM structures to identify reflected, stored, and blind injection points. The project distinguishes itself by providing a Model Context Protocol server and a REST API, allowing artificial intelligence agents and remote interfaces to trigger and manage security scans programmatically. It utilizes a payload mutation engine and fingerprinting strategies to execute WAF evasion t

    This is a specialized web application security scanner focused on XSS detection and verification, which serves as a powerful component for vulnerability testing within a broader security auditing workflow.

    GoVulnerability ScannersWeb Application Penetration Testing
    Ver en GitHub↗4,846
  • infinition/bjornAvatar de infinition

    infinition/Bjorn

    5,656Ver en GitHub↗

    Bjorn is a penetration testing framework that automates network scanning, credential brute-forcing, vulnerability assessment, and data exfiltration, all coordinated through an event-driven task pipeline and controlled via a web-based dashboard. Its modular plugin architecture allows independent security modules to be loaded and chained together, with an asynchronous network scanner discovering live hosts and open ports without blocking the main execution flow. The framework distinguishes itself by integrating a credential brute-force engine that systematically attempts login combinations agai

    Bjorn is a penetration testing framework that provides automated network scanning, vulnerability assessment, and post-exploitation capabilities, though it relies on a web-based dashboard rather than the command-line interface requested.

    PythonVulnerability Assessment Frameworks
    Ver en GitHub↗5,656
  • sqlmapproject/sqlmapAvatar de sqlmapproject

    sqlmapproject/sqlmap

    37,676Ver en GitHub↗

    This project is an automated security testing suite designed to detect and exploit database vulnerabilities. It functions as a command-line utility that streamlines the identification, verification, and exploitation of web application flaws by automating the injection of malicious payloads into input parameters. The tool provides a comprehensive framework for database enumeration, allowing users to extract schema information, user data, and system configurations from identified injection points. What distinguishes this tool is its sophisticated engine for dynamic payload adaptation and heuris

    This is a specialized penetration testing tool focused on automating the detection and exploitation of database-related vulnerabilities, providing a robust command-line interface for web application security auditing.

    PythonVulnerability Assessment Tools
    Ver en GitHub↗37,676
  • bee-san/rustscanAvatar de bee-san

    bee-san/RustScan

    19,969Ver en GitHub↗

    RustScan is a high-speed network reconnaissance tool designed for automated port discovery and service enumeration. It functions as an automated vulnerability scanner that identifies open ports and active services across network environments, providing a foundation for mapping attack surfaces and gathering intelligence on target systems. The tool distinguishes itself through its ability to dynamically adjust scanning parameters and concurrency in real-time based on system feedback, ensuring efficient performance while preventing network congestion. It features an extensible architecture that

    This is a specialized network reconnaissance and port scanning utility that serves as a building block for security workflows rather than a comprehensive penetration testing framework that includes exploit development or reporting features.

    RustNetwork Reconnaissance ToolsVulnerability Scanners
    Ver en GitHub↗19,969
  • six2dez/reconftwAvatar de six2dez

    six2dez/reconftw

    7,226Ver en GitHub↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    This is a comprehensive reconnaissance and attack surface management framework that automates vulnerability scanning and intelligence gathering, serving as a specialized component within a broader penetration testing workflow.

    ShellInfrastructure ReconnaissanceSecurity Report GenerationReconnaissance
    Ver en GitHub↗7,226
  • jaykali/maskphishAvatar de jaykali

    jaykali/maskphish

    3,020Ver en GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    This framework provides a command-line interface for network reconnaissance, vulnerability scanning, and penetration testing, though its primary focus on social engineering and payload generation makes it a specialized tool rather than a general-purpose auditing suite.

    ShellInfrastructure ReconnaissanceNetwork Reconnaissance ToolsVulnerability Scanners
    Ver en GitHub↗3,020
  • z4nzu/hackingtoolAvatar de Z4nzu

    Z4nzu/hackingtool

    77,515Ver en GitHub↗

    This project is a comprehensive cybersecurity tool collection designed to support security research, penetration testing, and vulnerability assessment. It functions as a unified penetration testing suite, providing a centralized environment where professionals can access a wide range of offensive security utilities to identify system weaknesses and study attack vectors. The platform distinguishes itself through a modular architecture that aggregates disparate security scripts into a single, hierarchical command-line interface. It simplifies the management of these utilities by integrating ext

    This repository is a collection and installer for various third-party security scripts rather than a unified penetration testing framework that provides its own vulnerability scanning or exploit development engine.

    PythonExploit FrameworksWeb Attack ToolsVulnerability Assessment Frameworks
    Ver en GitHub↗77,515
  • anchore/grypeAvatar de anchore

    anchore/grype

    12,423Ver en GitHub↗

    Grype is a command-line security scanner designed to identify known vulnerabilities within container images, filesystems, and software manifests. It functions as a software composition analysis tool that detects security flaws in application components and open-source libraries to support supply chain security. The tool distinguishes itself by reconstructing the final state of container images through layered filesystem inspection and normalizing diverse package formats into a unified dependency graph. It maintains a local cache of security advisories synchronized from multiple upstream sourc

    This tool is a specialized software composition analysis scanner for container images and dependencies, which serves as a building block for supply chain security rather than a comprehensive penetration testing framework for active network or application exploitation.

    GoSecurity Reporting ToolsSecurity Vulnerability ReportingAutomated Security Scanners
    Ver en GitHub↗12,423
Compara los 10 mejores de un vistazo
RepositorioEstrellasLenguajeLicenciaÚltimo push
shadow1ng/fscan13.4KGomit31 ene 2026
rapid7/metasploit-framework38.4KRubyNOASSERTION16 jun 2026
usestrix/strix20.1KPythonapache-2.019 feb 2026
beefproject/beef10.7KJavaScript—19 feb 2026
greydgl/pentestgpt11.7KPythonmit18 feb 2026
projectdiscovery/nuclei29.2KGoMIT15 jun 2026
ffuf/ffuf15.6KGomit24 abr 2025
1n3/sn1per10KShellother29 abr 2026
bettercap/bettercap18.9KGoother31 dic 2025
jasonxtn/argus3.3KPythonmit10 dic 2025

Related searches

  • un framework de seguridad para operaciones de pruebas de penetración
  • un framework autónomo para pruebas de penetración
  • framework de pruebas de penetración para auditorías de seguridad
  • framework de pruebas de penetración open source
  • Seguridad y explotación de aplicaciones web
  • Herramientas ofensivas y Red Teaming
  • una herramienta de pruebas de inyección SQL
  • a professional certification for breach and attack simulation