awesome-repositories.com
Blog
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoAcerca deCómo clasificamosPrensaServidor MCP
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to hightechsec/git-scanner

Open-source alternatives to Git Scanner

30 open-source projects similar to hightechsec/git-scanner, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Git Scanner alternative.

  • sqlmapproject/sqlmapAvatar de sqlmapproject

    sqlmapproject/sqlmap

    37,676Ver en GitHub↗

    This project is an automated security testing suite designed to detect and exploit database vulnerabilities. It functions as a command-line utility that streamlines the identification, verification, and exploitation of web application flaws by automating the injection of malicious payloads into input parameters. The tool provides a comprehensive framework for database enumeration, allowing users to extract schema information, user data, and system configurations from identified injection points. What distinguishes this tool is its sophisticated engine for dynamic payload adaptation and heuris

    Pythondatabasedetectionexploitation
    Ver en GitHub↗37,676
  • nil0x42/phpsploitAvatar de nil0x42

    nil0x42/phpsploit

    2,475Ver en GitHub↗

    Full-featured C2 framework which silently persists on webserver with a single-line PHP backdoor

    Pythonadvanced-persistent-threatbackdoorblackhat
    Ver en GitHub↗2,475
  • ultimatehackers/xsstrikeAvatar de UltimateHackers

    UltimateHackers/XSStrike

    15,027Ver en GitHub↗

    XSStrike is a security tool designed to detect cross-site scripting vulnerabilities through parameter fuzzing and web response analysis. It functions as a web application fuzzer and vulnerability scanner that identifies injection points and security flaws. The project includes a specialized utility for detecting blind XSS, where payloads execute asynchronously or on separate pages. It also features a JavaScript library auditor to identify outdated libraries with known vulnerabilities and a dedicated tool for identifying and bypassing web application firewalls using various evasion techniques.

    Python
    Ver en GitHub↗15,027

Búsqueda con IA

Explora más repositorios increíbles

Describe lo que necesitas en lenguaje sencillo: la IA clasifica miles de proyectos open-source curados por relevancia.

Find more with AI search
  • wpscanteam/wpscanAvatar de wpscanteam

    wpscanteam/wpscan

    9,636Ver en GitHub↗

    WPScan is a security analysis utility and vulnerability scanner designed specifically for auditing WordPress installations and other content management systems. It functions as a web application security tool that identifies misconfigurations, outdated software, and security holes in core installations, plugins, and themes. The tool employs black-box scanning techniques to perform site component enumeration, identifying users, themes, and plugins by matching known file paths and response signatures. It matches these detected components against a database of known security flaws to analyze the

    Ruby
    Ver en GitHub↗9,636
  • zaproxy/zaproxyAvatar de zaproxy

    zaproxy/zaproxy

    15,293Ver en GitHub↗

    OWASP ZAP is a dynamic application security testing tool and intercepting HTTP proxy used to find vulnerabilities in web applications. It functions as a penetration testing framework that enables both automated security scanning and manual security testing of running web services. The tool provides a suite of capabilities for analyzing web applications from the outside in, including the ability to capture and modify traffic between a browser and a target application. It is designed to integrate into DevSecOps pipelines to provide consistent security checks across different environments.

    Java
    Ver en GitHub↗15,293
  • spectralops/keyscopeAvatar de SpectralOps

    SpectralOps/keyscope

    411Ver en GitHub↗

    Keyscope is a key and secret workflow (validation, invalidation, etc.) tool built in Rust

    Rust
    Ver en GitHub↗411
  • v8blink/chromium-based-xss-taint-trackingAvatar de v8blink

    v8blink/Chromium-based-XSS-Taint-Tracking

    127Ver en GitHub↗

    Cyclops 是一款具有 XSS 检测功能的浏览器

    Ver en GitHub↗127
  • subfinder/subfinderAvatar de subfinder

    subfinder/subfinder

    13,859Ver en GitHub↗

    Subfinder is a passive subdomain enumeration tool and DNS asset discovery utility designed for mapping the external attack surface of a domain. It functions as a passive reconnaissance framework that identifies subdomains by querying curated third-party data sources and APIs without interacting directly with the target infrastructure. The tool utilizes a modular provider interface to integrate various passive sources and employs concurrent request orchestration to manage simultaneous network queries. It includes wildcard DNS filtering to identify and remove catch-all records, ensuring the res

    Go
    Ver en GitHub↗13,859
  • lanmaster53/recon-ngAvatar de lanmaster53

    lanmaster53/recon-ng

    5,698Ver en GitHub↗

    recon-ng is an open source intelligence reconnaissance framework designed to automate the collection and aggregation of public information. It is a modular intelligence tool that utilizes a system of pluggable modules to harvest target data, resolve DNS queries, and parse web content. The framework is built as an API-driven tool with a programmatic interface to integrate with other security workflows. It is provided as a containerized application, using Docker to ensure a consistent environment for running reconnaissance tasks and managing a persistent data store. Its capabilities cover exte

    Python
    Ver en GitHub↗5,698
  • codingo/vhostscanAvatar de codingo

    codingo/VHostScan

    1,299Ver en GitHub↗

    A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.

    Pythonbugbountyctf-toolsdiscovery-service
    Ver en GitHub↗1,299
  • tijme/angularjs-csti-scannerAvatar de tijme

    tijme/angularjs-csti-scanner

    324Ver en GitHub↗

    Automated client-side template injection (sandbox escape/bypass) detection for AngularJS v1.x.

    Python
    Ver en GitHub↗324
  • epi052/feroxbusterAvatar de epi052

    epi052/feroxbuster

    7,522Ver en GitHub↗

    Feroxbuster is an HTTP directory brute forcer and web resource enumerator designed to discover hidden files and directories on web servers. It functions as a recursive URL scanner that identifies unlinked endpoints and API resources by combining wordlist-based scanning with automated crawling. The tool operates as a proxy-aware fuzzer, allowing network requests to be routed through HTTP or SOCKS proxies for traffic interception or anonymity. It utilizes recursive directory crawling to automatically queue discovered paths and find nested content. The system includes capabilities for discovery

    Rustcontent-discoveryenumerationhacktoberfest
    Ver en GitHub↗7,522
  • bjeborn/basic-auth-potAvatar de bjeborn

    bjeborn/basic-auth-pot

    54Ver en GitHub↗

    bap - http Basic Authentication honeyPot

    Python
    Ver en GitHub↗54
  • biox/paAvatar de biox

    biox/pa

    562Ver en GitHub↗

    pa a simple password manager https://passwordass.org

    Shell
    Ver en GitHub↗562
  • arthaud/git-dumperAvatar de arthaud

    arthaud/git-dumper

    2,553Ver en GitHub↗
    Pythongitsecurityweb
    Ver en GitHub↗2,553
  • berzerk0/probable-wordlistsAvatar de berzerk0

    berzerk0/Probable-Wordlists

    9,289Ver en GitHub↗

    Probable-Wordlists is a collection of curated data resources providing password frequency lists, character masks, and common identity identifiers for security research. These resources serve as credential analysis tools to identify popular password trends and support the creation of secure credentials. The project provides password frequency wordlists and security research wordlists, including common usernames and top-level domains. It includes password recovery datasets featuring character masks and rule sets designed to analyze vulnerability patterns. The repository covers a broad range of

    dictionarydictionary-attackpassword
    Ver en GitHub↗9,289
  • beefproject/beefAvatar de beefproject

    beefproject/beef

    10,728Ver en GitHub↗

    BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It functions as a platform for security professionals to evaluate client-side defenses by injecting persistent scripts into web browsers, establishing a bidirectional communication channel for remote command execution and data exfiltration. The framework distinguishes itself through its ability to use compromised browser sessions as proxies to conduct internal network reconnaissance, effectively bypassing perimeter security controls. It utilizes an event-driven control interface and

    JavaScript
    Ver en GitHub↗10,728
  • archerysec/archerysecAvatar de archerysec

    archerysec/archerysec

    2,461Ver en GitHub↗

    ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

    JavaScript
    Ver en GitHub↗2,461
  • alebcay/awesome-shellAvatar de alebcay

    alebcay/awesome-shell

    37,110Ver en GitHub↗

    This project is a community-driven directory that serves as a comprehensive index of command-line tools, frameworks, and resources. It functions as a curated knowledge base designed to help users discover software for enhancing terminal environments and streamlining daily development tasks. The collection is maintained through an open-source contribution model, where community members manually verify and organize resources into structured categories. This collaborative approach ensures the directory remains a reliable reference for finding specialized utilities, alternative shell implementati

    awesomeawesome-listbash
    Ver en GitHub↗37,110
  • codingo/nosqlmapAvatar de codingo

    codingo/NoSQLMap

    3,304Ver en GitHub↗

    Automated NoSQL database enumeration and web application exploitation tool.

    Python
    Ver en GitHub↗3,304
  • bad-antics/nullsec-webfuzzAvatar de bad-antics

    bad-antics/nullsec-webfuzz

    6Ver en GitHub↗

    Rust web fuzzer - async/await, Tokio, directory brute-force

    Makefile
    Ver en GitHub↗6
  • cn0xroot/rfsec-toolkitAvatar de cn0xroot

    cn0xroot/RFSec-ToolKit

    1,705Ver en GitHub↗

    RFSec-ToolKit is a collection of Radio Frequency Communication Protocol Hacktools.无线通信协议相关的工具集,可借助SDR硬件+相关工具对无线通信进行研究。Collect with ♥ by HackSmith

    bladerfcommunicationfuzzing
    Ver en GitHub↗1,705
  • commixproject/commixAvatar de commixproject

    commixproject/commix

    5,757Ver en GitHub↗

    Commix is an automated tool for detecting and exploiting OS command injection vulnerabilities in web applications. It probes user-supplied input vectors with heuristic test payloads, analyzes response differences to identify injection points, and then automates the execution of arbitrary operating system commands on the target server. The tool distinguishes itself through a multi-layer filter bypass engine that evaluates input constraints independently per filter type and composes tailored evasion strategies into a single payload. A modular payload tamper pipeline transforms raw injection str

    Python
    Ver en GitHub↗5,757
  • cugu/awesome-forensicsAvatar de cugu

    cugu/awesome-forensics

    4,911Ver en GitHub↗
    computer-forensicsdfirdigital-forensics
    Ver en GitHub↗4,911
  • danielmiessler/seclistsAvatar de danielmiessler

    danielmiessler/SecLists

    71,596Ver en GitHub↗

    SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities. The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution log

    PHP
    Ver en GitHub↗71,596
  • danmcinerney/dnsspoofAvatar de DanMcInerney

    DanMcInerney/dnsspoof

    294Ver en GitHub↗

    DNS spoofer. Drops DNS responses from the router and replaces it with the spoofed DNS response

    Python
    Ver en GitHub↗294
  • davidprobinsky/redteam-physical-toolsAvatar de DavidProbinsky

    DavidProbinsky/RedTeam-Physical-Tools

    583Ver en GitHub↗

    Red Team Toolkit - A curated list of tools that are commonly used in the field for Physical Security, Red Teaming, and Tactical Covert Entry.

    edcethicalhackinghacking
    Ver en GitHub↗583
  • denispodgurskii/pentestkitAvatar de DenisPodgurskii

    DenisPodgurskii/pentestkit

    220Ver en GitHub↗

    OWASP PTK - application security browser extension.

    JavaScript
    Ver en GitHub↗220
  • ebookfoundation/free-programming-booksAvatar de EbookFoundation

    EbookFoundation/free-programming-books

    390,347Ver en GitHub↗

    This project is a centralized, open-access repository that serves as a structured directory for technical education and professional development. It functions as a community-driven knowledge base, aggregating high-quality learning materials to support global accessibility to computer science and software engineering resources. The platform distinguishes itself through a collaborative governance model that utilizes peer-reviewed workflows for all content additions and modifications. By leveraging structured text files and decentralized version control, the repository maintains a searchable, hu

    Pythonbookseducationhacktoberfest
    Ver en GitHub↗390,347
  • clong/detectionlabAvatar de clong

    clong/DetectionLab

    4,904Ver en GitHub↗

    DetectionLab is a reproducible Windows Active Directory security lab designed for testing detection capabilities. It uses an automation framework based on Vagrant and Packer to provision virtualized networks across multiple hypervisors and cloud platforms. The project utilizes Ansible for the declarative installation and configuration of domain services and endpoint security tools. It incorporates a browser-based remote access interface via Apache Guacamole to manage laboratory hosts without requiring standalone remote desktop clients. The environment includes a telemetry pipeline that aggre

    HTMLansibledetectiondetectionlab
    Ver en GitHub↗4,904