awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to wtsxdev/penetration-testing

Open-source alternatives to Penetration Testing

14 open-source projects similar to wtsxdev/penetration-testing, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Penetration Testing alternative.

  • arainho/awesome-api-securityarainho avatar

    arainho/awesome-api-security

    3,644View on GitHub↗
    api-hackingapi-hacksapi-hardening
    View on GitHub↗3,644
  • dolevf/damn-vulnerable-graphql-applicationdolevf avatar

    dolevf/Damn-Vulnerable-GraphQL-Application

    1,691View on GitHub↗

    Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.

    JavaScript
    View on GitHub↗1,691
  • erev0s/vampierev0s avatar

    erev0s/VAmPI

    1,245View on GitHub↗

    Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

    Python
    View on GitHub↗1,245
  • infoslack/awesome-web-hackinginfoslack avatar

    infoslack/awesome-web-hacking

    6,909View on GitHub↗

    A list of web application security

    appsechackinghacking-tools
    View on GitHub↗6,909
  • microsoft/security-101microsoft avatar

    microsoft/Security-101

    6,203View on GitHub↗

    Security-101 is a vendor-agnostic, foundational cybersecurity learning curriculum organized into modular, framework-aligned modules. It is designed to build core knowledge across multiple security domains without tying content to specific products or platforms, making it suitable for both beginners and professionals seeking a structured introduction to the field. The curriculum is built around established security frameworks, including the MITRE ATT&CK framework for standardized threat analysis and the NIST Cybersecurity Framework for incident response workflows. It covers a broad range of do

    HTMLappseccia-triaddata-protection
    View on GitHub↗6,203

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • owasp/wstgOWASP avatar

    OWASP/wstg

    9,473View on GitHub↗

    The Web Application Security Testing Guide is an open-source security testing standard and comprehensive framework of procedures for identifying vulnerabilities in web applications and services. It serves as a vulnerability assessment methodology and a web API security audit framework, providing a structured approach for conducting consistent and thorough security audits of web-based software. The project utilizes a methodology-based audit framework and checklist-driven workflows to ensure repeatable discovery and exploitation steps. It organizes security tests through taxonomy-based vulnerab

    application-securityappsecbest-practices
    View on GitHub↗9,473
  • paragonie/awesome-appsecparagonie avatar

    paragonie/awesome-appsec

    6,831View on GitHub↗
    PHPapplication-securitycuratedowasp
    View on GitHub↗6,831
  • projectdiscovery/nucleiprojectdiscovery avatar

    projectdiscovery/nuclei

    29,189View on GitHub↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Goattack-surfacecve-scannerdast
    View on GitHub↗29,189
  • qazbnm456/awesome-web-securityqazbnm456 avatar

    qazbnm456/awesome-web-security

    13,097View on GitHub↗

    This project serves as a comprehensive cybersecurity training platform and resource repository focused on web application security. It functions as a centralized hub for security practitioners, providing both a curated collection of technical documentation and research, and a system for deploying isolated, containerized environments to practice security analysis and exploitation techniques. The platform distinguishes itself by integrating automated data aggregation with hands-on, container-based orchestration. It maintains a current knowledge base of industry research and digital threats whil

    awesomeawesome-listlist
    View on GitHub↗13,097
  • sbilly/awesome-securitysbilly avatar

    sbilly/awesome-security

    14,022View on GitHub↗

    This project is a comprehensive, curated directory of cybersecurity resources, software, and documentation designed to support system and network protection. It serves as a centralized knowledge base and index for security professionals, aggregating industry-standard practices and open-source tools across a wide range of technical domains. The repository distinguishes itself by providing a structured collection of methodologies and frameworks for security operations. It covers critical areas including threat intelligence, digital forensics, infrastructure auditing, and vulnerability assessmen

    awesome-listsecurity
    View on GitHub↗14,022
  • shieldfy/api-security-checklistshieldfy avatar

    shieldfy/API-Security-Checklist

    23,258View on GitHub↗

    This project is a comprehensive API security audit checklist and vulnerability audit framework. It provides a structured guide of security countermeasures for designing, testing, and deploying secure APIs across various protocols. The framework includes specialized guides for securing OAuth 2.0 authorization flows, implementing zero trust networking for service-to-service communication, and protecting GraphQL endpoints from resource exhaustion and information leakage. It also provides standards for integrating static analysis, dynamic scanning, and secret detection into CI/CD delivery pipelin

    apijwtoauth2
    View on GitHub↗23,258
  • sottlmarek/devsecopssottlmarek avatar

    sottlmarek/DevSecOps

    6,596View on GitHub↗
    automationawesomeawesome-list
    View on GitHub↗6,596
  • vaib25vicky/awesome-mobile-securityvaib25vicky avatar

    vaib25vicky/awesome-mobile-security

    3,502View on GitHub↗

    An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.

    View on GitHub↗3,502
  • zaproxy/zaproxyzaproxy avatar

    zaproxy/zaproxy

    15,293View on GitHub↗

    OWASP ZAP is a dynamic application security testing tool and intercepting HTTP proxy used to find vulnerabilities in web applications. It functions as a penetration testing framework that enables both automated security scanning and manual security testing of running web services. The tool provides a suite of capabilities for analyzing web applications from the outside in, including the ability to capture and modify traffic between a browser and a target application. It is designed to integrate into DevSecOps pipelines to provide consistent security checks across different environments.

    Java
    View on GitHub↗15,293