awesome-repositories.com
Blog
MCP
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetServeur MCPÀ proposNotre méthodologiePresse
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

17 dépôts

Awesome GitHub RepositoriesPenetration Testing Tools

Comprehensive toolkits and browser extensions for web application security testing.

Explore 17 awesome GitHub repositories matching part of an awesome list · Penetration Testing Tools. Refine with filters or upvote what's useful.

Awesome Penetration Testing Tools GitHub Repositories

Trouvez les meilleurs dépôts grâce à l'IA.Nous recherchons les dépôts les plus pertinents grâce à l'IA.
  • immersive-translate/immersive-translateAvatar de immersive-translate

    immersive-translate/immersive-translate

    17,917Voir sur GitHub↗

    Immersive Translate is a browser-based translation tool that integrates third-party translation engines and large language models to provide automated, real-time text conversion directly within the web interface. It functions as a browser extension that intercepts and modifies web content, injecting translated text nodes into the document object model to maintain original page layouts and styling. The project distinguishes itself through its granular control over the translation process, allowing users to define site-specific rules, manage custom terminology glossaries, and customize translat

    Translation tool for analyzing foreign language web content.

    chrome-extensionsafari-extensiontranslation
    Voir sur GitHub↗17,917
  • yaklang/yakitAvatar de yaklang

    yaklang/yakit

    7,386Voir sur GitHub↗

    Yakit is a comprehensive cybersecurity all-in-one platform designed for security assessments. It integrates a suite of core tools including an HTTP interception proxy for real-time traffic modification, an out-of-band interaction detector for verifying remote command execution via TCP, DNSLog, and ICMP, and a reverse shell manager for controlling remote server connections. The platform is distinguished by its dedicated security scripting environment, which allows for the development and execution of custom logic and plugins using a specialized high-performance language. It further extends fun

    Integrated security testing platform for web applications.

    TypeScriptblueteamburpsuiteexploit
    Voir sur GitHub↗7,386
  • zero-peak/zeroomegaAvatar de zero-peak

    zero-peak/ZeroOmega

    6,954Voir sur GitHub↗

    ZeroOmega is a web-based proxy orchestrator and manager designed for real-time updates to active network gateways. It functions as a system for configuring, storing, and switching between different network proxy profiles to direct internet traffic. The project features a PAC script generator that translates structured proxy profile data into auto-configuration files. These scripts automate network routing decisions by matching requested URLs against defined patterns. Administration is handled through a browser-based interface that allows for the modification of routing rules and the manageme

    Proxy management extension for browser-based testing.

    CoffeeScriptproxyswitchyomegazeroomega
    Voir sur GitHub↗6,954
  • callumlocke/json-formatterAvatar de callumlocke

    callumlocke/json-formatter

    4,118Voir sur GitHub↗

    Ce projet est un formateur et visualiseur JSON basé sur le web conçu pour le débogage structurel et l'exploration de données. Il transforme les chaînes JSON brutes en une structure arborescente lisible présentant la coloration syntaxique, des guides d'indentation et des nœuds repliables. L'outil fournit un visualiseur de données pour comparer les réponses brutes du serveur avec les représentations analysées. Il inclut également un exportateur de console qui envoie les données JSON analysées vers la console de développement du navigateur en tant que variable globale pour une inspection et une manipulation immédiates. Le système couvre l'inspection des réponses API et l'analyse de structure JSON, permettant aux utilisateurs de basculer entre le texte brut et les vues formatées pour vérifier des données imbriquées complexes.

    Extension for formatting and inspecting JSON responses.

    TypeScript
    Voir sur GitHub↗4,118
  • gh0stkey/haeAvatar de gh0stkey

    gh0stkey/HaE

    4,034Voir sur GitHub↗

    HaE is a network traffic analysis tool designed to extract, classify, and highlight specific data fragments within network messages and HTTP traffic. It functions as an HTTP data extractor and traffic content filter, utilizing a network metadata aggregator to centralize highlighted data fragments and annotations for analysis. The tool identifies high-value network packets by mapping classification results to visual color markers and employs a modular classification system to isolate data fragments from binary or text streams. It distinguishes the severity of matched data by piping extracted c

    Burp Suite extension for highlighting and extracting sensitive data.

    Javabughunterburpsuitedata-security
    Voir sur GitHub↗4,034
  • whwlsfb/burpcryptoAvatar de whwlsfb

    whwlsfb/BurpCrypto

    1,633Voir sur GitHub↗

    BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite). 支持多种加密算法或直接执行JS代码的用于爆破前端加密的BurpSuite插件

    Burp Suite extension for handling various cryptographic operations.

    Javaburp-extensionsburp-pluginburpcrypto
    Voir sur GitHub↗1,633
  • moustachauve/cookie-editorAvatar de Moustachauve

    Moustachauve/cookie-editor

    1,572Voir sur GitHub↗

    A powerful browser extension to create, edit and delete cookies

    Extension for managing and manipulating browser cookies.

    JavaScriptandroidbrowser-extensionchrome
    Voir sur GitHub↗1,572
  • f0ng/autodecoderAvatar de f0ng

    f0ng/autoDecoder

    1,410Voir sur GitHub↗

    Burp插件,根据自定义来达到对数据包的处理(适用于加解密、爆破等),类似mitmproxy,不同点在于经过了burp中转,在自动加解密的基础上,不影响APP、网站加解密正常逻辑等。

    Burp Suite extension for automated request/response decoding.

    Javaburpburp-pluginburpsuite-extender
    Voir sur GitHub↗1,410
  • simov/markdown-viewerAvatar de simov

    simov/markdown-viewer

    1,420Voir sur GitHub↗

    Extension for rendering markdown documentation during assessments.

    JavaScriptbrowser-extensionchromechrome-extension
    Voir sur GitHub↗1,420
  • f6jo/routevulscanAvatar de F6JO

    F6JO/RouteVulScan

    1,323Voir sur GitHub↗

    Burpsuite - Route Vulnerable Scanning 递归式被动检测脆弱路径的burp插件

    Burp Suite extension for scanning routing-related vulnerabilities.

    Java
    Voir sur GitHub↗1,323
  • whwlsfb/log4j2scanAvatar de whwlsfb

    whwlsfb/Log4j2Scan

    835Voir sur GitHub↗

    Log4j2 RCE Passive Scanner plugin for BurpSuite

    Burp Suite scanner for identifying Log4j vulnerabilities.

    Java
    Voir sur GitHub↗835
  • youmulijiang/haetoyakitY

    youmulijiang/HaeToYakit

    0Voir sur GitHub↗

    Integration tool between different security testing platforms.

    Voir sur GitHub↗0
  • mrknow001/burpappletpentesterM

    mrknow001/BurpAppletPentester

    0Voir sur GitHub↗

    Burp Suite extension for decrypting session keys.

    Voir sur GitHub↗0
  • ghr07h/heimdallrG

    Ghr07h/Heimdallr

    0Voir sur GitHub↗

    Browser extension for detecting honeypot interactions.

    Voir sur GitHub↗0
  • dpacassi/disable-javascriptD

    dpacassi/disable-javascript

    0Voir sur GitHub↗

    Extension for testing web application behavior without JavaScript.

    Voir sur GitHub↗0
  • 0140454/hackbar0

    0140454/hackbar

    0Voir sur GitHub↗

    Browser extension for manual web application security testing.

    Voir sur GitHub↗0
  • residuallaugh/findsomethingR

    ResidualLaugh/FindSomething

    0Voir sur GitHub↗

    Tool for discovering sensitive information in web source code.

    Voir sur GitHub↗0
  1. Home
  2. Part of an Awesome List
  3. Developer Tools
  4. Penetration Testing Tools