awesome-repositories.com
Blog
MCP
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetServeur MCPÀ proposNotre méthodologiePresse
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

56 dépôts

Awesome GitHub RepositoriesVulnerability Exploitation Frameworks

Specialized frameworks for detecting and exploiting specific vulnerabilities in CMS, middleware, and applications.

Explore 56 awesome GitHub repositories matching part of an awesome list · Vulnerability Exploitation Frameworks. Refine with filters or upvote what's useful.

Awesome Vulnerability Exploitation Frameworks GitHub Repositories

Trouvez les meilleurs dépôts grâce à l'IA.Nous recherchons les dépôts les plus pertinents grâce à l'IA.
  • manisso/fsocietyAvatar de Manisso

    Manisso/fsociety

    12,136Voir sur GitHub↗

    fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits. It functions as a wrapper that integrates external security binaries into a unified, menu-driven interface, providing a centralized system for command-line parameter mapping and execution. The project distinguishes itself by organizing specialized utilities into domain-specific collections for structured navigation. It automates the transition between different phases of an audit by chaining reconnaissance and exploitation tools through sequential workflow automation. The fram

    Launches automated exploits against web applications and services to confirm unauthorized access.

    Pythonbrute-force-attacksdesktopexploitation
    Voir sur GitHub↗12,136
  • liamg/traitorAvatar de liamg

    liamg/traitor

    7,144Voir sur GitHub↗

    Traitor is a Linux privilege escalation framework and automated root exploit suite. It provides specialized utilities for scanning system misconfigurations and deploying automated exploit scripts on local Linux hosts to elevate user privileges to the root level. The tool identifies insecure system setups and binary vulnerabilities, such as GTFOBins, to map potential routes for gaining root access. It automates the process of discovering and exploiting these local vulnerabilities through targeted exploit execution and the deployment of sequential scripts. The system covers vulnerability asses

    Runs a predetermined sequence of vulnerability triggers to automatically establish a root shell.

    Gocve-2021-3560cve-2022-0847dirtypipe
    Voir sur GitHub↗7,144
  • guardicore/monkeyAvatar de guardicore

    guardicore/monkey

    7,014Voir sur GitHub↗

    Monkey is an adversary emulation platform and breach and attack simulation tool designed to test network defenses through automated lateral movement and exploit delivery. It functions as a network security testing system that evaluates security posture by attempting to propagate through vulnerabilities and extract sensitive system credentials. The platform distinguishes itself by simulating specific real-world attacker behaviors, such as ransomware encryption, cryptojacking, and the theft of browser-stored credentials and secure shell keys. It utilizes binary hash randomization to evade antiv

    Uses a library of plugins to propagate through known network vulnerabilities and test security perimeters.

    Python
    Voir sur GitHub↗7,014
  • k8gege/k8toolsAvatar de k8gege

    k8gege/K8tools

    6,167Voir sur GitHub↗

    K8tools is a multi-stage attack framework that combines memory-only payload execution, credential testing, port forwarding, privilege escalation, and physical USB-based keystroke injection for comprehensive system compromise. At its core, the Ladon PowerShell module loads a multi-function scanner directly into memory, enabling command execution without writing files to disk, while supporting memory-only payload delivery that downloads and runs obfuscated shellcode or PowerShell commands to evade antivirus detection. The framework distinguishes itself through its breadth of integrated capabili

    Launches pre-built exploits against web applications, operating systems, and services.

    PowerShell0daybrute-forcebypass
    Voir sur GitHub↗6,167
  • commixproject/commixAvatar de commixproject

    commixproject/commix

    5,757Voir sur GitHub↗

    Commix is an automated tool for detecting and exploiting OS command injection vulnerabilities in web applications. It probes user-supplied input vectors with heuristic test payloads, analyzes response differences to identify injection points, and then automates the execution of arbitrary operating system commands on the target server. The tool distinguishes itself through a multi-layer filter bypass engine that evaluates input constraints independently per filter type and composes tailored evasion strategies into a single payload. A modular payload tamper pipeline transforms raw injection str

    Automates the detection and exploitation of OS command injection vulnerabilities to execute arbitrary commands on target servers.

    Python
    Voir sur GitHub↗5,757
  • nullarray/autosploitAvatar de NullArray

    NullArray/AutoSploit

    5,240Voir sur GitHub↗

    AutoSploit est un framework d'exploitation automatisé conçu pour découvrir des hôtes distants et exécuter des modules d'exploitation à grande échelle pour établir des reverse shells. Il fonctionne comme un outil de reconnaissance réseau et un orchestrateur d'exécution de code à distance, gérant le déploiement de modules d'attaque contre plusieurs cibles. Le système dispose d'un masqueur de trafic basé sur proxy qui achemine les requêtes réseau via des serveurs externes et fait pivoter les en-têtes HTTP et les agents utilisateurs pour masquer la source de l'activité. Il permet une orchestration d'exploitation personnalisée via l'intégration de modules d'attaque externes et la gestion des paramètres de connexion de l'espace de travail. Le framework couvre la découverte de cibles via des requêtes de moteurs de recherche et des intégrations API, ainsi que la gestion de listes de cibles utilisant des fichiers externes et des listes blanches. Il inclut en outre des capacités pour la configuration d'écouteurs basés sur des sessions pour capturer les connexions distantes entrantes.

    Automates the execution of multiple exploit modules against targets to achieve remote code execution at scale.

    Python
    Voir sur GitHub↗5,240
  • andresriancho/w3afAvatar de andresriancho

    andresriancho/w3af

    4,850Voir sur GitHub↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    Tests the viability of discovered security holes to confirm if they permit unauthorized access or data extraction.

    Pythonappseccross-site-scriptingscanner
    Voir sur GitHub↗4,850
  • zhzyker/exphubAvatar de zhzyker

    zhzyker/exphub

    4,282Voir sur GitHub↗

    Exphub est une bibliothèque de scripts d'exploitation CVE et une suite de vulnérabilités logicielles d'entreprise conçue pour vérifier et exploiter des failles de sécurité connues dans des environnements serveurs tels que WebLogic, Struts2, Tomcat et JBoss. Il fonctionne comme un toolkit d'exécution de code à distance et un framework de déploiement de web shell pour déclencher l'exécution de commandes non autorisées et établir un accès persistant sur des systèmes distants. Le projet inclut des utilitaires spécialisés pour la reconnaissance de réseaux internes, utilisant spécifiquement la falsification de requêtes côté serveur (SSRF) pour scanner les ports et services ouverts. Il fournit en outre des mécanismes pour contourner les contrôles d'accès et effectuer des lectures et téléchargements de fichiers non autorisés. La suite couvre de larges domaines de capacités, notamment l'évaluation des vulnérabilités, les tests d'intrusion et l'exécution de scripts de preuve de concept pour confirmer la présence de failles de sécurité.

    Provides a framework for detecting and exploiting security flaws in middleware and application frameworks.

    Pythoncve-2020-10199cve-2020-10204cve-2020-11444
    Voir sur GitHub↗4,282
  • jtesta/ssh-auditAvatar de jtesta

    jtesta/ssh-audit

    4,218Voir sur GitHub↗

    This project is an SSH security audit tool designed to analyze server and client configurations. It functions as a cryptographic analyzer that evaluates key exchange, MAC, and encryption algorithms to identify weak or legacy primitives and ensure security compliance. The tool distinguishes itself by providing a hardening guide with platform-specific configuration instructions and algorithm recommendations to remediate detected vulnerabilities. It also includes a denial of service tester that measures server resilience against CPU exhaustion and concurrent socket connection attacks. Broad cap

    Identifies the specific SSH software version by matching supported algorithms and banner strings against a known database.

    Python
    Voir sur GitHub↗4,218
  • epinna/tplmapAvatar de epinna

    epinna/tplmap

    4,169Voir sur GitHub↗

    tplmap est un outil de sécurité conçu pour la détection et l'exploitation de vulnérabilités d'injection de templates côté serveur (SSTI). Il fonctionne comme un scanner automatisé pour identifier les contextes de moteurs de template vulnérables et fournit un framework pour parvenir à l'exécution de code à distance. L'outil se concentre sur la traduction de requêtes de haut niveau en syntaxe spécifique au moteur pour exécuter des commandes système et contourner les sandboxes d'applications. Il permet en outre l'accès au système de fichiers distant, autorisant les utilisateurs à lire, écrire et transférer des fichiers entre une machine locale et un serveur cible. Les fonctionnalités supplémentaires incluent la possibilité de lancer des serveurs vulnérables locaux pour simuler des environnements défectueux afin de vérifier les payloads. Le projet prend également en charge l'intégration avec des proxies de sécurité web pour automatiser l'injection de payloads de test dans le trafic intercepté.

    Detects and exploits server-side template injection.

    Python
    Voir sur GitHub↗4,169
  • retirejs/retire.jsAvatar de RetireJS

    RetireJS/retire.js

    4,141Voir sur GitHub↗

    Retire.js est un scanner de vulnérabilités JavaScript et un analyseur de sécurité des dépendances. Il identifie les bibliothèques JavaScript obsolètes ou non sécurisées présentant des failles de sécurité connues au sein d'applications web et de projets locaux. L'outil fonctionne comme un utilitaire d'audit de sécurité web pouvant être utilisé lors de tests d'intrusion pour détecter des scripts vulnérables sur des sites web en production. Il prend en charge la génération de nomenclatures logicielles (SBOM) au format CycloneDX pour documenter les dépendances d'un projet. Le système utilise une détection de bibliothèque basée sur des signatures et une correspondance de motifs (pattern-matching) pour comparer les versions identifiées à une base de données de sécurité au format JSON. Les capacités d'analyse incluent l'utilisation de navigateurs headless pour examiner les scripts chargés par des applications en cours d'exécution.

    Detects vulnerable JavaScript libraries.

    JavaScriptbuild-toolchrome-extensionfirefox-extension
    Voir sur GitHub↗4,141
  • knownsec/pocsuite3Avatar de knownsec

    knownsec/pocsuite3

    3,853Voir sur GitHub↗

    Pocsuite3 is a modular vulnerability testing framework designed for the development and execution of security assessment scripts. It provides a comprehensive toolkit for remote vulnerability verification and exploitation, enabling users to automate the identification of security flaws across network targets. The framework is built on an object-oriented scripting architecture that allows for the creation of custom security modules and plugins. It distinguishes itself through a highly extensible design that supports asynchronous task execution for large-scale infrastructure assessments, alongsi

    Provides a modular framework for developing and executing security assessment scripts to identify and exploit vulnerabilities across network targets.

    Pythonpentestingpythonsecurity
    Voir sur GitHub↗3,853
  • cloudsploit/scansAvatar de cloudsploit

    cloudsploit/scans

    3,748Voir sur GitHub↗

    This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr

    Security scanning checks for AWS environments.

    JavaScript
    Voir sur GitHub↗3,748
  • mbechler/marshalsecAvatar de mbechler

    mbechler/marshalsec

    3,691Voir sur GitHub↗

    Marshalsec is a toolkit designed for generating malicious serialized Java objects to achieve remote code execution during the unmarshalling process. It functions as a Java deserialization exploit tool and a framework for triggering Java Naming and Directory Interface lookups to remote servers. The project provides a JNDI redirector service that intercepts lookups and points targets toward a remote codebase. It includes utilities for crafting payloads that force Java applications to download and execute arbitrary classes from a remote URL. The toolset covers security analysis activities inclu

    Generates payloads to trigger remote code execution by forcing Java applications to perform external JNDI lookups.

    Java
    Voir sur GitHub↗3,691
  • lijiejie/githackAvatar de lijiejie

    lijiejie/GitHack

    3,550Voir sur GitHub↗

    GitHack is a .git folder disclosure exploit.

    Exploits .git folder disclosures.

    Python
    Voir sur GitHub↗3,550
  • jaykali/maskphishAvatar de jaykali

    jaykali/maskphish

    3,020Voir sur GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Provides a framework to apply predefined exploits against targets identified through network scanning.

    Shellhackhackinghacking-tool
    Voir sur GitHub↗3,020
  • tuhinshubhra/cmseekAvatar de Tuhinshubhra

    Tuhinshubhra/CMSeeK

    2,543Voir sur GitHub↗

    CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 180 other CMSs

    Suite for CMS detection and exploitation.

    Pythonbruteforcecmscms-bruteforce
    Voir sur GitHub↗2,543
  • joaomatosf/jexbossAvatar de joaomatosf

    joaomatosf/jexboss

    2,512Voir sur GitHub↗

    jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit deserialization flaws to achieve remote code execution on target servers. It functions as a suite of tools for delivering payloads and executing system commands on vulnerable remote applications. The project includes a reverse shell orchestrator to establish and maintain persistent remote command connections from exploited targets back to a listener. It also provides post-exploitation automation for managing remote access and updating software on compromised systems. The fra

    Provides a framework to deliver specialized Java deserialization payloads to achieve remote code execution.

    Pythondeserializationexploitexploiting-vulnerabilities
    Voir sur GitHub↗2,512
  • lijiejie/bbscanAvatar de lijiejie

    lijiejie/BBScan

    2,372Voir sur GitHub↗

    BBScan 是一个高并发的、轻量级的Web漏洞扫描工具。它帮助安全工程师从大量目标中,快速发现,定位可能存在弱点的目标,辅助半自动化测试。

    Batch web vulnerability scanner.

    Python
    Voir sur GitHub↗2,372
  • anouarbensaad/vulnxAvatar de anouarbensaad

    anouarbensaad/vulnx

    2,074Voir sur GitHub↗

    Automated CMS injection and vulnerability scanner.

    Pythonauto-exploiterbotcloudflare-detection
    Voir sur GitHub↗2,074
Préc.123Suivant
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Vulnerability Exploitation Frameworks

Explorer les sous-tags

  • Batch Exploit Execution2 sous-tagsAutomated systems for running multiple exploit payloads against a set of compatible vulnerabilities. **Distinct from Vulnerability Exploitation Frameworks:** Distinct from Vulnerability Exploitation Frameworks: focuses on the batch processing and conditional execution of multiple exploits
  • Router Exploit ExecutionExecution of specific exploit modules against router vulnerabilities for unauthorized access. **Distinct from Vulnerability Exploitation Frameworks:** Focuses on the target device (routers) rather than general CMS or middleware frameworks.
  • Web Application Exploits1 sous-tagSpecialized techniques and payloads for verifying vulnerabilities in web applications to confirm unauthorized access or data extraction. **Distinct from Vulnerability Exploitation Frameworks:** Focuses specifically on web-layer vulnerabilities rather than general CMS or middleware frameworks.