awesome-repositories.com
Blog
MCP
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetServeur MCPÀ proposNotre méthodologiePresse
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

15 dépôts

Awesome GitHub RepositoriesPenetration Testing Frameworks

Software environments used to simulate cyber attacks for identifying system vulnerabilities.

Explore 15 awesome GitHub repositories matching security & cryptography · Penetration Testing Frameworks. Refine with filters or upvote what's useful.

Awesome Penetration Testing Frameworks GitHub Repositories

Trouvez les meilleurs dépôts grâce à l'IA.Nous recherchons les dépôts les plus pertinents grâce à l'IA.
  • z4nzu/hackingtoolAvatar de Z4nzu

    Z4nzu/hackingtool

    77,515Voir sur GitHub↗

    This project is a comprehensive cybersecurity tool collection designed to support security research, penetration testing, and vulnerability assessment. It functions as a unified penetration testing suite, providing a centralized environment where professionals can access a wide range of offensive security utilities to identify system weaknesses and study attack vectors. The platform distinguishes itself through a modular architecture that aggregates disparate security scripts into a single, hierarchical command-line interface. It simplifies the management of these utilities by integrating ext

    Simulates cyber attacks through a collection of integrated frameworks to identify potential system weaknesses.

    Pythonallinonehackingtoolbesthackingtoolctf-tools
    Voir sur GitHub↗77,515
  • usestrix/strixAvatar de usestrix

    usestrix/strix

    20,138Voir sur GitHub↗

    Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno

    Coordinates multi-agent workflows, browser automation, and traffic analysis to automate penetration testing and vulnerability validation.

    Pythonagentsartificial-intelligencecybersecurity
    Voir sur GitHub↗20,138
  • ethicalhack3r/dvwaAvatar de ethicalhack3r

    ethicalhack3r/DVWA

    13,236Voir sur GitHub↗

    DVWA is a vulnerable web application sandbox and PHP security training environment. It serves as a deployable penetration testing target and an OWASP Top 10 lab designed for practicing exploits and simulating common web security vulnerabilities. The application allows users to adjust security difficulty levels to match their skill level and toggle between different SQL database engines to test how various systems handle injection attacks. It includes a mechanism to disable authentication, enabling automated security tools to interact directly with the environment. The project provides capabi

    Creates a safe, isolated environment for testing security tools and manual attack methods against known flaws.

    PHP
    Voir sur GitHub↗13,236
  • manisso/fsocietyAvatar de Manisso

    Manisso/fsociety

    12,136Voir sur GitHub↗

    fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits. It functions as a wrapper that integrates external security binaries into a unified, menu-driven interface, providing a centralized system for command-line parameter mapping and execution. The project distinguishes itself by organizing specialized utilities into domain-specific collections for structured navigation. It automates the transition between different phases of an audit by chaining reconnaissance and exploitation tools through sequential workflow automation. The fram

    Conducting a full security audit from initial reconnaissance and vulnerability scanning to exploiting services and maintaining system access.

    Pythonbrute-force-attacksdesktopexploitation
    Voir sur GitHub↗12,136
  • empireproject/empireAvatar de EmpireProject

    EmpireProject/Empire

    7,813Voir sur GitHub↗

    Empire is a command and control framework and post-exploitation toolkit used for network penetration testing. It serves as a centralized platform for coordinating remote agent communication and automating the delivery of security testing payloads to target systems. The project provides a suite of modules for host reconnaissance, lateral movement, and credential harvesting across corporate environments. It functions as a remote administration tool to maintain persistence and execute commands on compromised hosts. The framework incorporates capabilities for agent orchestration and the executio

    Serves as a comprehensive software environment for simulating cyber attacks to identify system vulnerabilities.

    PowerShell
    Voir sur GitHub↗7,813
  • fireeye/commando-vmAvatar de fireeye

    fireeye/commando-vm

    7,668Voir sur GitHub↗

    Commando-VM is a Windows penetration testing distribution and offensive security toolkit. It provides a specialized virtual machine environment loaded with a curated suite of security auditing and exploitation tools designed for red teaming operations. The project facilitates the creation of red team infrastructure and security audit environments. It focuses on windows security auditing and penetration testing to help simulate adversary behavior and identify exploitable security flaws. The environment is established through script-based provisioning and modular toolset deployment. This proce

    Ships a pre-configured environment for simulating cyber attacks to identify vulnerabilities within Windows systems.

    PowerShell
    Voir sur GitHub↗7,668
  • owasp/nettackerAvatar de OWASP

    OWASP/Nettacker

    5,258Voir sur GitHub↗

    Nettacker est un framework de test d'intrusion automatisé conçu pour orchestrer la reconnaissance, le scan de ports et la détection de vulnérabilités. Il fonctionne comme un outil de reconnaissance réseau et un scanner de vulnérabilités qui identifie les ports ouverts, empreinte les services et vérifie les systèmes par rapport à des bases de données de failles de sécurité connues. Le framework se distingue en combinant un crawler d'applications web pour découvrir des chemins cachés via le fuzzing, avec un système de gestion des vulnérabilités qui persiste les résultats des scans dans une base de données pour suivre les évaluations historiques. Il inclut également des capacités spécialisées pour l'énumération de sous-domaines, le brute forcing d'identifiants et la possibilité d'acheminer le trafic via des proxys pour l'anonymisation. Le système couvre une large surface de capacités de sécurité, incluant la découverte d'actifs réseau, l'audit de services multi-protocoles et l'audit de configuration. Il prend en charge le scan multi-cibles sur des plages IP et des blocs CIDR, et fournit des outils pour générer des rapports de sécurité dans plusieurs formats. Un contrôle programmatique est disponible via une interface REST, permettant au framework d'être intégré dans des pipelines de sécurité et des flux d'automatisation.

    Provides a complete software environment to automate the discovery and exploitation of network security weaknesses.

    Pythonautomationbruteforcecve
    Voir sur GitHub↗5,258
  • aquasecurity/kube-hunterAvatar de aquasecurity

    aquasecurity/kube-hunter

    5,064Voir sur GitHub↗

    Kube-hunter est un scanner de sécurité et un chasseur de vulnérabilités pour les clusters Kubernetes. Il opère comme un outil de pénétration cloud-native conçu pour identifier les faiblesses de sécurité, les mauvaises configurations d'infrastructure et les lacunes exploitables en simulant des techniques d'attaquants. L'outil se distingue par un moteur de scan en mode dual qui exécute à la fois des sondes externes distantes et des scans réseau internes. Il dispose d'une usurpation d'identité, lui permettant d'utiliser des jetons de compte de service et des identités de pod pour simuler l'accès de sécurité à partir de rôles de cluster spécifiques et déterminer le rayon d'explosion potentiel d'un compromis de conteneur. Le projet couvre une large surface de capacités d'évaluation de sécurité, incluant le scan de vulnérabilités de cluster, la cartographie de topologie réseau interne et la vérification de conformité. Il peut détecter des secrets exposés, analyser des templates d'infrastructure pour des mauvaises configurations et effectuer des tentatives d'exploitation actives pour vérifier que les vulnérabilités découvertes sont exploitables. L'application est packagée sous forme d'exécutable autonome pour supprimer les dépendances runtime pendant le déploiement.

    Simulates attacker techniques and pod compromises to identify lateral movement paths and exploitability.

    Python
    Voir sur GitHub↗5,064
  • antswordproject/antswordAvatar de AntSwordProject

    AntSwordProject/antSword

    4,620Voir sur GitHub↗

    AntSword est un gestionnaire web multiplateforme et un framework de test de pénétration conçu pour l'administration centralisée de multiples environnements de sites web distants. Il fonctionne comme un outil d'administration de site web distant et un outil de gestion de web shell, permettant aux utilisateurs d'organiser et de contrôler divers serveurs web depuis une interface unique. Le projet fournit une boîte à outils pour les chercheurs en sécurité afin d'effectuer des audits de sécurité autorisés et d'identifier les vulnérabilités. Il prend en charge les tests de pénétration web et les workflows de recherche en sécurité pour analyser le comportement des applications web et découvrir des exploits potentiels. Le système couvre de larges capacités en administration de sites web distants et en gestion web multiplateforme, permettant l'exécution de tâches administratives et de contrôles de sécurité sur différents systèmes d'exploitation et plateformes d'hébergement.

    Serves as a software environment for simulating attacks to identify vulnerabilities during authorized audits.

    JavaScript
    Voir sur GitHub↗4,620
  • htr-tech/nexphisherAvatar de htr-tech

    htr-tech/nexphisher

    3,829Voir sur GitHub↗

    Nexphisher is a command-line security utility and social engineering simulation framework designed for capturing credentials during authorized security audits. It functions as a tool for credential harvesting and penetration testing to evaluate organizational resilience against phishing attacks. The system orchestrates the deployment of realistic login pages and integrates network tunneling to expose local web servers to the public internet. This allows for remote security testing and the execution of controlled social engineering simulations. The framework provides capabilities for template

    Provides a framework for conducting authorized security audits by deploying temporary deceptive web interfaces.

    Shellhtr-techlinuxphisher
    Voir sur GitHub↗3,829
  • tuhinshubhra/red_hawkAvatar de Tuhinshubhra

    Tuhinshubhra/RED_HAWK

    3,695Voir sur GitHub↗

    RED_HAWK is a penetration testing framework and reconnaissance suite designed for information gathering and vulnerability assessment. It provides a toolkit for infrastructure reconnaissance, technology stack detection, automated web spidering, and security scanning. The project distinguishes itself through a multi-stage reconnaissance pipeline that maps attack surfaces. This includes DNS-based infrastructure mapping to resolve network layouts and pattern-based detection to identify specific content management systems and server stacks. The system covers a broad range of capabilities includin

    Provides a comprehensive software environment for simulating attacks and identifying system vulnerabilities.

    PHPadmin-scannerbackups-findercloudflare-detection
    Voir sur GitHub↗3,695
  • securethisshit/winpwnAvatar de SecureThisShit

    SecureThisShit/WinPwn

    3,673Voir sur GitHub↗

    WinPwn is a Windows penetration testing framework designed for conducting internal security assessments and privilege escalation. It functions as a suite for Active Directory security auditing, credential extraction, and the execution of privilege escalation scripts. The toolset enables the automation of SMB relay attacks to intercept and reuse authentication hashes. It provides specialized capabilities for retrieving passwords and hashes from system memory, registries, and browsers using obfuscated techniques to avoid detection. The framework covers broad capability areas including domain a

    Provides a comprehensive framework for conducting internal security assessments and privilege escalation on Windows environments.

    PowerShell
    Voir sur GitHub↗3,673
  • samsar4/ethical-hacking-labsAvatar de Samsar4

    Samsar4/Ethical-Hacking-Labs

    3,397Voir sur GitHub↗

    Ethical-Hacking-Labs is a comprehensive cybersecurity training curriculum and lab suite designed for learning penetration testing, network analysis, and offensive security techniques. It provides a structured environment for practicing the full attack lifecycle, from initial reconnaissance and scanning to exploitation and post-compromise analysis. The project provides instructional materials and guided exercises that cover specific technical domains, including open source intelligence research and network security courseware. It includes a practical workbook for identifying system vulnerabili

    Provides a comprehensive framework for simulating cyberattacks across the full lifecycle from scanning to covering tracks.

    ethical-hacking-labshackinglinux
    Voir sur GitHub↗3,397
  • seemoo-lab/nexmonAvatar de seemoo-lab

    seemoo-lab/nexmon

    2,750Voir sur GitHub↗

    Nexmon is a suite of operational tools designed for firmware patching, ROM extraction, frame injection, and enabling monitor mode on wireless hardware. It provides utilities to modify wireless chip firmware to unlock low-level hardware capabilities not supported by official drivers. The project enables the activation of monitor mode for capturing raw network packets with radiotap headers and allows for the transmission of custom-crafted wireless frames. It includes tools for dumping the read-only memory of wireless chips to facilitate reverse engineering and analysis of hardware behavior. Th

    Enables the injection of custom wireless frames to test network security vulnerabilities.

    Cbroadcomfirmwareframework
    Voir sur GitHub↗2,750
  • sofianehamlaoui/lockdoor-frameworkAvatar de SofianeHamlaoui

    SofianeHamlaoui/Lockdoor-Framework

    1,540Voir sur GitHub↗

    Lockdoor-Framework est une suite de tests d'intrusion modulaire conçue pour faciliter les évaluations de sécurité complètes via une interface en ligne de commande centralisée. Il fonctionne comme une plateforme intégrée pour la reconnaissance, l'analyse de vulnérabilité et l'exploitation de systèmes cibles, fournissant un environnement unifié pour gérer des flux de travail de sécurité complexes. Le framework se distingue par une architecture de plugin modulaire qui permet l'extension des capacités de base sans modifier la base de code sous-jacente. Il intègre un pipeline de reconnaissance automatisé pour cartographier les surfaces d'attaque et exploite l'intégration d'outils externes pour envelopper des utilitaires standard de l'industrie, permettant aux utilisateurs d'exécuter diverses opérations de sécurité au sein d'un système unique et cohérent. L'outil couvre une large surface de capacité, y compris l'analyse binaire et l'ingénierie inverse pour examiner les logiciels compilés, ainsi que l'analyse automatisée d'applications web pour identifier les failles d'injection et les erreurs de configuration. Il prend également en charge les tests au niveau du système, tels que l'élévation de privilèges et l'audit de mots de passe, et inclut un moteur dédié pour agréger les résultats dans des rapports d'évaluation de sécurité standardisés.

    Provides a modular suite for executing comprehensive security assessments, reconnaissance, and exploitation workflows within a unified command-line environment.

    Pythonblackarch-packagesblueteamingcyber-security
    Voir sur GitHub↗1,540
  1. Home
  2. Security & Cryptography
  3. Vulnerability Assessment and Testing
  4. Penetration Testing Frameworks