awesome-repositories.com
Blog
MCP
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetServeur MCPÀ proposNotre méthodologiePresse
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

28 dépôts

Awesome GitHub RepositoriesWeb Application Penetration Testing

Systematic identification and validation of security flaws in web services.

Explore 28 awesome GitHub repositories matching security & cryptography · Web Application Penetration Testing. Refine with filters or upvote what's useful.

Awesome Web Application Penetration Testing GitHub Repositories

Trouvez les meilleurs dépôts grâce à l'IA.Nous recherchons les dépôts les plus pertinents grâce à l'IA.
  • swisskyrepo/payloadsallthethingsAvatar de swisskyrepo

    swisskyrepo/PayloadsAllTheThings

    78,434Voir sur GitHub↗

    This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers. It functions as a centralized repository of offensive security techniques, providing a structured collection of exploit payloads, attack vectors, and methodologies for conducting vulnerability assessments and penetration testing. The repository distinguishes itself through a cross-platform payload taxonomy that categorizes exploitation methods by vulnerability type and target environment, enabling rapid lookup during security assessments. It maintains high standards of data i

    Facilitates systematic security audits through a vast index of attack vectors and injection patterns used in web service validation.

    Pythonbountybugbountybypass
    Voir sur GitHub↗78,434
  • usestrix/strixAvatar de usestrix

    usestrix/strix

    20,138Voir sur GitHub↗

    Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno

    Simulates user behavior and intercepts network traffic to discover and exploit vulnerabilities in complex web interfaces.

    Pythonagentsartificial-intelligencecybersecurity
    Voir sur GitHub↗20,138
  • micropoor/micro8Avatar de Micropoor

    Micropoor/Micro8

    18,060Voir sur GitHub↗

    Micro8 is a security auditing knowledge base and penetration testing resource library. It serves as a curated collection of guides and documentation focused on vulnerability assessment. The project provides educational content and study guides for manual source code review, domain escalation, and internal network auditing. It includes a toolkit of reference materials for analyzing network traffic logs and identifying brute-force patterns. The library covers technical domains including web penetration testing and privilege escalation. It organizes these materials through PDF-based knowledge r

    Provides structured techniques and guides for the systematic identification of security flaws in web services.

    micro8micropoorpenetration
    Voir sur GitHub↗18,060
  • ffuf/ffufAvatar de ffuf

    ffuf/ffuf

    15,618Voir sur GitHub↗

    This tool is a command-line utility designed for automated web resource discovery, fuzzing, and application structure mapping. It functions as a security-focused scanner that identifies hidden files, directories, parameters, and virtual hosts by injecting payloads into HTTP requests. By systematically testing how servers handle various inputs, it assists in mapping the architecture of web applications and uncovering potential security vulnerabilities. The tool distinguishes itself through a highly concurrent engine that manages asynchronous request execution and recursive job orchestration. I

    Automates the discovery of hidden files, directories, and parameters on web servers to identify potential vulnerabilities.

    Gofuzzerinfosecpentesting
    Voir sur GitHub↗15,618
  • htr-tech/zphisherAvatar de htr-tech

    htr-tech/zphisher

    15,416Voir sur GitHub↗

    Zphisher is a security testing framework designed for conducting authorized social engineering assessments and penetration testing. It functions as a credential harvesting simulator that enables security professionals to evaluate organizational defenses and user awareness by deploying deceptive login interfaces. The platform automates the creation of realistic web pages through dynamic template rendering and provides tools to mask destination addresses. It integrates reverse proxy tunneling to expose local testing services to the public internet, allowing for remote access during security aud

    Creates realistic web interfaces designed to capture user credentials for authorized security assessments.

    HTMLhtr-techphisherphishing
    Voir sur GitHub↗15,416
  • zaproxy/zaproxyAvatar de zaproxy

    zaproxy/zaproxy

    15,293Voir sur GitHub↗

    OWASP ZAP is a dynamic application security testing tool and intercepting HTTP proxy used to find vulnerabilities in web applications. It functions as a penetration testing framework that enables both automated security scanning and manual security testing of running web services. The tool provides a suite of capabilities for analyzing web applications from the outside in, including the ability to capture and modify traffic between a browser and a target application. It is designed to integrate into DevSecOps pipelines to provide consistent security checks across different environments.

    Enables systematic identification and validation of security flaws in web services through manual probing.

    Java
    Voir sur GitHub↗15,293
  • s0md3v/xsstrikeAvatar de s0md3v

    s0md3v/XSStrike

    14,752Voir sur GitHub↗

    XSStrike is an automated security scanning engine designed for web application discovery, input

    Systematically scanning and fuzzing web application inputs to uncover hidden security flaws and validate the effectiveness of input filters.

    Pythonwaf-detectionxssxss-bruteforce
    Voir sur GitHub↗14,752
  • ethicalhack3r/dvwaAvatar de ethicalhack3r

    ethicalhack3r/DVWA

    13,236Voir sur GitHub↗

    DVWA is a vulnerable web application sandbox and PHP security training environment. It serves as a deployable penetration testing target and an OWASP Top 10 lab designed for practicing exploits and simulating common web security vulnerabilities. The application allows users to adjust security difficulty levels to match their skill level and toggle between different SQL database engines to test how various systems handle injection attacks. It includes a mechanism to disable authentication, enabling automated security tools to interact directly with the environment. The project provides capabi

    Offers a controlled, insecure environment to practice common web exploitation and build penetration testing skills.

    PHP
    Voir sur GitHub↗13,236
  • digininja/dvwaAvatar de digininja

    digininja/DVWA

    13,229Voir sur GitHub↗

    DVWA is a vulnerable web application lab and penetration testing sandbox designed to simulate common security flaws. It serves as a training platform for the OWASP Top 10 security risks and functions as a PHP and MySQL security lab for practicing the identification and exploitation of web vulnerabilities. The project provides a graduated learning experience through configurable security levels that adjust the difficulty of the vulnerabilities. It also supports switching between different database engines to research how various storage systems respond to injection attacks. The application is

    Provides a safe environment to practice the systematic identification and exploitation of web service security flaws.

    PHPdvwahackinginfosec
    Voir sur GitHub↗13,229
  • beefproject/beefAvatar de beefproject

    beefproject/beef

    10,728Voir sur GitHub↗

    BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It functions as a platform for security professionals to evaluate client-side defenses by injecting persistent scripts into web browsers, establishing a bidirectional communication channel for remote command execution and data exfiltration. The framework distinguishes itself through its ability to use compromised browser sessions as proxies to conduct internal network reconnaissance, effectively bypassing perimeter security controls. It utilizes an event-driven control interface and

    Simulates attack vectors in a controlled environment to test the resilience of web-based systems against exploitation.

    JavaScript
    Voir sur GitHub↗10,728
  • owasp/wstgAvatar de OWASP

    OWASP/wstg

    9,473Voir sur GitHub↗

    The Web Application Security Testing Guide is an open-source security testing standard and comprehensive framework of procedures for identifying vulnerabilities in web applications and services. It serves as a vulnerability assessment methodology and a web API security audit framework, providing a structured approach for conducting consistent and thorough security audits of web-based software. The project utilizes a methodology-based audit framework and checklist-driven workflows to ensure repeatable discovery and exploitation steps. It organizes security tests through taxonomy-based vulnerab

    Offers a standardized approach for identifying and validating security flaws in web services.

    application-securityappsecbest-practices
    Voir sur GitHub↗9,473
  • fuzzdb-project/fuzzdbAvatar de fuzzdb-project

    fuzzdb-project/fuzzdb

    8,819Voir sur GitHub↗

    fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a fuzzing payload dictionary, a resource discovery wordlist, and a fault injection dataset containing corrupted Unicode, null bytes, and escape codes to trigger application crashes and logic errors. The project includes a security filter bypass list featuring polyglots and encoded strings to evade web application firewalls and input validation filters. It also provides a comprehensive web application penetration testing dataset specifically for identifying flaws such as cross-s

    Supplies a comprehensive dataset of payloads for identifying common security flaws in web services.

    PHP
    Voir sur GitHub↗8,819
  • thekingofduck/fuzzdictsAvatar de TheKingOfDuck

    TheKingOfDuck/fuzzDicts

    8,355Voir sur GitHub↗

    fuzzDicts is a repository of curated wordlists and dictionaries designed for web application fuzzing. It provides collections of strings and payloads used to discover hidden files, subdomains, and security vulnerabilities. The project includes specialized libraries for different security testing vectors, such as dictionaries for common request and cookie parameters, lists of common subdomain prefixes, and collections of passwords and default vendor credentials for brute-force testing. It also maintains a security payload library containing character sequences used to identify flaws like SQL i

    Provides the data necessary for identifying hidden or undocumented parameters in web applications.

    Pythondirectoryfuzz-testingfuzzer
    Voir sur GitHub↗8,355
  • kathanp19/howtohuntAvatar de KathanP19

    KathanP19/HowToHunt

    7,146Voir sur GitHub↗

    HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It provides a research methodology for organizing security testing procedures and validating application behaviors against known vulnerability patterns. The project features a curated library of security flaws and reconnaissance techniques. It organizes security testing into modular playbooks, checklists, and categorical vulnerability mappings to align specific exploitation techniques with target weaknesses. The repository covers a systematic sequence of information gathering task

    Provides a structured guide for the systematic identification and validation of security flaws in web services.

    bugbountybugbountytipsbughunting-methodology
    Voir sur GitHub↗7,146
  • lascc/hacktoolsAvatar de LasCC

    LasCC/HackTools

    6,742Voir sur GitHub↗

    HackTools is a browser extension pentesting toolkit designed for offensive security professionals. It serves as a centralized collection of tools for generating payloads, managing penetration testing workflows, and accessing security reference materials within a web-based interface. The project provides specialized utilities for generating attack strings for XSS, SQL injection, and reverse shells to identify and exploit web vulnerabilities. It includes a data encoding and hashing utility to convert information between various formats for the purpose of bypassing security filters or verifying

    Provides tools for generating payloads to identify and validate vulnerabilities in web applications.

    TypeScriptbug-bountycheatsheetchrome-extension
    Voir sur GitHub↗6,742
  • s0md3v/arjunAvatar de s0md3v

    s0md3v/Arjun

    6,086Voir sur GitHub↗

    Arjun is an HTTP parameter discovery tool that identifies valid parameters on web endpoints by testing large dictionaries of parameter names against target URLs. It systematically probes endpoints using GET, POST, JSON, and XML request formats to find which parameters the server accepts, and can detect parameters whose values appear reflected in the response body. The tool distinguishes itself through its multi-method scanning approach, passive parameter collection from public archives like OTX and CommonCrawl, and its ability to detect value-sensitive parameters that only trigger a response

    Identifies hidden or undocumented parameters in web applications to uncover potential attack surfaces.

    Pythonapi-fuzzerapi-fuzzingapi-testing
    Voir sur GitHub↗6,086
  • audi-1/sqli-labsAvatar de Audi-1

    Audi-1/sqli-labs

    5,791Voir sur GitHub↗

    sqli-labs est une collection d'applications web intentionnellement vulnérables et d'environnements sandbox conçus pour s'entraîner à l'identification et à l'exploitation de vulnérabilités par injection SQL. Il sert de laboratoire d'éducation en cybersécurité où les utilisateurs peuvent expérimenter des exploits de base de données dans un cadre contrôlé. L'environnement fournit des modules spécialisés pour tester un large éventail de vecteurs d'attaque, y compris les injections basées sur les erreurs, les injections aveugles booléennes et les injections basées sur le temps. Il couvre spécifiquement des techniques avancées telles que les injections de second ordre, les requêtes empilées et les attaques ciblant les en-têtes HTTP. Le projet inclut également des exercices axés sur l'évasion des filtres de sécurité et le contournement des pare-feu d'applications web via des techniques comme le retrait de commentaires et l'inadéquation d'impédance. Ces scénarios permettent la simulation de tests d'intrusion réels et d'audits de sécurité de bases de données.

    Simulates real-world attack scenarios, including second-order and stacked queries, for web application security assessment.

    PHP
    Voir sur GitHub↗5,791
  • lylemi/learn-web-hackingAvatar de LyleMi

    LyleMi/Learn-Web-Hacking

    5,414Voir sur GitHub↗

    Learn-Web-Hacking est un guide d'étude structuré sur la sécurité web et une base de connaissances en tests d'intrusion. Il propose une collection de notes de recherche axées sur l'identification et l'exploitation de vulnérabilités dans les applications web et les protocoles réseau. Le projet inclut des frameworks spécialisés pour évaluer les risques de sécurité dans les grands modèles de langage (LLM) afin de prévenir les injections de prompts, ainsi que des guides pour durcir l'infrastructure cloud-native, incluant les standards de conteneurs et les outils d'orchestration. Il couvre également l'analyse des standards d'identité et des protocoles d'authentification. Le matériel couvre un large éventail de capacités de sécurité, incluant l'analyse de protocoles réseau, la collecte d'informations pour la cartographie de la surface d'attaque, et les tests d'intrusion sur réseaux internes impliquant des mouvements latéraux et la persistance. Il détaille en outre des stratégies défensives telles que les architectures zero-trust et la détection d'intrusion.

    Offers a systematic approach to identifying and validating security flaws in web services.

    Pythonhackingpenetration-testingpentesting
    Voir sur GitHub↗5,414
  • hahwul/dalfoxAvatar de hahwul

    hahwul/dalfox

    4,846Voir sur GitHub↗

    Dalfox is an automated web application security tool specifically designed for discovering and verifying cross-site scripting vulnerabilities. It functions as an XSS vulnerability scanner that analyzes HTTP parameters and DOM structures to identify reflected, stored, and blind injection points. The project distinguishes itself by providing a Model Context Protocol server and a REST API, allowing artificial intelligence agents and remote interfaces to trigger and manage security scans programmatically. It utilizes a payload mutation engine and fingerprinting strategies to execute WAF evasion t

    Uncovers undocumented parameters not present in the URL by analyzing DOM structures and framework patterns.

    Gobugbountybugbounty-toolcicd-pipeline
    Voir sur GitHub↗4,846
  • antswordproject/antswordAvatar de AntSwordProject

    AntSwordProject/antSword

    4,620Voir sur GitHub↗

    AntSword est un gestionnaire web multiplateforme et un framework de test de pénétration conçu pour l'administration centralisée de multiples environnements de sites web distants. Il fonctionne comme un outil d'administration de site web distant et un outil de gestion de web shell, permettant aux utilisateurs d'organiser et de contrôler divers serveurs web depuis une interface unique. Le projet fournit une boîte à outils pour les chercheurs en sécurité afin d'effectuer des audits de sécurité autorisés et d'identifier les vulnérabilités. Il prend en charge les tests de pénétration web et les workflows de recherche en sécurité pour analyser le comportement des applications web et découvrir des exploits potentiels. Le système couvre de larges capacités en administration de sites web distants et en gestion web multiplateforme, permettant l'exécution de tâches administratives et de contrôles de sécurité sur différents systèmes d'exploitation et plateformes d'hébergement.

    Provides a comprehensive framework for systematic identification and validation of security flaws in web services.

    JavaScript
    Voir sur GitHub↗4,620
Préc.12Suivant
  1. Home
  2. Security & Cryptography
  3. Vulnerability Assessment and Testing
  4. Security Testing and Auditing
  5. Security Testing
  6. Web Application Penetration Testing

Explorer les sous-tags

  • Hidden Parameter DiscoveryIdentifying hidden or undocumented parameters in web applications to uncover potential attack surfaces or misconfigurations. **Distinct from Web Application Penetration Testing:** Distinct from Web Application Penetration Testing: focuses specifically on discovering undocumented parameters rather than general vulnerability identification.
  • Phishing Page GeneratorsUtilities for creating realistic login interfaces to simulate credential harvesting attacks. **Distinct from Web Application Penetration Testing:** Distinct from Web Application Penetration Testing: focuses on the creation of deceptive interfaces rather than general vulnerability scanning.