awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to ztgrace/changeme

Projects sharing features with Changeme

30 open-source projects similar to ztgrace/changeme, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • ihebski/defaultcreds-cheat-sheetihebski avatar

    ihebski/DefaultCreds-cheat-sheet

    6,409View on GitHub↗

    DefaultCreds-cheat-sheet is a searchable reference database of default usernames and passwords for thousands of hardware and software products, designed for use during security assessments. It functions as a curated directory that maps vendor products to their known factory-set login credentials, enabling rapid lookup during penetration testing and security preparation workflows. The tool is delivered as a single-file client application with no backend dependencies, serving static content from any web server or local file system for offline use. It stores credential mappings in a flat JSON da

    Pythonblueteamblueteam-toolsblueteaming
    View on GitHub↗6,409
  • yogeshojha/rengineyogeshojha avatar

    yogeshojha/rengine

    8,472View on GitHub↗

    Rengine is an automated reconnaissance framework and vulnerability management platform designed for attack surface monitoring. It functions as a centralized hub for discovering subdomains and open ports, gathering open-source intelligence, and tracking security flaws across target networks. The system integrates large language models to analyze reconnaissance data and generate vulnerability descriptions and insights. It distinguishes itself through a plugin-based tool integration that wraps external security scanning binaries and a target mapping system that tracks changes to assets over time

    HTMLbug-bountybugbountyhacking
    View on GitHub↗8,472
  • sensepost/gowitnesssensepost avatar

    sensepost/gowitness

    4,174View on GitHub↗

    Gowitness is a system for rendering web interfaces at scale to capture visual snapshots, HTTP metadata, and network scan results. It functions as a headless browser screenshot tool and a web surface mapper used to identify and visually document the attack surface of network ranges and URL lists. The tool includes a screenshot gallery server that provides a web-based interface for browsing, filtering, and managing a database of captures. It specifically serves as an Nmap target visualizer, parsing network scan results to automatically capture screenshots of discovered web services. Capabiliti

    Gochromechrome-headlessfingerprint
    View on GitHub↗4,174

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • kathanp19/howtohuntKathanP19 avatar

    KathanP19/HowToHunt

    7,146View on GitHub↗

    HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It provides a research methodology for organizing security testing procedures and validating application behaviors against known vulnerability patterns. The project features a curated library of security flaws and reconnaissance techniques. It organizes security testing into modular playbooks, checklists, and categorical vulnerability mappings to align specific exploitation techniques with target weaknesses. The repository covers a systematic sequence of information gathering task

    bugbountybugbountytipsbughunting-methodology
    View on GitHub↗7,146
  • aipengjie/sensitivefilescanaipengjie avatar

    aipengjie/sensitivefilescan

    183View on GitHub↗

    this tools can be searched web leak files

    Python
    View on GitHub↗183
  • archerysec/archerysecarcherysec avatar

    archerysec/archerysec

    2,461View on GitHub↗

    ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

    JavaScript
    View on GitHub↗2,461
  • 1n3/brutex1N3 avatar

    1N3/BruteX

    2,265View on GitHub↗
    Shellbrutebrute-forcebruteforce
    View on GitHub↗2,265
  • bc-security/empireBC-SECURITY avatar

    BC-SECURITY/Empire

    5,045View on GitHub↗

    Empire is a post-exploitation command-and-control (C2) framework designed for red team operations. It deploys and manages agents written in PowerShell, Python, C#, Go, and C across Windows, Linux, and macOS, using encrypted communication channels over HTTP, HTTPS, and SMB. The framework executes over 400 built-in modules for reconnaissance, privilege escalation, credential theft, and lateral movement, and provides a modular engine for authoring custom attack modules. What sets Empire apart is its multi-language agent deployment system, which allows operators to choose implants that suit each

    PowerShellc2empirehacktoberfest
    View on GitHub↗5,045
  • 3xp10it/xcdn3xp10it avatar

    3xp10it/xcdn

    337View on GitHub↗

    尝试找出cdn背后的真实ip

    Python
    View on GitHub↗337
  • bcoles/kasldbcoles avatar

    bcoles/kasld

    494View on GitHub↗

    KASLD derandomises the Linux kernel's virtual and physical memory layout as an unprivileged local user.

    C
    View on GitHub↗494
  • binaryanalysisplatform/qiraBinaryAnalysisPlatform avatar

    BinaryAnalysisPlatform/qira

    4,071View on GitHub↗

    Qira is a binary analysis platform and execution tracer that records every instruction and data access during program execution for interactive playback and debugging. It functions as a runtime analysis environment that uses QEMU to trace execution and inspect memory and register states. The system provides a binary static analysis tool that maps program structure and annotates instructions based on captured runtime data. It includes a runtime memory analyzer to monitor reads and writes to specific addresses and an interactive debugger for navigating execution timelines. The platform covers

    C
    View on GitHub↗4,071
  • bishopfox/sliverBishopFox avatar

    BishopFox/sliver

    10,707View on GitHub↗

    Sliver is a command and control framework designed for adversary emulation and security assessment operations. It provides a centralized platform for managing remote systems, enabling security professionals to coordinate multi-operator sessions and maintain persistent, secure communication channels across diverse network environments. The framework distinguishes itself through its focus on stealth and infrastructure flexibility. It utilizes dynamic payload obfuscation to generate unique binaries and supports in-memory execution to minimize disk artifacts. Communication is secured through mutu

    Goadversarial-attacksadversary-simulationc2
    View on GitHub↗10,707
  • bjrjk/cve-2022-4262B

    bjrjk/CVE-2022-4262

    0View on GitHub↗
    View on GitHub↗0
  • blackye/webdirdigblackye avatar

    blackye/webdirdig

    129View on GitHub↗

    webdirdig web敏感目录\信息泄漏扫描脚本

    Python
    View on GitHub↗129
  • boy-hack/w11scanboy-hack avatar

    boy-hack/w11scan

    472View on GitHub↗

    w11scan是一款分布式的WEB指纹识别系统(包括CMS识别、js框架、组件容器、代码语言、WAF等等),管理员可以在WEB端新增/修改指纹,建立批量的扫描任务,并且支持多种搜索语法。

    CSS
    View on GitHub↗472
  • b1gcat/darkeyeB

    b1gcat/DarkEye

    0View on GitHub↗
    View on GitHub↗0
  • boy-hack/gwhatwebboy-hack avatar

    boy-hack/gwhatweb

    213View on GitHub↗

    CMS识别 python gevent实现

    Python
    View on GitHub↗213
  • boy-hack/w8fuckcdnboy-hack avatar

    boy-hack/w8fuckcdn

    784View on GitHub↗

    Get website IP address by scanning the entire net 通过扫描全网绕过CDN获取网站IP地址

    Python
    View on GitHub↗784
  • brannondorsey/dns-rebind-toolkitbrannondorsey avatar

    brannondorsey/dns-rebind-toolkit

    501View on GitHub↗

    A front-end JavaScript toolkit for creating DNS rebinding attacks.

    JavaScript
    View on GitHub↗501
  • brannondorsey/whonowbrannondorsey avatar

    brannondorsey/whonow

    661View on GitHub↗

    A "malicious" DNS server for executing DNS Rebinding attacks on the fly (public instance running on rebind.network:53)

    JavaScript
    View on GitHub↗661
  • bsauce/kernel-exploit-factorybsauce avatar

    bsauce/kernel-exploit-factory

    1,293View on GitHub↗

    Linux kernel CVE exploit analysis report and relative debug environment. You don't need to compile Linux kernel and configure your environment anymore.

    C
    View on GitHub↗1,293
  • byt3bl33d3r/crackmapexecbyt3bl33d3r avatar

    byt3bl33d3r/CrackMapExec

    9,144View on GitHub↗

    CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security postures across large IP ranges. It functions as a multi-protocol security scanner and network protocol auditor used to identify vulnerabilities and misconfigurations. The tool provides capabilities for Active Directory auditing to enumerate users and permissions, as well as post-exploitation enumeration to gather system metadata and discover lateral movement paths. It includes a framework for credential spraying and harvesting across various network services. The system utilize

    Python
    View on GitHub↗9,144
  • byt3bl33d3r/witnessmebyt3bl33d3r avatar

    byt3bl33d3r/WitnessMe

    763View on GitHub↗

    Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier.

    Python
    View on GitHub↗763
  • chichou/grab.jschichou avatar

    chichou/grab.js

    50View on GitHub↗

    simple TCP banner grabbing with node.js

    Shell
    View on GitHub↗50
  • cloudtracer/pasktocloudtracer avatar

    cloudtracer/paskto

    150View on GitHub↗

    Paskto will passively scan the web using the Common Crawl internet index either by downloading the indexes on request or parsing data from your local system. URLs are then processed through Nikto and known URL lists to identify interesting content. Hash signatures are also used to identify known…

    JavaScript
    View on GitHub↗150
  • cn33liz/p0wnedshellCn33liz avatar

    Cn33liz/p0wnedShell

    1,549View on GitHub↗

    PowerShell Runspace Post Exploitation Toolkit

    C#
    View on GitHub↗1,549
  • cobbr/covenantcobbr avatar

    cobbr/Covenant

    4,699View on GitHub↗

    Covenant is a .NET-based command and control framework designed for red team operations and adversary simulation. It serves as a collaborative platform for coordinating security assessments, managing remote implants, and executing tasks on compromised systems through a centralized server. The project is distinguished by its dynamic payload generator, which compiles and obfuscates executable binaries and scripts on the fly to bypass detection. It further separates itself through a collaborative environment that allows multiple authenticated operators to share a synchronized state, track operat

    C#
    View on GitHub↗4,699
  • deibit/cansinadeibit avatar

    deibit/cansina

    899View on GitHub↗

    Web Content Discovery Tool

    Pythonpentestingpythonsecurity-audit
    View on GitHub↗899
  • dzonerzy/gowaptdzonerzy avatar

    dzonerzy/goWAPT

    347View on GitHub↗

    GOWAPT is the younger brother of wfuzz a swiss army knife of WAPT, it allow pentester to perform huge activity with no stress at all, just configure it and it's just a matter of clicks.

    Go
    View on GitHub↗347
  • blasty/lexmarkblasty avatar

    blasty/lexmark

    207View on GitHub↗

    This repository contains all the work related to Lexmark printers I've released to the public. Most of you are probably here for the firmware decryption utilities; check the tools folder.

    Python
    View on GitHub↗207