awesome-repositories.com
Blog
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

Open Source Penetration Testing Tools

Ranking updated Jul 1, 2026

For a security framework for penetration testing operations, the strongest matches are z4nzu/hackingtool (z4nzu/hackingtool is a unified, modular penetration testing suite that), rapid7/metasploit-framework (Metasploit Framework is the leading open-source penetration testing platform) and infinition/bjorn (Bjorn is a modular penetration testing framework that automates). greydgl/pentestgpt and shadow1ng/fscan round out the shortlist. Each is ranked by relevance to your query, popularity and recent activity.

Discover professional-grade security assessment utilities for vulnerability scanning, network exploitation, and comprehensive penetration testing workflows.

Open Source Penetration Testing Tools

Find the best repos with AI.We'll search the best matching repositories with AI.
  • z4nzu/hackingtoolZ4nzu avatar

    Z4nzu/hackingtool

    77,515View on GitHub↗

    This project is a comprehensive cybersecurity tool collection designed to support security research, penetration testing, and vulnerability assessment. It functions as a unified penetration testing suite, providing a centralized environment where professionals can access a wide range of offensive security utilities to identify system weaknesses and study attack vectors. The platform distinguishes itself through a modular architecture that aggregates disparate security scripts into a single, hierarchical command-line interface. It simplifies the management of these utilities by integrating ext

    z4nzu/hackingtool is a unified, modular penetration testing suite that aggregates a broad collection of offensive security utilities covering reconnaissance, exploitation, web and wireless testing, and credential harvesting, all accessible from a single command-line interface.

    PythonExploit FrameworksPost-Exploitation ToolsWireless Attack Tools
    View on GitHub↗77,515
  • rapid7/metasploit-frameworkrapid7 avatar

    rapid7/metasploit-framework

    38,415View on GitHub↗

    The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures. The platform distinguishes itself through a modular architecture that supports reflective payload injection, allowing for the execution of code directly in memory without writing to disk. It utilizes an asynchronous event loop to

    Metasploit Framework is the leading open-source penetration testing platform, providing a modular exploitation framework, auxiliary scanning modules, post-exploitation capabilities, and reporting features — it directly fulfills the search for a comprehensive penetration testing toolkit.

    RubyExploit FrameworksExploitation FrameworksExploitation Frameworks
    View on GitHub↗38,415
  • infinition/bjorninfinition avatar

    infinition/Bjorn

    5,656View on GitHub↗

    Bjorn is a penetration testing framework that automates network scanning, credential brute-forcing, vulnerability assessment, and data exfiltration, all coordinated through an event-driven task pipeline and controlled via a web-based dashboard. Its modular plugin architecture allows independent security modules to be loaded and chained together, with an asynchronous network scanner discovering live hosts and open ports without blocking the main execution flow. The framework distinguishes itself by integrating a credential brute-force engine that systematically attempts login combinations agai

    Bjorn is a modular penetration testing framework that automates network scanning, credential brute-forcing, vulnerability assessment, and data exfiltration through an event-driven pipeline and web dashboard, covering the core reconnaissance, exploitation, and reporting needs of this search.

    PythonPost-Exploitation FrameworksVulnerability ScanningNetwork Scanning Tools
    View on GitHub↗5,656
  • greydgl/pentestgptGreyDGL avatar

    GreyDGL/PentestGPT

    11,697View on GitHub↗

    PentestGPT is an autonomous security testing framework that leverages large language models to plan, execute, and coordinate end-to-end penetration testing engagements. By functioning as an autonomous agent, the system automates the entire testing lifecycle, from initial reconnaissance and vulnerability analysis to the generation of custom exploits and the execution of post-exploitation tasks. The platform distinguishes itself through a multi-agent orchestration system that coordinates specialized AI agents to collaborate on complex, multi-stage attack chains. It integrates multimodal context

    PentestGPT is an autonomous penetration testing framework that uses LLMs to plan and execute the full testing lifecycle, including reconnaissance, vulnerability analysis, exploitation, and post-exploitation, making it a comprehensive and innovative toolkit for this search.

    PythonExploit FrameworksExploitation FrameworksPost-Exploitation Tools
    View on GitHub↗11,697
  • shadow1ng/fscanshadow1ng avatar

    shadow1ng/fscan

    13,421View on GitHub↗

    Fscan is an automated penetration testing tool designed for internal network reconnaissance and vulnerability assessment. It functions as a comprehensive security framework that maps network infrastructure, identifies active hosts and services, and detects security weaknesses across internal environments. The tool distinguishes itself through a modular plugin architecture that allows for extensible security checks and a stateful asset tracking system that maintains an in-memory registry of discovered infrastructure. It incorporates a dedicated credential brute-force engine for testing passwor

    fscan is an automated penetration testing toolkit focused on internal network reconnaissance, vulnerability scanning, and credential brute‑forcing via a modular plugin architecture, making it a fitting narrow tool for the search—though it lacks built‑in exploitation, reporting, web app, and wireless testing features.

    GoPost-Exploitation ToolsVulnerability ScannersVulnerability Scanning
    View on GitHub↗13,421
  • reverse-shell/routersploitreverse-shell avatar

    reverse-shell/routersploit

    13,151View on GitHub↗

    RouterSploit is an embedded device exploitation framework and vulnerability scanner designed to identify and exploit security flaws in networked embedded hardware and firmware. It provides a centralized toolkit for scanning for known weaknesses and common misconfigurations to gain unauthorized system access. The framework includes an architecture-specific payload generator to create custom binary payloads tailored to the target hardware. It also features an automated brute force tool that uses dictionary-based credential guessing to bypass authentication on hardware devices. The tool covers

    RouterSploit is a dedicated exploitation framework and vulnerability scanner for embedded devices, covering credential harvesting and vulnerability scanning, but it is specialized rather than a full-scope penetration testing toolkit with network recon, web app, or wireless testing built in.

    PythonExploit FrameworksExploitation FrameworksVulnerability Scanning
    View on GitHub↗13,151
  • usestrix/strixusestrix avatar

    usestrix/strix

    20,138View on GitHub↗

    Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno

    Strix is a comprehensive, LLM-powered penetration testing framework that handles reconnaissance, vulnerability scanning, and exploitation orchestration, making it a strong fit for this search.

    PythonSecurity Reporting ToolsVulnerability ScannersVulnerability Scanning
    View on GitHub↗20,138
  • v1s1t0r1sh3r3/airgeddonv1s1t0r1sh3r3 avatar

    v1s1t0r1sh3r3/airgeddon

    7,797View on GitHub↗

    airgeddon is a bash-based wireless network audit suite and security toolkit for Linux. It serves as a framework for testing wireless vulnerabilities and verifying network configurations across various encryption standards, including WPA, WEP, and WPS. The project functions as an orchestration layer that integrates a collection of third-party wireless security tools. It features a modular approach to attack vectorization, coordinating tasks such as evil twin simulations with captive portals, WPA handshake interception, and the execution of WPS vulnerability tests. Its capabilities cover a bro

    Airgeddon is a Bash-based wireless network audit toolkit that covers wireless reconnaissance, exploitation (e.g., evil twin, WPA handshake capture), and credential harvesting, but it is narrowly focused on wireless testing rather than the full range of pentesting activities (web app testing, post-exploitation, reporting) you seem to need.

    ShellWireless Attack ToolsWireless Deauthentication ToolsNetwork Discovery
    View on GitHub↗7,797
  • manisso/fsocietyManisso avatar

    Manisso/fsociety

    12,136View on GitHub↗

    fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits. It functions as a wrapper that integrates external security binaries into a unified, menu-driven interface, providing a centralized system for command-line parameter mapping and execution. The project distinguishes itself by organizing specialized utilities into domain-specific collections for structured navigation. It automates the transition between different phases of an audit by chaining reconnaissance and exploitation tools through sequential workflow automation. The fram

    fsociety is a penetration testing framework that orchestrates external security tools into a unified menu-driven interface for automating reconnaissance, exploitation, and post-exploitation tasks, fitting the need for a structured toolkit covering scanning, web testing, and wireless auditing.

    PythonPost-Exploitation FrameworksPost-Exploitation ToolkitsPost-Exploitation Tools
    View on GitHub↗12,136
  • zan8in/afrogzan8in avatar

    zan8in/afrog

    4,182View on GitHub↗

    afrog is an HTTP vulnerability scanner and web vulnerability management system that identifies security flaws and known CVEs using a YAML-based rule engine. It functions as a payload generator and scanner, comparing server responses against detection rules to find unauthorized access points. The project provides a framework for out-of-band security testing, detecting blind vulnerabilities by triggering and verifying external DNS or HTTP callbacks. Beyond web traffic, it includes a protocol fuzzer capable of executing multi-step read and write sequences over raw TCP and SSL sockets to identify

    afrog is an HTTP vulnerability scanner and exploitation tool for penetration testing, covering web application security testing and credential brute-forcing, though it is narrower in scope than a full penetration testing framework and lacks post-exploitation and wireless modules.

    GoVulnerability ScannersVulnerability ScanningPort Scanners
    View on GitHub↗4,182
  • threat9/routersploitthreat9 avatar

    threat9/routersploit

    13,150View on GitHub↗

    Routersploit is a penetration testing framework designed for the security assessment of embedded network devices and routers. It functions as a comprehensive tool for auditing hardware configurations and testing network protocols to identify and verify security vulnerabilities. The framework utilizes a modular plugin architecture that allows for the dynamic loading of exploit and scanner modules. It provides a centralized command interface that manages target state and executes controlled payloads, enabling the automation of security testing across diverse network hardware. The platform cove

    Routersploit is a modular penetration testing framework focused on auditing and exploiting embedded network devices and routers, which fits the penetration testing toolkit category you are looking for, though it is narrower in scope than a general-purpose framework.

    PythonExploitation FrameworksExploitation FrameworksNetwork Scanners
    View on GitHub↗13,150
  • rhinosecuritylabs/pacuRhinoSecurityLabs avatar

    RhinoSecurityLabs/pacu

    5,234View on GitHub↗

    Pacu is an exploitation framework designed for auditing and testing the security of Amazon Web Services environments. It serves as a cloud penetration testing tool and resource enumerator used to identify misconfigurations, map attack surfaces, and execute privilege escalation paths. The framework provides specialized capabilities for post-exploitation and red team operations, including establishing persistence through identity and access management backdooring. It distinguishes itself with a plugin-based module system that allows for the development of custom tasks and the orchestration of A

    Pacu is a dedicated cloud penetration testing framework for AWS, providing reconnaissance, exploitation, and post‑exploitation modules — it fits the penetration testing toolkit category but is narrowly scoped to cloud environments and lacks the broader network, web, and wireless testing capabilities your query lists.

    PythonExploitation FrameworksPost-Exploitation FrameworksEnumeration
    View on GitHub↗5,234
  • jaykali/maskphishjaykali avatar

    jaykali/maskphish

    3,020View on GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Maskphish is a multi-purpose security toolkit that explicitly covers penetration testing, network vulnerability scanning, and reconnaissance, though its focus on phishing and social engineering makes it a narrower fit for a comprehensive pentesting framework rather than a flagship one.

    ShellCredential Harvesting PagesPost-Exploitation FrameworksPost-Exploitation Plugins
    View on GitHub↗3,020
  • beefproject/beefbeefproject avatar

    beefproject/beef

    10,728View on GitHub↗

    BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It functions as a platform for security professionals to evaluate client-side defenses by injecting persistent scripts into web browsers, establishing a bidirectional communication channel for remote command execution and data exfiltration. The framework distinguishes itself through its ability to use compromised browser sessions as proxies to conduct internal network reconnaissance, effectively bypassing perimeter security controls. It utilizes an event-driven control interface and

    BeEF is a specialized penetration testing framework focused on browser exploitation and web application auditing, fitting the intent for offensive security tools but lacking the broader network scanning, wireless testing, and vulnerability scanning a comprehensive toolkit would cover.

    JavaScriptExploitation Frameworks
    View on GitHub↗10,728
  • hackplayers/evil-winrmHackplayers avatar

    Hackplayers/evil-winrm

    5,403View on GitHub↗

    Evil-WinRM is a penetration testing tool and interactive remote shell designed for managing and executing commands on remote Windows systems via the WinRM protocol. It functions as a security utility for auditing Windows environments through remote command execution and credential manipulation. The tool distinguishes itself through its authentication capabilities, acting as both a Kerberos authentication client using ticket-based files and an NTLM pass-the-hash client that accesses services using password hashes instead of plaintext credentials. To evade detection, it supports in-memory paylo

    Evil-WinRM is a focused penetration testing tool for remote Windows command execution and credential harvesting via WinRM, matching the category as a real pentesting utility, though it does not cover the broader reconnaissance, scanning, or reporting features listed.

    RubyService Enumeration ToolsLateral Movement
    View on GitHub↗5,403
  • samratashok/nishangsamratashok avatar

    samratashok/nishang

    9,951View on GitHub↗

    Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows targets. It functions as a post-exploitation toolkit and payload generator to automate attacks and manage remote targets. The project provides specialized capabilities for bypassing security controls, such as disabling the Antimalware Scan Interface and employing in-memory execution to avoid disk-based detection. It includes a variety of stealthy command and control mechanisms, utilizing non-standard channels like DNS TXT records, ICMP traffic, and webmail for communication a

    Nishang is a PowerShell-based offensive security framework purpose-built for penetration testing and red teaming on Windows, squarely fitting the toolkit category; however, its focus on post-exploitation and payload generation means it does not directly cover reconnaissance, vulnerability scanning, or reporting as first-class features.

    PowerShellPost-Exploitation FrameworksPost-Exploitation ToolkitsPort Scanners
    View on GitHub↗9,951
  • bettercap/bettercapbettercap avatar

    bettercap/bettercap

    18,855View on GitHub↗

    Bettercap is a modular framework designed for network reconnaissance, security testing, and the execution of man-in-the-middle attacks. It functions as a comprehensive utility for surveying wired and wireless network segments, identifying connected devices, and analyzing communication protocols through real-time traffic interception and manipulation. The platform distinguishes itself through an event-driven architecture that coordinates network state changes and packet-level data through a centralized message pipeline. It provides a programmable scripting engine and an API for orchestrating s

    Bettercap is a modular penetration testing framework focused on network reconnaissance, man-in-the-middle attacks, and wireless security testing, making it squarely a toolkit in this category, though it lacks built-in vulnerability scanning, web application testing, and reporting features.

    GoWireless Attack Tools
    View on GitHub↗18,855
  • byt3bl33d3r/crackmapexecbyt3bl33d3r avatar

    byt3bl33d3r/CrackMapExec

    9,144View on GitHub↗

    CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security postures across large IP ranges. It functions as a multi-protocol security scanner and network protocol auditor used to identify vulnerabilities and misconfigurations. The tool provides capabilities for Active Directory auditing to enumerate users and permissions, as well as post-exploitation enumeration to gather system metadata and discover lateral movement paths. It includes a framework for credential spraying and harvesting across various network services. The system utilize

    CrackMapExec is a network penetration testing framework focused on Active Directory auditing, lateral movement, and credential harvesting—it squarely fits the penetration testing toolkit category, though it lacks coverage of web application and wireless testing features.

    PythonExploitation FrameworksPost-Exploitation FrameworksLateral Movement
    View on GitHub↗9,144
  • justcallmekoko/esp32marauderjustcallmekoko avatar

    justcallmekoko/ESP32Marauder

    9,916View on GitHub↗

    ESP32Marauder is a suite of specialized firmware images and tools designed for wireless network auditing, packet sniffing, and Bluetooth scanning on ESP32 hardware. It functions as a wireless penetration tool used to analyze network security and monitor signal traffic. The project includes capabilities for capturing wireless handshakes and simulating access points to test infrastructure resilience. It also features a Bluetooth low energy scanner used to identify hardware signatures and detect unauthorized signals or skimming devices. The firmware supports broader security operations includin

    This repository provides a specialized firmware suite for wireless penetration testing on ESP32 hardware, covering Wi-Fi deauthentication, handshake capture, and Bluetooth scanning — it is a genuine wireless penetration testing tool, though narrower than a full-scope framework.

    C++Bluetooth Security Testing
    View on GitHub↗9,916
  • pr3y/brucepr3y avatar

    pr3y/Bruce

    5,985View on GitHub↗

    Bruce is offensive security firmware for ESP32 hardware designed for network attacks, radio analysis, and hardware-based identity spoofing. It provides a specialized toolkit for conducting red team operations, including a WiFi penetration testing tool, a multi-protocol radio toolkit, and a system for emulating USB keyboards and mice to inject payloads. The firmware distinguishes itself through a broad range of signal manipulation capabilities, allowing for the cloning and writing of RFID tags and the transmission of disruptive pairing requests to Bluetooth devices. It also includes a multi-pr

    Bruce is an offensive security firmware for ESP32 hardware that provides a specialized penetration testing toolkit for wireless network attacks, radio analysis, and hardware-based identity spoofing, making it a fit for the intent but focused on specific attack vectors rather than covering the full range of features like vulnerability scanning or web app testing.

    C++Red Team ToolsBadUSB PayloadsBluetooth Pairing Notification Spam
    View on GitHub↗5,985
  • m0bilesecurity/rms-runtime-mobile-securitym0bilesecurity avatar

    m0bilesecurity/RMS-Runtime-Mobile-Security

    2,971View on GitHub↗

    This project is an Android security analysis toolkit and mobile app runtime manipulator designed for reverse engineering and auditing mobile applications. It provides a system for modifying Java classes and method behavior in active mobile processes to bypass security controls. The toolkit includes a web-based interface for controlling the instrumentation engine and a specialized utility for disabling certificate validation to intercept and inspect encrypted network traffic via SSL pinning bypass. It also features an Android file explorer for browsing and managing files within private data di

    rms-runtime-mobile-security is a mobile-specific security analysis toolkit for runtime manipulation, reverse engineering, and bypassing controls — it fits the penetration testing category squarely, but as a narrow mobile-focused tool it does not cover the full breadth of network reconnaissance, web, or wireless testing.

    JavaScriptInstrumentation & HookingRuntime Class ModificationsAndroid Application Reverse Engineering
    View on GitHub↗2,971
Compare the top 10 at a glance
RepositoryStarsLanguageLicenseLast push
z4nzu/hackingtool77.5KPythonMITMar 15, 2026
rapid7/metasploit-framework38.4KRubyNOASSERTIONJun 16, 2026
infinition/bjorn5.7KPythonmitFeb 18, 2026
greydgl/pentestgpt11.7KPythonmitFeb 18, 2026
shadow1ng/fscan13.4KGomitJan 31, 2026
reverse-shell/routersploit13.2KPythonNOASSERTIONMay 5, 2026
usestrix/strix20.1KPythonapache-2.0Feb 19, 2026
v1s1t0r1sh3r3/airgeddon7.8KShellGPL-3.0Jun 13, 2026
manisso/fsociety12.1KPythonMITAug 8, 2024
zan8in/afrog4.2KGomitFeb 20, 2026

Related searches

  • an open source penetration testing framework
  • an open source toolkit for penetration testing
  • a penetration testing framework for security auditing
  • Offensive Tooling and Red Teaming
  • a post-exploitation toolkit
  • an autonomous framework for penetration testing
  • an open source tool for network security
  • an automated security scanner for web applications