For an open source penetration testing framework, the first results are rapid7/metasploit-framework (Metasploit Framework is the world's most widely used open-source exploitation framework, offering a modular exploit library, payload generation, post-exploitation modules, C2 integration, and a large community contributing custom modules—exactly what this search asks for), joaomatosf/jexboss and screetsec/thefatrat. n1nj4sec/pupy and greydgl/pentestgpt round out the shortlist. Compare the match explanations and check the project documentation against your requirements.
Explore powerful open-source penetration testing and red teaming frameworks designed for security assessment and exploitation.
The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures. The platform distinguishes itself through a modular architecture that supports reflective payload injection, allowing for the execution of code directly in memory without writing to disk. It utilizes an asynchronous event loop to
Metasploit Framework is the world's most widely used open-source exploitation framework, offering a modular exploit library, payload generation, post-exploitation modules, C2 integration, and a large community contributing custom modules—exactly what this search asks for.
jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit deserialization flaws to achieve remote code execution on target servers. It functions as a suite of tools for delivering payloads and executing system commands on vulnerable remote applications. The project includes a reverse shell orchestrator to establish and maintain persistent remote command connections from exploited targets back to a listener. It also provides post-exploitation automation for managing remote access and updating software on compromised systems. The fra
jexboss is a Java deserialization exploitation framework with reverse shell and post-exploitation capabilities, so it fits the exploitation-framework category, but its narrow focus on a single vulnerability type means it falls short of the broad module library and payload variety expected in a Metasploit-like tool.
TheFatRat is a security exploitation framework designed to automate the creation, obfuscation, and deployment of payloads for penetration testing. It functions as a comprehensive toolkit that streamlines the exploitation lifecycle, enabling users to generate malicious executables, manage network listeners, and execute post-exploitation tasks through a unified command-line interface. The framework distinguishes itself by integrating various third-party exploitation utilities into a single, orchestrated workflow. It provides specialized capabilities for embedding code into legitimate binaries a
TheFatRat is a security exploitation framework that automates payload generation, obfuscation, and deployment with post-exploitation and listener management, making it a solid fit for penetration testing—though it focuses more on payload creation than providing its own exploit module library.
Pupy is a command and control framework and post-exploitation suite used for remote administration and system management. It functions as a cross-platform tool for deploying payloads and controlling multiple remote agents through encrypted communication channels. The framework features a multi-platform payload generator that creates custom executable files using configurable network launchers. It employs a network traffic obfuscator that stacks encryption and obfuscation protocols to hide communication from observation. The system provides capabilities for in-memory code execution, remote pr
Pupy is a cross-platform command-and-control and post‑exploitation framework with payload generation and encrypted communication, fitting the need for a red‑teaming tool, though it focuses more on post‑exploitation than on hosting a broad exploit module library.
PentestGPT is an autonomous security testing framework that leverages large language models to plan, execute, and coordinate end-to-end penetration testing engagements. By functioning as an autonomous agent, the system automates the entire testing lifecycle, from initial reconnaissance and vulnerability analysis to the generation of custom exploits and the execution of post-exploitation tasks. The platform distinguishes itself through a multi-agent orchestration system that coordinates specialized AI agents to collaborate on complex, multi-stage attack chains. It integrates multimodal context
PentestGPT is an autonomous penetration testing framework that uses AI to automate exploit generation and post-exploitation tasks, fitting the exploitation framework category despite its novel LLM-based approach.
Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows targets. It functions as a post-exploitation toolkit and payload generator to automate attacks and manage remote targets. The project provides specialized capabilities for bypassing security controls, such as disabling the Antimalware Scan Interface and employing in-memory execution to avoid disk-based detection. It includes a variety of stealthy command and control mechanisms, utilizing non-standard channels like DNS TXT records, ICMP traffic, and webmail for communication a
Nishang is a PowerShell-based offensive security framework for red teaming on Windows, providing payload generation, post-exploitation modules, and stealthy C2 channels, which fits the search for an exploitation framework even though it is more Windows-specific and narrower than a full Metasploit replacement.
Pacu is an exploitation framework designed for auditing and testing the security of Amazon Web Services environments. It serves as a cloud penetration testing tool and resource enumerator used to identify misconfigurations, map attack surfaces, and execute privilege escalation paths. The framework provides specialized capabilities for post-exploitation and red team operations, including establishing persistence through identity and access management backdooring. It distinguishes itself with a plugin-based module system that allows for the development of custom tasks and the orchestration of A
Pacu is a Python-based exploitation framework for cloud penetration testing on AWS, with a plugin module system and post-exploitation features—it's a specialized match for the intent, though it focuses on cloud environments rather than general network exploitation like Metasploit.
BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It functions as a platform for security professionals to evaluate client-side defenses by injecting persistent scripts into web browsers, establishing a bidirectional communication channel for remote command execution and data exfiltration. The framework distinguishes itself through its ability to use compromised browser sessions as proxies to conduct internal network reconnaissance, effectively bypassing perimeter security controls. It utilizes an event-driven control interface and
BeEF is a specialized browser exploitation framework that provides module-based exploits, payload injection, command-and-control capabilities, and post-exploitation features for client-side attacks, fitting the exploitation framework category even though it focuses on a narrower attack surface.
Havoc is a post-exploitation framework used for red team operations. It provides a centralized command and control system for managing remote agents through persistent network connections and customizable communication profiles. The framework focuses on security evasion and stealth, utilizing indirect syscall execution, return address spoofing, and hardware-breakpoint patching to bypass endpoint detection and response tools. It includes a payload generation workflow to create executable shellcode or DLLs for initial remote access. The system covers a broad range of operational capabilities,
Havoc is a post-exploitation and C2 framework for red teams that includes payload generation and custom modules, but it lacks the extensive exploit module library for initial vulnerability exploitation that defines a full penetration testing framework like Metasploit.
Empire is a command and control framework and post-exploitation toolkit used for network penetration testing. It serves as a centralized platform for coordinating remote agent communication and automating the delivery of security testing payloads to target systems. The project provides a suite of modules for host reconnaissance, lateral movement, and credential harvesting across corporate environments. It functions as a remote administration tool to maintain persistence and execute commands on compromised hosts. The framework incorporates capabilities for agent orchestration and the executio
Empire is a post-exploitation command and control framework rather than an exploitation framework for discovering and exploiting vulnerabilities, making it a neighbouring tool for red team operations but not a direct match to Metasploit-style exploitation frameworks.
Sliver is a command and control framework designed for adversary emulation and security assessment operations. It provides a centralized platform for managing remote systems, enabling security professionals to coordinate multi-operator sessions and maintain persistent, secure communication channels across diverse network environments. The framework distinguishes itself through its focus on stealth and infrastructure flexibility. It utilizes dynamic payload obfuscation to generate unique binaries and supports in-memory execution to minimize disk artifacts. Communication is secured through mutu
Sliver is a command-and-control framework focused on post-exploitation and payload delivery, but it lacks a built-in exploit module library — the core of the exploitation framework you're after — so it's more of a companion to tools like Metasploit rather than a replacement.
Stitch is a command and control framework and post-exploitation toolkit designed for managing multiple remote systems from a central server. It functions as a remote administration tool and payload builder, enabling the execution of commands and the deployment of agents across different operating systems. The project features a cross-platform builder for generating custom executable agents with configurable network bindings and boot behaviors. It utilizes encrypted communication channels to secure traffic between the controller and remote clients, and it supports the execution of dynamic scri
Stitch is a command-and-control and post-exploitation framework with payload generation, but it lacks an exploit module library for vulnerability exploitation, so it is a complementary tool rather than a full exploitation framework like Metasploit.
| Repository | Stars | Language | License | Last push |
|---|---|---|---|---|
| rapid7/metasploit-framework | 38.4K | Ruby | NOASSERTION | |
| joaomatosf/jexboss | 2.5K | Python | other | |
| 11K |
| C |
| gpl-3.0 |
| n1nj4sec/pupy | 8.9K | Python | other |
| greydgl/pentestgpt | 11.7K | Python | mit |
| samratashok/nishang | 10K | PowerShell | NOASSERTION |
| rhinosecuritylabs/pacu | 5.2K | Python | BSD-3-Clause |
| beefproject/beef | 10.7K | JavaScript | — |
| havocframework/havoc | 8.2K | Go | gpl-3.0 |
| empireproject/empire | 7.8K | PowerShell | bsd-3-clause |