awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to 1n3/findsploit

Open-source alternatives to Findsploit

30 open-source projects similar to 1n3/findsploit, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Findsploit alternative.

  • vulnerscom/getsploitvulnersCom avatar

    vulnersCom/getsploit

    1,814View on GitHub↗
    Python
    View on GitHub↗1,814
  • byt3bl33d3r/crackmapexecbyt3bl33d3r avatar

    byt3bl33d3r/CrackMapExec

    9,144View on GitHub↗

    CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security postures across large IP ranges. It functions as a multi-protocol security scanner and network protocol auditor used to identify vulnerabilities and misconfigurations. The tool provides capabilities for Active Directory auditing to enumerate users and permissions, as well as post-exploitation enumeration to gather system metadata and discover lateral movement paths. It includes a framework for credential spraying and harvesting across various network services. The system utilize

    Python
    View on GitHub↗9,144
  • kathanp19/howtohuntKathanP19 avatar

    KathanP19/HowToHunt

    7,146View on GitHub↗

    HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It provides a research methodology for organizing security testing procedures and validating application behaviors against known vulnerability patterns. The project features a curated library of security flaws and reconnaissance techniques. It organizes security testing into modular playbooks, checklists, and categorical vulnerability mappings to align specific exploitation techniques with target weaknesses. The repository covers a systematic sequence of information gathering task

    bugbountybugbountytipsbughunting-methodology
    View on GitHub↗7,146
  • 1337g/cve-2017-102711

    1337g/CVE-2017-10271

    0View on GitHub↗
    View on GitHub↗0

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • 4w4k3/umbrella4

    4w4k3/Umbrella

    0View on GitHub↗
    View on GitHub↗0
  • arachni/arachniArachni avatar

    Arachni/arachni

    4,000View on GitHub↗

    Arachni is a dynamic application security testing vulnerability scanner and web application security tool. It functions as a distributed web audit framework that performs active and passive audits to identify security flaws such as SQL injection and cross-site scripting. The project features a JavaScript-aware web crawler that executes scripts and monitors DOM changes to analyze modern dynamic web applications. It utilizes server platform fingerprinting to target compatible security payloads and provides a grid-based system to distribute scanning workloads across multiple nodes. The tool cov

    Rubyanalysisarachniaudit
    View on GitHub↗4,000
  • 1n3/sn1per1N3 avatar

    1N3/Sn1per

    10,049View on GitHub↗

    Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan

    Shellattack-surfaceattack-surface-managementattacksurface
    View on GitHub↗10,049
  • baidu/openraspbaidu avatar

    baidu/openrasp

    2,964View on GitHub↗

    🔥Open source RASP solution

    C++
    View on GitHub↗2,964
  • beefproject/beefbeefproject avatar

    beefproject/beef

    10,728View on GitHub↗

    BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It functions as a platform for security professionals to evaluate client-side defenses by injecting persistent scripts into web browsers, establishing a bidirectional communication channel for remote command execution and data exfiltration. The framework distinguishes itself through its ability to use compromised browser sessions as proxies to conduct internal network reconnaissance, effectively bypassing perimeter security controls. It utilizes an event-driven control interface and

    JavaScript
    View on GitHub↗10,728
  • bigblackhat/ofxB

    bigblackhat/oFx

    0View on GitHub↗
    View on GitHub↗0
  • bigsizeme/burplugin-java-rcebigsizeme avatar

    bigsizeme/burplugin-java-rce

    109View on GitHub↗

    *本软件仅限用于学习交流禁止用于任何非法行为 本软件为burpsuite的一个插件,实验作品只是为插件开发做一个实验。使用burpsuite提供的API很少,希望抛砖引玉fork指正。 本版本支持elasticsearch java语言远程命令执行及文件上传 elasticsearchgroov语言远程命令执行及文件上传 struts2-005、 struts2-009、struts2-013、struts2-016、struts2-019、struts2-020、struts2-devmode、 struts2-032、struts2-033、…

    Java
    View on GitHub↗109
  • bitthebyte/eagleBitTheByte avatar

    BitTheByte/Eagle

    128View on GitHub↗

    Multithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities

    Python
    View on GitHub↗128
  • bnagy/crashwalkbnagy avatar

    bnagy/crashwalk

    361View on GitHub↗

    Crashwalk

    Go
    View on GitHub↗361
  • bountyyfi/lonkerobountyyfi avatar

    bountyyfi/lonkero

    929View on GitHub↗

    Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.

    Rust
    View on GitHub↗929
  • byt3bl33d3r/gcatbyt3bl33d3r avatar

    byt3bl33d3r/gcat

    1,351View on GitHub↗

    Gcat A stealthy Python based backdoor that uses Gmail as a command and control server

    Python
    View on GitHub↗1,351
  • auth0/repo-supervisorauth0 avatar

    auth0/repo-supervisor

    653View on GitHub↗

    Scan your code for security misconfiguration, search for passwords and secrets. :mag:

    JavaScript
    View on GitHub↗653
  • capt-meelo/telewreckcapt-meelo avatar

    capt-meelo/telewreck

    97View on GitHub↗

    A Burp extension to detect and exploit versions of Telerik Web UI vulnerable to CVE-2017-9248. This extension is based on the original exploit tool written by Paul Taylor (@bao7uo) which is available at https://github.com/bao7uo/dp_crypto. Credits and big thanks to him.

    Python
    View on GitHub↗97
  • chaitin/xraychaitin avatar

    chaitin/xray

    11,612View on GitHub↗

    Xray is a security assessment tool focused on web vulnerability scanning, attack surface mapping, and technology fingerprinting. It identifies common security flaws through automated scanning and semantic analysis, while verifying findings via a custom proof-of-concept execution engine. The system distinguishes itself with a containerized vulnerability testbed used to deploy pre-configured vulnerable applications. This environment allows for the simulation of specific vulnerabilities and edge-case scenarios to validate scanner accuracy and eliminate false positives. The platform covers a bro

    Vuepassive-vulnerability-scannerpocsecurity
    View on GitHub↗11,612
  • chalker/notesChALkeR avatar

    ChALkeR/notes

    1,277View on GitHub↗

    Some public notes

    View on GitHub↗1,277
  • cloudflare/flancloudflare avatar

    cloudflare/flan

    4,162View on GitHub↗

    Flan is a containerized network vulnerability scanner and security auditor. It identifies open ports and service versions across a network to detect known security weaknesses and misconfigurations. The system is designed to run within isolated container environments, utilizing configuration maps to manage target lists and secrets. It includes a dedicated mechanism for archiving scan output files and security analysis data to remote S3 buckets for long-term storage. The tool generates formatted vulnerability summaries and security reports in multiple document formats for technical analysis. I

    Python
    View on GitHub↗4,162
  • codedx/burp-extensioncodedx avatar

    codedx/burp-extension

    5View on GitHub↗

    burp-extension

    Java
    View on GitHub↗5
  • codewatchorg/burp-indicatorsofvulnerabilitycodewatchorg avatar

    codewatchorg/Burp-IndicatorsOfVulnerability

    42View on GitHub↗

    Burp extension that checks application requests and responses for indicators of vulnerability or targets for attack

    Java
    View on GitHub↗42
  • commixproject/commixcommixproject avatar

    commixproject/commix

    5,757View on GitHub↗

    Commix is an automated tool for detecting and exploiting OS command injection vulnerabilities in web applications. It probes user-supplied input vectors with heuristic test payloads, analyzes response differences to identify injection points, and then automates the execution of arbitrary operating system commands on the target server. The tool distinguishes itself through a multi-layer filter bypass engine that evaluates input constraints independently per filter type and composes tailored evasion strategies into a single payload. A modular payload tamper pipeline transforms raw injection str

    Python
    View on GitHub↗5,757
  • d35m0nd142/lfisuiteD35m0nd142 avatar

    D35m0nd142/LFISuite

    1,945View on GitHub↗

    Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

    Python
    View on GitHub↗1,945
  • danielmiessler/seclistsdanielmiessler avatar

    danielmiessler/SecLists

    71,596View on GitHub↗

    SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities. The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution log

    PHP
    View on GitHub↗71,596
  • darrenmartyn/visualdoorD

    darrenmartyn/VisualDoor

    0View on GitHub↗
    View on GitHub↗0
  • denispodgurskii/pentestkitDenisPodgurskii avatar

    DenisPodgurskii/pentestkit

    220View on GitHub↗

    OWASP PTK - application security browser extension.

    JavaScript
    View on GitHub↗220
  • directdefense/superserialdirectdefense avatar

    directdefense/superserial

    9View on GitHub↗

    SuperSerial - Burp Java Deserialization Vulnerability Identification

    Java
    View on GitHub↗9
  • directdefense/superserial-activedirectdefense avatar

    directdefense/superserial-active

    7View on GitHub↗

    SuperSerial-Active - Java Deserialization Vulnerability Active Identification Burp Extender

    Java
    View on GitHub↗7
  • 1n3/blackwidow1N3 avatar

    1N3/BlackWidow

    1,804View on GitHub↗
    Pythonactiveapplicationautomated
    View on GitHub↗1,804