awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
beefproject avatar

beefproject/beef

0
View on GitHub↗
10,728 stars·2,342 forks·JavaScript·17 viewsbeefproject.com↗

Beef

BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It functions as a platform for security professionals to evaluate client-side defenses by injecting persistent scripts into web browsers, establishing a bidirectional communication channel for remote command execution and data exfiltration.

The framework distinguishes itself through its ability to use compromised browser sessions as proxies to conduct internal network reconnaissance, effectively bypassing perimeter security controls. It utilizes an event-driven control interface and asynchronous command queuing to manage multiple hooked sessions, allowing for the coordination of complex, multi-stage assessment workflows.

The system supports a modular architecture that enables the development of custom plugins and automated rules to extend its core testing capabilities. It includes comprehensive administrative controls, such as role-based access control, authentication rate limiting, and network access restrictions, to secure the testing environment and manage component lifecycles.

Features

  • Exploitation Frameworks - Functions as a security testing platform that hooks web browsers to execute targeted scripts within compromised sessions.
  • Penetration Testing Tools - Provides a modular environment for security professionals to conduct internal network mapping and client-side assessments.
  • Browser API Hooks - Injects persistent client-side scripts into browsers to establish bidirectional communication for remote command execution.
  • Browser Scripting Tools - Injects persistent scripts into web browsers to establish bidirectional communication channels for remote command execution.
  • Browser Security Testers - Provides a framework for launching directed command modules to evaluate client-side browser defenses and identify vulnerabilities.
  • Reconnaissance and Assessment Platforms - Acts as a framework for testing browser defenses and simulating real-world attack vectors by injecting scripts into remote clients.
  • Browser-Based Attack Modules - Executes targeted scripts within compromised browser sessions to gather information or perform automated security tasks.
  • Reverse Tunnels - Routes network traffic through compromised browser sessions to bypass perimeter security controls and interact with internal infrastructure.
  • Network Reconnaissance Tools - Uses compromised browser sessions as proxies to conduct internal network reconnaissance and map infrastructure.
  • Web Application Penetration Testing - Simulates attack vectors in a controlled environment to test the resilience of web-based systems against exploitation.
  • Exploitation Tools - Browser exploitation framework.
  • Watering Hole Attack - Browser exploitation framework for client-side testing.
  • Command And Control Frameworks - Framework for exploiting and controlling compromised web browsers.
  • Exploitation and Payloads - Framework for browser-based exploitation.
  • Offensive Security - Framework for browser-based exploitation and control.
  • OSINT and Recon - A browser exploitation framework for security testing.
  • Security Frameworks - Framework for exploiting web browsers and client-side security.
  • Security Tools - Browser exploitation framework for security testing and research.
  • Web Vulnerability Tools - Browser exploitation framework for XSS testing.
  • Role-Based Access Control - Enforces authentication and authorization checks at administrative and API layers to restrict sensitive system functions.
  • Modular Plugin Architectures - Supports a modular architecture that allows dynamic loading of functional components at runtime to extend core capabilities.
  • Security Testing Tools - Provides a platform for building custom modules and automated rules to extend core security testing functionality.
  • Modular Extension Architectures - Enables users to build custom modules and automated rules to expand core security testing capabilities.
  • Administrative Access Controls - Enforces unique credential requirements for web and programming interfaces to prevent unauthorized access to control panels.
  • Event-Driven Architectures - Coordinates state changes and module execution across multiple connected browser sessions using an event-driven architecture.
  • Request Queuing - Buffers instructions for hooked clients until the target browser establishes a connection and requests the next operation.

Star history

Star history chart for beefproject/beefStar history chart for beefproject/beef

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does beefproject/beef do?

BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It functions as a platform for security professionals to evaluate client-side defenses by injecting persistent scripts into web browsers, establishing a bidirectional communication channel for remote command execution and data exfiltration.

What are the main features of beefproject/beef?

The main features of beefproject/beef are: Exploitation Frameworks, Penetration Testing Tools, Browser API Hooks, Browser Scripting Tools, Browser Security Testers, Reconnaissance and Assessment Platforms, Browser-Based Attack Modules, Reverse Tunnels.

What are some open-source alternatives to beefproject/beef?

Open-source alternatives to beefproject/beef include: swisskyrepo/payloadsallthethings — This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers.… trustedsec/social-engineer-toolkit — The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate… shadow1ng/fscan — Fscan is an automated penetration testing tool designed for internal network reconnaissance and vulnerability… rapid7/metasploit-framework — The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of… s0md3v/xsstrike — XSStrike is an automated security scanning engine designed for web application discovery, input. mlogclub/bbs-go — bbs-go is a community forum software written in Go. It functions as a gamified community platform and social network…

Open-source alternatives to Beef

Similar open-source projects, ranked by how many features they share with Beef.
  • swisskyrepo/payloadsallthethingsswisskyrepo avatar

    swisskyrepo/PayloadsAllTheThings

    78,434View on GitHub↗

    This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers. It functions as a centralized repository of offensive security techniques, providing a structured collection of exploit payloads, attack vectors, and methodologies for conducting vulnerability assessments and penetration testing. The repository distinguishes itself through a cross-platform payload taxonomy that categorizes exploitation methods by vulnerability type and target environment, enabling rapid lookup during security assessments. It maintains high standards of data i

    Pythonbountybugbountybypass
    View on GitHub↗78,434
  • trustedsec/social-engineer-toolkittrustedsec avatar

    trustedsec/social-engineer-toolkit

    14,984View on GitHub↗

    The Social-Engineer Toolkit is a social engineering framework and penetration testing suite designed to simulate human-centric security attacks. It serves as a phishing simulation tool and credential harvesting utility to evaluate personnel awareness and organizational resilience. The toolkit provides specialized tooling for phishing campaign testing and credential theft simulation. It enables the creation of deceptive emails and landing pages to identify vulnerabilities in how users handle sensitive account information. The system includes capabilities for security awareness training and br

    Python
    View on GitHub↗14,984
  • shadow1ng/fscanshadow1ng avatar

    shadow1ng/fscan

    13,421View on GitHub↗

    Fscan is an automated penetration testing tool designed for internal network reconnaissance and vulnerability assessment. It functions as a comprehensive security framework that maps network infrastructure, identifies active hosts and services, and detects security weaknesses across internal environments. The tool distinguishes itself through a modular plugin architecture that allows for extensible security checks and a stateful asset tracking system that maintains an in-memory registry of discovered infrastructure. It incorporates a dedicated credential brute-force engine for testing passwor

    Go
    View on GitHub↗13,421
  • rapid7/metasploit-frameworkrapid7 avatar

    rapid7/metasploit-framework

    38,415View on GitHub↗

    The framework is a comprehensive penetration testing platform designed for the development, testing, and execution of security exploits. It serves as a research toolkit and automated assessment environment, enabling security professionals to identify and validate vulnerabilities within networked systems and infrastructure through repeatable, standardized procedures. The platform distinguishes itself through a modular architecture that supports reflective payload injection, allowing for the execution of code directly in memory without writing to disk. It utilizes an asynchronous event loop to

    Rubyhacktoberfest
    View on GitHub↗38,415
See all 30 alternatives to Beef→