awesome-repositories.com
Blog
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Manisso avatar

Manisso/fsociety

0
View on GitHub↗
12,136 stars·2,105 forks·Python·MIT·10 views

Fsociety

fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits. It functions as a wrapper that integrates external security binaries into a unified, menu-driven interface, providing a centralized system for command-line parameter mapping and execution.

The project distinguishes itself by organizing specialized utilities into domain-specific collections for structured navigation. It automates the transition between different phases of an audit by chaining reconnaissance and exploitation tools through sequential workflow automation.

The framework covers a broad range of security capabilities, including network reconnaissance, web application auditing, and system vulnerability exploitation. It provides dedicated toolsets for credential brute forcing, network traffic interception, wireless security auditing, and post-exploitation management to maintain persistence on compromised systems.

Features

  • Penetration Testing Frameworks - Conducting a full security audit from initial reconnaissance and vulnerability scanning to exploiting services and maintaining system access.
  • Information Gathering - Discovers host information and software versions using a suite of network scanners and auditors.
  • Password Attacks - Provides utilities for cracking credentials and generating wordlists to recover user passwords.
  • Password Cracking - Provides tools for brute-forcing and managing password recovery sessions to test credential strength.
  • Credential Cracking - Runs dictionary attacks against login services and password hashes to recover credentials.
  • Traffic Interception - Captures and modifies network traffic to perform man-in-the-middle attacks.
  • Automated Exploit Execution - Executes automated attacks like SQL injection and remote code execution against targeted services.
  • Web Application Exploits - Launches automated exploits against web applications and services to confirm unauthorized access.
  • Web Exploitation - Provides tools for reconnaissance and exploiting SQL injection, command injection, and remote code execution flaws.
  • Web Vulnerability Scanning - Integrates tools to identify and exploit vulnerabilities in web applications.
  • Command Line Interface Mappings - Provides a system for mapping abstract user targets and flags to specific executable binaries via a unified interface.
  • Security Tool Orchestrators - A wrapper that integrates external security binaries into a unified interface for command-line parameter mapping and execution.
  • Target Argument Mappers - Translates user-provided targets and flags into the specific command-line arguments required by underlying security tools.
  • Man-in-the-Middle Frameworks - Provides frameworks for intercepting and manipulating network traffic via man-in-the-middle attacks.
  • Post-Exploitation Frameworks - Verifies shell connectivity and maintains persistence on a compromised system after an initial breach.
  • Post-Exploitation Toolkits - Provides tools for maintaining access and escalating privileges on compromised systems.
  • Reconnaissance Workflow Automation - Chains individual reconnaissance and exploitation tools together to automate the transition between different phases of a security audit.
  • Web Vulnerability Scanners - A toolkit for detecting SQL injection, cross-site scripting, and exposed directories on target websites.
  • Information Gathering Tools - Collects data on targets using scanners to identify active hosts, open ports, and server users.
  • Post-Exploitation Tools - Verifies shell connectivity and deploys persistence tools to maintain access after a successful compromise.
  • System Exploitation Tools - Automates the discovery and exploitation of vulnerabilities in servers and services to gain unauthorized access.
  • Network Reconnaissance Tools - Scans target hosts and ports to map network infrastructure and active services.
  • Credential Brute-Forcing - Executes automated dictionary and brute-force attacks to evaluate authentication strength.
  • Wireless Security Auditing - A set of tools for exploiting access point vulnerabilities and auditing Bluetooth and Wi-Fi communication protocols.
  • Web Application Pipelines - Orchestrates automated probes to detect software bugs and remote code execution vectors in web endpoints.
  • Web Security Auditing - Ships toolsets for systematically verifying the security posture of web applications through vulnerability scanning.
  • Exploitation Tool Wrappers - Integrates a suite of external security binaries by providing a unified interface for input passing and output capture.
  • Security Tool Collections - Groups related security utilities into functional collections for network reconnaissance, web auditing, and credential cracking.
  • Sniffing and Spoofing - Captures and manipulates data packets via sniffing, SSL stripping, and spoofing to steal credentials.
  • Web Enumeration - Locates specific website types, control panels, and exposed files using automated discovery.
  • Wireless Testing - Audits wireless security by exploiting access point vulnerabilities and deploying honeypots.
  • Exposed Asset Detection - Searches for unprotected sensitive data by locating open control panels and upload directories.
  • Hidden File Discovery - Searches for exposed control panels, archived zip files, and specific CMS installations across the web.
  • Private Asset Discovery - Enumerates hidden websites, control panels, and server information to bypass security protections.
  • Web Asset Harvesting - Provides capabilities to find specific website types and exposed control panels via automated search queries.
  • Web Directory Enumeration Tools - Implements utilities for discovering hidden files and directories on web servers through wordlist-based brute-force testing.
  • Web Infrastructure Mapping - Maps target footprints by discovering hidden files and server users while bypassing active protections.
  • Functionality Module Organizations - Organizes specialized utilities into domain-specific collections to structure the navigation and execution of toolsets.
  • Security Domain Organizations - Organizes specialized utilities into functional domains to structure the navigation and execution of different toolsets.
  • Data-Driven Routing - Directs target data through a series of tool wrappers to automate the progression from data gathering to exploitation.
  • Security Reconnaissance Modules - Organizes specialized hacking utilities into functional domains like reconnaissance and exploitation for structured navigation.
  • Categorized Tool Menus - Provides a categorized menu interface to launch security tools without typing manual command-line arguments.
  • Penetration Testing Frameworks - Collection of penetration testing and hacking tools.

Star history

Star history chart for manisso/fsocietyStar history chart for manisso/fsociety

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Frequently asked questions

What does manisso/fsociety do?

fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits. It functions as a wrapper that integrates external security binaries into a unified, menu-driven interface, providing a centralized system for command-line parameter mapping and execution.

What are the main features of manisso/fsociety?

The main features of manisso/fsociety are: Penetration Testing Frameworks, Information Gathering, Password Attacks, Password Cracking, Credential Cracking, Traffic Interception, Automated Exploit Execution, Web Application Exploits.

What are some open-source alternatives to manisso/fsociety?

Open-source alternatives to manisso/fsociety include: jaykali/maskphish — Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network… andresriancho/w3af — w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities… mishakorzik/allhackingtools — AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of… samratashok/nishang — Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows… owasp/nettacker — Nettacker is an automated penetration testing framework designed to orchestrate reconnaissance, port scanning, and… sofianehamlaoui/lockdoor-framework — Lockdoor-Framework is a modular penetration testing suite designed to facilitate comprehensive security assessments…

Open-source alternatives to Fsociety

Similar open-source projects, ranked by how many features they share with Fsociety.
  • jaykali/maskphishjaykali avatar

    jaykali/maskphish

    3,020View on GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Shellhackhackinghacking-tool
    View on GitHub↗3,020
  • andresriancho/w3afandresriancho avatar

    andresriancho/w3af

    4,850View on GitHub↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    Pythonappseccross-site-scriptingscanner
    View on GitHub↗4,850
mishakorzik/allhackingtoolsmishakorzik avatar

mishakorzik/AllHackingTools

5,186View on GitHub↗

AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of third-party hacking and security utilities from a single command interface. It functions as a centralized hub for network analysis, open source intelligence, penetration testing, and social engineering tools. The project provides specialized frameworks for gathering open source intelligence and searching for user profiles across social platforms. It includes toolkits for network reconnaissance, vulnerability scanning, and the execution of security exploits, as well as a social eng

Shellall-in-onebruteforcecibersecurity
View on GitHub↗5,186
  • samratashok/nishangsamratashok avatar

    samratashok/nishang

    9,951View on GitHub↗

    Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows targets. It functions as a post-exploitation toolkit and payload generator to automate attacks and manage remote targets. The project provides specialized capabilities for bypassing security controls, such as disabling the Antimalware Scan Interface and employing in-memory execution to avoid disk-based detection. It includes a variety of stealthy command and control mechanisms, utilizing non-standard channels like DNS TXT records, ICMP traffic, and webmail for communication a

    PowerShellactivedirectoryhackinginfosec
    View on GitHub↗9,951
  • See all 30 alternatives to Fsociety→