awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to nickstadb/barmie

Open-source alternatives to BaRMIe

30 open-source projects similar to nickstadb/barmie, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best BaRMIe alternative.

  • luisfontes19/xxexploiterluisfontes19 avatar

    luisfontes19/xxexploiter

    608View on GitHub↗

    Tool to help exploit XXE vulnerabilities

    TypeScript
    View on GitHub↗608
  • mzfr/liffymzfr avatar

    mzfr/liffy

    968View on GitHub↗

    Local file inclusion exploitation tool

    Python
    View on GitHub↗968
  • knownsec/pocsuite3knownsec avatar

    knownsec/pocsuite3

    3,853View on GitHub↗

    Pocsuite3 is a modular vulnerability testing framework designed for the development and execution of security assessment scripts. It provides a comprehensive toolkit for remote vulnerability verification and exploitation, enabling users to automate the identification of security flaws across network targets. The framework is built on an object-oriented scripting architecture that allows for the creation of custom security modules and plugins. It distinguishes itself through a highly extensible design that supports asynchronous task execution for large-scale infrastructure assessments, alongsi

    Pythonpentestingpythonsecurity
    View on GitHub↗3,853
  • andresriancho/w3afandresriancho avatar

    andresriancho/w3af

    4,850View on GitHub↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    Pythonappseccross-site-scriptingscanner
    View on GitHub↗4,850

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • k8gege/k8toolsk8gege avatar

    k8gege/K8tools

    6,167View on GitHub↗

    K8tools is a multi-stage attack framework that combines memory-only payload execution, credential testing, port forwarding, privilege escalation, and physical USB-based keystroke injection for comprehensive system compromise. At its core, the Ladon PowerShell module loads a multi-function scanner directly into memory, enabling command execution without writing files to disk, while supporting memory-only payload delivery that downloads and runs obfuscated shellcode or PowerShell commands to evade antivirus detection. The framework distinguishes itself through its breadth of integrated capabili

    PowerShell0daybrute-forcebypass
    View on GitHub↗6,167
  • zhzyker/exphubzhzyker avatar

    zhzyker/exphub

    4,282View on GitHub↗

    Exphub is a CVE exploit script library and enterprise software vulnerability suite designed to verify and exploit known security flaws in server environments such as WebLogic, Struts2, Tomcat, and JBoss. It functions as a remote code execution toolkit and a web shell deployment framework for triggering unauthorized command execution and establishing persistent access on remote systems. The project includes specialized utilities for internal network reconnaissance, specifically using server-side request forgery to scan for open ports and services. It further provides mechanisms for bypassing a

    Pythoncve-2020-10199cve-2020-10204cve-2020-11444
    View on GitHub↗4,282
  • guardicore/monkeyguardicore avatar

    guardicore/monkey

    7,014View on GitHub↗

    Monkey is an adversary emulation platform and breach and attack simulation tool designed to test network defenses through automated lateral movement and exploit delivery. It functions as a network security testing system that evaluates security posture by attempting to propagate through vulnerabilities and extract sensitive system credentials. The platform distinguishes itself by simulating specific real-world attacker behaviors, such as ransomware encryption, cryptojacking, and the theft of browser-stored credentials and secure shell keys. It utilizes binary hash randomization to evade antiv

    Python
    View on GitHub↗7,014
  • jaykali/maskphishjaykali avatar

    jaykali/maskphish

    3,020View on GitHub↗

    Maskphish is a comprehensive security toolkit that integrates capabilities for digital forensics, network vulnerability scanning, open-source intelligence, penetration testing, and social engineering. It functions as a multi-purpose framework for automating reconnaissance and executing security audits across diverse network environments. The project features a specialized phishing and social engineering toolkit used for cloning websites, masking URLs, and deploying deceptive pages to capture user credentials. It also includes a remote access Trojan builder for generating platform-specific exe

    Shellhackhackinghacking-tool
    View on GitHub↗3,020
  • 3xp10it/xupload3xp10it avatar

    3xp10it/xupload

    54View on GitHub↗

    xupload是一个用于自动测试上传功能是否可上传webshell的工具

    Python
    View on GitHub↗54
  • d35m0nd142/lfisuiteD35m0nd142 avatar

    D35m0nd142/LFISuite

    1,945View on GitHub↗

    Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner

    Python
    View on GitHub↗1,945
  • 3gstudent/smbtouch-scanner3gstudent avatar

    3gstudent/Smbtouch-Scanner

    138View on GitHub↗

    Author: 3gstudent

    Python
    View on GitHub↗138
  • anouarbensaad/vulnxanouarbensaad avatar

    anouarbensaad/vulnx

    2,074View on GitHub↗
    Pythonauto-exploiterbotcloudflare-detection
    View on GitHub↗2,074
  • beefproject/beefbeefproject avatar

    beefproject/beef

    10,728View on GitHub↗

    BeEF is a modular security testing environment designed for browser exploitation and web application auditing. It functions as a platform for security professionals to evaluate client-side defenses by injecting persistent scripts into web browsers, establishing a bidirectional communication channel for remote command execution and data exfiltration. The framework distinguishes itself through its ability to use compromised browser sessions as proxies to conduct internal network reconnaissance, effectively bypassing perimeter security controls. It utilizes an event-driven control interface and

    JavaScript
    View on GitHub↗10,728
  • ben-lichtman/roprB

    Ben-Lichtman/ropr

    0View on GitHub↗
    View on GitHub↗0
  • 0xhjk/dumpall0xHJK avatar

    0xHJK/dumpall

    1,578View on GitHub↗

    支持多种泄漏情况利用 - Dumpall使用方式简单 - 使用asyncio异步处理速度快

    Python
    View on GitHub↗1,578
  • almandin/fuxploiderA

    almandin/fuxploider

    0View on GitHub↗

    fuxploider is an open source penetration testing tool that automates the process of detecting and exploiting file upload forms flaws. This tool is able to detect the file types allowed to be uploaded and is able to detect which technique will work best tu upload web shells or any malicious file…

    View on GitHub↗0
  • chuhades/cms-exploit-frameworkchuhades avatar

    chuhades/CMS-Exploit-Framework

    194View on GitHub↗

    CMS Exploit Framework

    Python
    View on GitHub↗194
  • accenture/jenkins-attack-frameworkAccenture avatar

    Accenture/jenkins-attack-framework

    576View on GitHub↗

    Jenkins Attack Framework

    Python
    View on GitHub↗576
  • 1n3/xsstracer1

    1N3/XSSTracer

    0View on GitHub↗

    https://crowdshield.com

    View on GitHub↗0
  • chybeta/cmspocCHYbeta avatar

    CHYbeta/cmsPoc

    582View on GitHub↗

    项目正在重构中:cmsPoc 2.0

    Python
    View on GitHub↗582
  • cloudsploit/scanscloudsploit avatar

    cloudsploit/scans

    3,748View on GitHub↗

    This project is a multi-cloud security auditor and configuration audit tool designed to identify misconfigurations and vulnerabilities across various cloud service provider environments. It functions as a cloud security posture management tool and a vulnerability remediation engine, allowing users to scan resources against security best practices and industry compliance standards. The system distinguishes itself by combining detection with a remediation engine that executes corrective actions to fix discovered security gaps. It employs a plugin-based audit engine and a provider-agnostic abstr

    JavaScript
    View on GitHub↗3,748
  • code-scan/dzscancode-scan avatar

    code-scan/dzscan

    307View on GitHub↗

    ##新版本刚发布 可能存在一些bug,正在修复中,若有问题请提交issue带上图是最好不过辣 关注的人们啊, 被关注不是目的, 要来贡献代码或者反馈bug哦(●'◡'●)ノ♥ ##扫描的漏洞路径如下: - deafult admin & uc_server login page - develop.php - X3 - X3 tools/tools.php ~ Deafult password 188281MWWxjk - X3.1 utility/convert/index.php ~ Remote code execute - 6.x - 6.x my.php ~ SQL -…

    Python
    View on GitHub↗307
  • chenjj/espooferchenjj avatar

    chenjj/espoofer

    1,726View on GitHub↗

    An email spoofing testing tool that aims to bypass SPF/DKIM/DMARC and forge DKIM signatures.🍻

    Pythondkimdmarcdmarc-bypass
    View on GitHub↗1,726
  • enjoiz/xxeinjectorenjoiz avatar

    enjoiz/XXEinjector

    1,754View on GitHub↗

    Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.

    Ruby
    View on GitHub↗1,754
  • epinna/tplmapepinna avatar

    epinna/tplmap

    4,169View on GitHub↗

    tplmap is a security tool designed for the detection and exploitation of server-side template injection vulnerabilities. It functions as an automated scanner to identify vulnerable template engine contexts and provides a framework for achieving remote code execution. The tool focuses on translating high-level requests into engine-specific syntax to execute operating system commands and bypass application sandboxes. It further enables remote file system access, allowing users to read, write, and transfer files between a local machine and a target server. Additional capabilities include the ab

    Python
    View on GitHub↗4,169
  • charlie-belmer/nosqliCharlie-belmer avatar

    Charlie-belmer/nosqli

    409View on GitHub↗

    NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.

    Go
    View on GitHub↗409
  • hahwul/a2svhahwul avatar

    hahwul/a2sv

    634View on GitHub↗

    Auto Scanning to SSL Vulnerability

    Python
    View on GitHub↗634
  • ilmila/j2eescanilmila avatar

    ilmila/J2EEScan

    677View on GitHub↗

    J2EEScan is a plugin for Burp Suite Proxy. The goal of this plugin is to improve the test coverage during web application penetration tests on J2EE applications.

    Java
    View on GitHub↗677
  • irsdl/iis-shortname-scannerirsdl avatar

    irsdl/IIS-ShortName-Scanner

    1,679View on GitHub↗

    IIS Short Name Scanner - 2012-2023 & Still Giving...

    Java
    View on GitHub↗1,679
  • absozed/dockerpwn.pyA

    AbsoZed/DockerPwn.py

    0View on GitHub↗
    View on GitHub↗0