awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
NullArray avatar

NullArray/AutoSploit

0
View on GitHub↗
5,240 stars·1,188 forks·Python·GPL-3.0·25 views

AutoSploit

AutoSploit is an automated exploitation framework designed for discovering remote hosts and executing exploit modules at scale to establish reverse shells. It functions as a network reconnaissance tool and a remote code execution orchestrator, managing the deployment of attack modules against multiple targets.

The system features a proxy-based traffic masker that routes network requests through external servers and rotates HTTP headers and user agents to obscure the source of activity. It allows for custom exploit orchestration through the integration of external attack modules and the management of workspace connection parameters.

The framework covers target discovery via search engine queries and API integrations, as well as target list management using external files and whitelists. It further includes capabilities for session-based listener configuration to capture incoming remote connections.

Features

  • Automated Exploit Execution - Automates the execution of multiple exploit modules against targets to achieve remote code execution at scale.
  • Automated Exploitation Frameworks - Provides an integrated platform for automating remote host discovery and large-scale exploit execution.
  • Target Discovery - Discovers potentially vulnerable remote hosts using search engine queries and specialized API integrations.
  • Search Engine - Collects remote host addresses from search engines using specific keyword queries.
  • Traffic Masking Proxies - Routes network requests through external proxy servers and rotates headers to obscure the source of activity.
  • User Agent Rotation - Rotates and defines custom HTTP headers and user agents to bypass filters and mimic various clients.
  • Exploitation Workflow Managers - Orchestrates listener configurations and custom modules to automate the exploitation of remote services.
  • Exploit Orchestration Managers - Manages the deployment of specific attack modules against multiple targets using customized listeners and workspaces.
  • Attack Module Loaders - Implements a modular system to load and execute interchangeable attack payloads against target lists.
  • Remote Code Execution Tools - Runs sequences of compatible exploit modules to establish active reverse shell sessions on remote targets.
  • Reverse Shell Listeners - Sets up network listeners to capture incoming reverse shell connections from compromised targets.
  • Custom Attack Integrations - Allows the definition and integration of custom external modules to expand the range of attempted attacks.
  • Network Reconnaissance Tools - Collects remote target host addresses via search engines and APIs for security testing.
  • Penetration Testing - Executes automated attack sequences against numerous remote systems to establish reverse shells.
  • Host File Management - Provides mechanisms to load custom host files and apply whitelists to refine lists of active targets.
  • HTTP Header Spoofing - Randomizes HTTP request headers and user agents to disguise the automated nature of network requests.
  • Proxy Routing - Routes outgoing network requests through a set of external proxy servers to hide the origin IP.
  • Traffic Masking Proxies - Routes exploit traffic through proxies and rotates headers to obscure the source of network activity.
  • Network Traffic Obfuscators - Masks network traffic by routing requests through proxies and rotating user agents to evade detection.
  • Pentesting Frameworks - Automated exploitation using Shodan and Metasploit modules.

Star history

Star history chart for nullarray/autosploitStar history chart for nullarray/autosploit

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with AutoSploit

These projects share indexed features with AutoSploit. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • r0oth3x49/ghaurir0oth3x49 avatar

    r0oth3x49/ghauri

    4,032View on GitHub↗

    Ghauri is an automated SQL injection scanner and exploitation tool designed to detect and extract data from vulnerable databases. It functions as a database exfiltration framework that identifies security flaws and retrieves system banners, hostnames, and database schemas. The tool identifies boolean, error, time-based, and stacked query vulnerabilities across multiple input vectors, including HTTP headers, cookies, JSON, SOAP, and XML. It provides capabilities for automated database exfiltration and the processing of bulk target lists to identify flaws across multiple environments. The syst

    Python
    View on GitHub↗4,032
  • owasp/nettackerOWASP avatar

    OWASP/Nettacker

    5,258View on GitHub↗

    Nettacker is an automated penetration testing framework designed to orchestrate reconnaissance, port scanning, and vulnerability detection. It functions as a network reconnaissance tool and vulnerability scanner that identifies open ports, fingerprints services, and checks systems against databases of known security flaws. The framework distinguishes itself by combining a web application crawler for discovering hidden paths via fuzzing with a vulnerability management system that persists scan results in a database to track historical assessments. It also includes specialized capabilities for

    Pythonautomationbruteforcecve
    View on GitHub↗5,258
  • manisso/fsocietyManisso avatar

    Manisso/fsociety

    12,136View on GitHub↗

    fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits. It functions as a wrapper that integrates external security binaries into a unified, menu-driven interface, providing a centralized system for command-line parameter mapping and execution. The project distinguishes itself by organizing specialized utilities into domain-specific collections for structured navigation. It automates the transition between different phases of an audit by chaining reconnaissance and exploitation tools through sequential workflow automation. The fram

    Pythonbrute-force-attacksdesktopexploitation
    View on GitHub↗12,136
  • zhzyker/exphubzhzyker avatar

    zhzyker/exphub

    4,282View on GitHub↗

    Exphub is a CVE exploit script library and enterprise software vulnerability suite designed to verify and exploit known security flaws in server environments such as WebLogic, Struts2, Tomcat, and JBoss. It functions as a remote code execution toolkit and a web shell deployment framework for triggering unauthorized command execution and establishing persistent access on remote systems. The project includes specialized utilities for internal network reconnaissance, specifically using server-side request forgery to scan for open ports and services. It further provides mechanisms for bypassing a

    Pythoncve-2020-10199cve-2020-10204cve-2020-11444
    View on GitHub↗4,282
Compare all 30 related projects→

Frequently asked questions

What does nullarray/autosploit do?

AutoSploit is an automated exploitation framework designed for discovering remote hosts and executing exploit modules at scale to establish reverse shells. It functions as a network reconnaissance tool and a remote code execution orchestrator, managing the deployment of attack modules against multiple targets.

What are the main features of nullarray/autosploit?

The main features of nullarray/autosploit are: Automated Exploit Execution, Automated Exploitation Frameworks, Target Discovery, Search Engine, Traffic Masking Proxies, User Agent Rotation, Exploitation Workflow Managers, Exploit Orchestration Managers.

Which projects share features with nullarray/autosploit?

Projects with overlapping indexed features include: r0oth3x49/ghauri — Ghauri is an automated SQL injection scanner and exploitation tool designed to detect and extract data from vulnerable… owasp/nettacker — Nettacker is an automated penetration testing framework designed to orchestrate reconnaissance, port scanning, and… manisso/fsociety — fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits.… zhzyker/exphub — Exphub is a CVE exploit script library and enterprise software vulnerability suite designed to verify and exploit… mantvydasb/redteaming-tactics-and-techniques — This project is a red teaming knowledge base and offensive security playbook designed to simulate adversary behavior.… speedyapply/jobspy — JobSpy is a job board scraper and listing aggregator designed to extract employment opportunities from multiple…