awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
yaklang avatar

yaklang/yakit

0
View on GitHub↗
7,386 stars·807 forks·TypeScript·AGPL-3.0·29 views

Yakit

Yakit is a comprehensive cybersecurity all-in-one platform designed for security assessments. It integrates a suite of core tools including an HTTP interception proxy for real-time traffic modification, an out-of-band interaction detector for verifying remote command execution via TCP, DNSLog, and ICMP, and a reverse shell manager for controlling remote server connections.

The platform is distinguished by its dedicated security scripting environment, which allows for the development and execution of custom logic and plugins using a specialized high-performance language. It further extends functionality through a plugin framework and a centralized marketplace for integrating third-party tools.

The toolset covers a wide range of capability areas, including web application fuzzing with dynamic parameter generation and automated vulnerability scanning using proof-of-concept templates. It also provides advanced network utilities such as multi-protocol port multiplexing and reverse-shell tunneling to bridge internal network services to the public internet.

The system supports remote backend management, enabling a local client to execute security tasks across different network environments.

Features

  • Cybersecurity Platforms - Provides a unified environment for conducting comprehensive security assessments, integrating traffic interception and vulnerability scanning.
  • Web Application Fuzzers - Ships a comprehensive web application fuzzer using dynamic data generation to identify security vulnerabilities.
  • HTTP Traffic Inspection - Runs an HTTP proxy to capture, decode, and modify requests and responses in real time.
  • Traffic Interception Tools - Provides utilities for capturing and modifying HTTP traffic in real time to analyze and replay packets.
  • Traffic Proxying - Intercepts and hijacks HTTP traffic via a proxy to manually edit, track, and replay packets.
  • Security Logic Runtimes - Includes a dedicated high-performance scripting environment for developing and executing custom security logic and plugins.
  • Man-in-the-Middle Frameworks - Provides a man-in-the-middle proxy to intercept, decode, and modify HTTP requests and responses in real time.
  • Out-of-Band Security Testing - Monitors TCP, DNSLog, and ICMP callbacks to verify command execution or network egress on target systems.
  • Parameter Fuzzing - Implements active testing of application input fields using malformed data to find injection points.
  • Reverse Shells - Ships a reverse shell manager to control remote server connections and deliver exploitation payloads.
  • Security Scripting Frameworks - Provides a dedicated security scripting environment for developing and executing custom logic and plugins.
  • Security Tool Development - Supports the development of custom security tools and automation using a specialized high-performance language.
  • Out-of-Band Interaction Monitoring - Monitors TCP, DNSLog, and ICMP callbacks to verify remote command execution via out-of-band interaction.
  • Vulnerability Assessment and Testing - Automates the identification and verification of security flaws using PoC templates and custom scripts.
  • Scanning Template Libraries - Integrates a library of proof-of-concept templates to automate the detection of known security flaws.
  • Real-Time Modifications - Intercepts network requests and responses in real-time to view, edit, and replay data packets.
  • HTTP Fuzzing - Provides tools for generating permutations of HTTP requests to discover hidden endpoints and test input validation.
  • Fuzzing Parameter Tags - Uses a tagging system and external dictionaries to generate malformed data for automated HTTP fuzzing.
  • Security Tool Orchestrators - Provides a unified interface to orchestrate and manage various cybersecurity tools during assessments.
  • Internal Network Bridging - Maps internal network services to the public internet using reverse-shell tunneling to facilitate lateral movement.
  • Multi-Protocol Port Multiplexing - Implements multi-protocol port multiplexing to handle diverse network callbacks on a single listening port.
  • Reverse Tunnels - Provides reverse-shell tunneling to map internal network services to the public internet for remote access.
  • Automated Vulnerability Detection - Runs proof-of-concept scripts and templates to automatically identify known security flaws in target web services.
  • Input Parameter Fuzzers - Includes a web application fuzzer for discovering vulnerabilities via dynamic parameter generation and dictionary attacks.
  • Proof of Concept Execution - Integrates an ecosystem of proof-of-concept templates to run security probes and verify vulnerabilities on target systems.
  • Remote Security Backend Management - Allows a local client to connect to and manage a remote backend for executing security tasks across networks.
  • Remote Security Backends - Connects local clients to remote backends to facilitate security tasks across different network environments.
  • Connection Control - Controls remote servers through reverse shells and delivers protocol payloads to exploit vulnerabilities upon connection.
  • Shell Management - Controls remote server shells through a listener that provides a native terminal experience.
  • HTTP Parameter Brute Forcing - Provides automated brute-forcing of HTTP parameters using wordlists and dynamic tags to discover accepted parameters.
  • Plugin Frameworks - Ships a plugin framework that allows expanding the toolset using a dedicated scripting language.
  • Automated Exploitation Frameworks - All-in-one security testing platform for automated penetration testing.
  • Penetration Testing Tools - Integrated security testing platform for web applications.

Star history

Star history chart for yaklang/yakitStar history chart for yaklang/yakit

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Yakit

These projects share indexed features with Yakit. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • six2dez/reconftwsix2dez avatar

    six2dez/reconftw

    7,226View on GitHub↗

    reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the discovery, mapping, and monitoring of external digital assets. It operates as a modular tool-chain pipeline that coordinates a sequence of security tools to perform intelligence gathering and vulnerability scanning. The project distinguishes itself through a cloud-native deployment model that parallelizes scanning workloads across a fleet of remote VPS instances to bypass local resource constraints. It utilizes container-based environment isolation to ensure consistent executio

    Shellbug-bountybugbountybugbounty-tool
    View on GitHub↗7,226
  • xmendez/wfuzzxmendez avatar

    xmendez/wfuzz

    6,519View on GitHub↗

    Wfuzz is a web application fuzzing framework that automates the injection of payloads into HTTP requests to discover hidden resources, parameters, and vulnerabilities. It functions as a content discovery scanner, a brute-force tool for credential guessing, and a plugin-based vulnerability scanner, all within a single modular system. The tool distinguishes itself through its plugin-based extensibility, allowing custom Python modules to add new payload sources, output printers, or scanning logic without modifying core code. It supports concurrent request dispatch using thread-based parallelism

    Python
    View on GitHub↗6,519
  • w-digital-scanner/w13scanw-digital-scanner avatar

    w-digital-scanner/w13scan

    1,945View on GitHub↗

    W13scan is an automated vulnerability assessment tool designed to identify security flaws in web applications through a modular plugin architecture. It functions as a scanning engine that executes specialized security logic against web endpoints to detect injection flaws, information leaks, and configuration errors. The platform distinguishes itself by combining active probing with passive traffic analysis and out-of-band detection. It utilizes a callback-based service to verify blind vulnerabilities that do not provide immediate feedback, and it operates as a proxy to intercept and inspect l

    Smartypassive-vulnerability-scannersecurity-tools
    View on GitHub↗1,945
  • zan8in/afrogzan8in avatar

    zan8in/afrog

    4,182View on GitHub↗

    afrog is an HTTP vulnerability scanner and web vulnerability management system that identifies security flaws and known CVEs using a YAML-based rule engine. It functions as a payload generator and scanner, comparing server responses against detection rules to find unauthorized access points. The project provides a framework for out-of-band security testing, detecting blind vulnerabilities by triggering and verifying external DNS or HTTP callbacks. Beyond web traffic, it includes a protocol fuzzer capable of executing multi-step read and write sequences over raw TCP and SSL sockets to identify

    Goafrogbug-bountypenetration-testing
    View on GitHub↗4,182
Compare all 30 related projects→

Frequently asked questions

What does yaklang/yakit do?

Yakit is a comprehensive cybersecurity all-in-one platform designed for security assessments. It integrates a suite of core tools including an HTTP interception proxy for real-time traffic modification, an out-of-band interaction detector for verifying remote command execution via TCP, DNSLog, and ICMP, and a reverse shell manager for controlling remote server connections.

What are the main features of yaklang/yakit?

The main features of yaklang/yakit are: Cybersecurity Platforms, Web Application Fuzzers, HTTP Traffic Inspection, Traffic Interception Tools, Traffic Proxying, Security Logic Runtimes, Man-in-the-Middle Frameworks, Out-of-Band Security Testing.

Which projects share features with yaklang/yakit?

Projects with overlapping indexed features include: six2dez/reconftw — reconftw is an attack surface management framework and reconnaissance workflow orchestrator designed to automate the… xmendez/wfuzz — Wfuzz is a web application fuzzing framework that automates the injection of payloads into HTTP requests to discover… zan8in/afrog — afrog is an HTTP vulnerability scanner and web vulnerability management system that identifies security flaws and… w-digital-scanner/w13scan — W13scan is an automated vulnerability assessment tool designed to identify security flaws in web applications through… andresriancho/w3af — w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities… bettercap/bettercap — Bettercap is a modular framework designed for network reconnaissance, security testing, and the execution of…