awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

17 个仓库

Awesome GitHub RepositoriesPenetration Testing Tools

Comprehensive toolkits and browser extensions for web application security testing.

Explore 17 awesome GitHub repositories matching part of an awesome list · Penetration Testing Tools. Refine with filters or upvote what's useful.

Awesome Penetration Testing Tools GitHub Repositories

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • immersive-translate/immersive-translateimmersive-translate 的头像

    immersive-translate/immersive-translate

    17,917在 GitHub 上查看↗

    Immersive Translate is a browser-based translation tool that integrates third-party translation engines and large language models to provide automated, real-time text conversion directly within the web interface. It functions as a browser extension that intercepts and modifies web content, injecting translated text nodes into the document object model to maintain original page layouts and styling. The project distinguishes itself through its granular control over the translation process, allowing users to define site-specific rules, manage custom terminology glossaries, and customize translat

    Translation tool for analyzing foreign language web content.

    chrome-extensionsafari-extensiontranslation
    在 GitHub 上查看↗17,917
  • yaklang/yakityaklang 的头像

    yaklang/yakit

    7,386在 GitHub 上查看↗

    Yakit is a comprehensive cybersecurity all-in-one platform designed for security assessments. It integrates a suite of core tools including an HTTP interception proxy for real-time traffic modification, an out-of-band interaction detector for verifying remote command execution via TCP, DNSLog, and ICMP, and a reverse shell manager for controlling remote server connections. The platform is distinguished by its dedicated security scripting environment, which allows for the development and execution of custom logic and plugins using a specialized high-performance language. It further extends fun

    Integrated security testing platform for web applications.

    TypeScriptblueteamburpsuiteexploit
    在 GitHub 上查看↗7,386
  • zero-peak/zeroomegazero-peak 的头像

    zero-peak/ZeroOmega

    6,954在 GitHub 上查看↗

    ZeroOmega is a web-based proxy orchestrator and manager designed for real-time updates to active network gateways. It functions as a system for configuring, storing, and switching between different network proxy profiles to direct internet traffic. The project features a PAC script generator that translates structured proxy profile data into auto-configuration files. These scripts automate network routing decisions by matching requested URLs against defined patterns. Administration is handled through a browser-based interface that allows for the modification of routing rules and the manageme

    Proxy management extension for browser-based testing.

    CoffeeScriptproxyswitchyomegazeroomega
    在 GitHub 上查看↗6,954
  • callumlocke/json-formattercallumlocke 的头像

    callumlocke/json-formatter

    4,118在 GitHub 上查看↗

    这是一个基于 Web 的 JSON 格式化和可视化工具,专为结构化调试和数据探索而设计。它将原始 JSON 字符串转换为具有语法高亮、缩进指南和可折叠节点的易读树状结构。 该工具提供了一个数据可视化器,用于比较原始服务器响应与解析后的表示形式。它还包含一个控制台导出器,将解析后的 JSON 数据作为全局变量发送到浏览器开发者控制台,以便立即进行检查和操作。 该系统涵盖了 API 响应检查和 JSON 结构分析,允许用户在原始文本和格式化视图之间切换,以验证复杂的嵌套数据。

    Extension for formatting and inspecting JSON responses.

    TypeScript
    在 GitHub 上查看↗4,118
  • gh0stkey/haegh0stkey 的头像

    gh0stkey/HaE

    4,034在 GitHub 上查看↗

    HaE is a network traffic analysis tool designed to extract, classify, and highlight specific data fragments within network messages and HTTP traffic. It functions as an HTTP data extractor and traffic content filter, utilizing a network metadata aggregator to centralize highlighted data fragments and annotations for analysis. The tool identifies high-value network packets by mapping classification results to visual color markers and employs a modular classification system to isolate data fragments from binary or text streams. It distinguishes the severity of matched data by piping extracted c

    Burp Suite extension for highlighting and extracting sensitive data.

    Javabughunterburpsuitedata-security
    在 GitHub 上查看↗4,034
  • whwlsfb/burpcryptowhwlsfb 的头像

    whwlsfb/BurpCrypto

    1,633在 GitHub 上查看↗

    BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite). 支持多种加密算法或直接执行JS代码的用于爆破前端加密的BurpSuite插件

    Burp Suite extension for handling various cryptographic operations.

    Javaburp-extensionsburp-pluginburpcrypto
    在 GitHub 上查看↗1,633
  • moustachauve/cookie-editorMoustachauve 的头像

    Moustachauve/cookie-editor

    1,572在 GitHub 上查看↗

    A powerful browser extension to create, edit and delete cookies

    Extension for managing and manipulating browser cookies.

    JavaScriptandroidbrowser-extensionchrome
    在 GitHub 上查看↗1,572
  • f0ng/autodecoderf0ng 的头像

    f0ng/autoDecoder

    1,410在 GitHub 上查看↗

    Burp插件,根据自定义来达到对数据包的处理(适用于加解密、爆破等),类似mitmproxy,不同点在于经过了burp中转,在自动加解密的基础上,不影响APP、网站加解密正常逻辑等。

    Burp Suite extension for automated request/response decoding.

    Javaburpburp-pluginburpsuite-extender
    在 GitHub 上查看↗1,410
  • simov/markdown-viewersimov 的头像

    simov/markdown-viewer

    1,420在 GitHub 上查看↗

    Extension for rendering markdown documentation during assessments.

    JavaScriptbrowser-extensionchromechrome-extension
    在 GitHub 上查看↗1,420
  • f6jo/routevulscanF6JO 的头像

    F6JO/RouteVulScan

    1,323在 GitHub 上查看↗

    Burpsuite - Route Vulnerable Scanning 递归式被动检测脆弱路径的burp插件

    Burp Suite extension for scanning routing-related vulnerabilities.

    Java
    在 GitHub 上查看↗1,323
  • whwlsfb/log4j2scanwhwlsfb 的头像

    whwlsfb/Log4j2Scan

    835在 GitHub 上查看↗

    Log4j2 RCE Passive Scanner plugin for BurpSuite

    Burp Suite scanner for identifying Log4j vulnerabilities.

    Java
    在 GitHub 上查看↗835
  • youmulijiang/haetoyakitY

    youmulijiang/HaeToYakit

    0在 GitHub 上查看↗

    Integration tool between different security testing platforms.

    在 GitHub 上查看↗0
  • mrknow001/burpappletpentesterM

    mrknow001/BurpAppletPentester

    0在 GitHub 上查看↗

    Burp Suite extension for decrypting session keys.

    在 GitHub 上查看↗0
  • ghr07h/heimdallrG

    Ghr07h/Heimdallr

    0在 GitHub 上查看↗

    Browser extension for detecting honeypot interactions.

    在 GitHub 上查看↗0
  • dpacassi/disable-javascriptD

    dpacassi/disable-javascript

    0在 GitHub 上查看↗

    Extension for testing web application behavior without JavaScript.

    在 GitHub 上查看↗0
  • 0140454/hackbar0

    0140454/hackbar

    0在 GitHub 上查看↗

    Browser extension for manual web application security testing.

    在 GitHub 上查看↗0
  • residuallaugh/findsomethingR

    ResidualLaugh/FindSomething

    0在 GitHub 上查看↗

    Tool for discovering sensitive information in web source code.

    在 GitHub 上查看↗0
  1. Home
  2. Part of an Awesome List
  3. Developer Tools
  4. Penetration Testing Tools