awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

15 个仓库

Awesome GitHub RepositoriesPenetration Testing Frameworks

Software environments used to simulate cyber attacks for identifying system vulnerabilities.

Explore 15 awesome GitHub repositories matching security & cryptography · Penetration Testing Frameworks. Refine with filters or upvote what's useful.

Awesome Penetration Testing Frameworks GitHub Repositories

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • z4nzu/hackingtoolZ4nzu 的头像

    Z4nzu/hackingtool

    77,515在 GitHub 上查看↗

    This project is a comprehensive cybersecurity tool collection designed to support security research, penetration testing, and vulnerability assessment. It functions as a unified penetration testing suite, providing a centralized environment where professionals can access a wide range of offensive security utilities to identify system weaknesses and study attack vectors. The platform distinguishes itself through a modular architecture that aggregates disparate security scripts into a single, hierarchical command-line interface. It simplifies the management of these utilities by integrating ext

    Simulates cyber attacks through a collection of integrated frameworks to identify potential system weaknesses.

    Pythonallinonehackingtoolbesthackingtoolctf-tools
    在 GitHub 上查看↗77,515
  • usestrix/strixusestrix 的头像

    usestrix/strix

    20,138在 GitHub 上查看↗

    Strix is an automated security research and vulnerability scanning platform that leverages language models to orchestrate complex security analysis tasks. It functions as a comprehensive framework for penetration testing and continuous security integration, allowing users to embed automated vulnerability research directly into development pipelines or execute it within isolated, containerized environments. The platform distinguishes itself through a multi-agent orchestration engine that coordinates specialized autonomous agents to perform parallel security assessments. By integrating LLM-agno

    Coordinates multi-agent workflows, browser automation, and traffic analysis to automate penetration testing and vulnerability validation.

    Pythonagentsartificial-intelligencecybersecurity
    在 GitHub 上查看↗20,138
  • ethicalhack3r/dvwaethicalhack3r 的头像

    ethicalhack3r/DVWA

    13,236在 GitHub 上查看↗

    DVWA is a vulnerable web application sandbox and PHP security training environment. It serves as a deployable penetration testing target and an OWASP Top 10 lab designed for practicing exploits and simulating common web security vulnerabilities. The application allows users to adjust security difficulty levels to match their skill level and toggle between different SQL database engines to test how various systems handle injection attacks. It includes a mechanism to disable authentication, enabling automated security tools to interact directly with the environment. The project provides capabi

    Creates a safe, isolated environment for testing security tools and manual attack methods against known flaws.

    PHP
    在 GitHub 上查看↗13,236
  • manisso/fsocietyManisso 的头像

    Manisso/fsociety

    12,136在 GitHub 上查看↗

    fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits. It functions as a wrapper that integrates external security binaries into a unified, menu-driven interface, providing a centralized system for command-line parameter mapping and execution. The project distinguishes itself by organizing specialized utilities into domain-specific collections for structured navigation. It automates the transition between different phases of an audit by chaining reconnaissance and exploitation tools through sequential workflow automation. The fram

    Conducting a full security audit from initial reconnaissance and vulnerability scanning to exploiting services and maintaining system access.

    Pythonbrute-force-attacksdesktopexploitation
    在 GitHub 上查看↗12,136
  • empireproject/empireEmpireProject 的头像

    EmpireProject/Empire

    7,813在 GitHub 上查看↗

    Empire is a command and control framework and post-exploitation toolkit used for network penetration testing. It serves as a centralized platform for coordinating remote agent communication and automating the delivery of security testing payloads to target systems. The project provides a suite of modules for host reconnaissance, lateral movement, and credential harvesting across corporate environments. It functions as a remote administration tool to maintain persistence and execute commands on compromised hosts. The framework incorporates capabilities for agent orchestration and the executio

    Serves as a comprehensive software environment for simulating cyber attacks to identify system vulnerabilities.

    PowerShell
    在 GitHub 上查看↗7,813
  • fireeye/commando-vmfireeye 的头像

    fireeye/commando-vm

    7,668在 GitHub 上查看↗

    Commando-VM is a Windows penetration testing distribution and offensive security toolkit. It provides a specialized virtual machine environment loaded with a curated suite of security auditing and exploitation tools designed for red teaming operations. The project facilitates the creation of red team infrastructure and security audit environments. It focuses on windows security auditing and penetration testing to help simulate adversary behavior and identify exploitable security flaws. The environment is established through script-based provisioning and modular toolset deployment. This proce

    Ships a pre-configured environment for simulating cyber attacks to identify vulnerabilities within Windows systems.

    PowerShell
    在 GitHub 上查看↗7,668
  • owasp/nettackerOWASP 的头像

    OWASP/Nettacker

    5,258在 GitHub 上查看↗

    Nettacker 是一个自动化渗透测试框架,旨在编排侦察、端口扫描和漏洞检测。它作为一个网络侦察工具和漏洞扫描器,能够识别开放端口、指纹识别服务,并根据已知安全漏洞数据库检查系统。 该框架的独特之处在于结合了用于通过模糊测试发现隐藏路径的 Web 应用爬虫,以及一个将扫描结果持久化到数据库以跟踪历史评估的漏洞管理系统。它还包含子域名枚举、凭据暴力破解以及通过代理路由流量以实现匿名化的专业功能。 该系统涵盖了广泛的安全能力,包括网络资产发现、多协议服务审计和配置审计。它支持跨 IP 范围和 CIDR 块的多目标扫描,并提供多种格式的安全报告生成工具。 通过基于 REST 的接口可实现程序化控制,从而将该框架集成到安全流水线和自动化流程中。

    Provides a complete software environment to automate the discovery and exploitation of network security weaknesses.

    Pythonautomationbruteforcecve
    在 GitHub 上查看↗5,258
  • aquasecurity/kube-hunteraquasecurity 的头像

    aquasecurity/kube-hunter

    5,064在 GitHub 上查看↗

    Kube-hunter 是一个用于 Kubernetes 集群的安全扫描器和漏洞猎手。它作为一个云原生渗透工具运行,旨在通过模拟攻击者技术来识别安全弱点、基础设施配置错误和可利用的漏洞。 该工具以其双模式扫描引擎而著称,该引擎既执行远程外部探测,也执行内部网络扫描。它具有基于身份的模拟功能,允许它使用服务账户令牌和 Pod 身份来模拟来自特定集群角色的安全访问,并确定容器受损的潜在影响范围。 该项目涵盖了广泛的安全评估能力,包括集群漏洞扫描、内部网络拓扑映射和合规性验证。它可以检测暴露的密钥、分析基础设施模板中的配置错误,并执行主动利用尝试以验证发现的漏洞是否可被利用。 该应用程序被打包为独立的可执行文件,以在部署期间消除运行时依赖。

    Simulates attacker techniques and pod compromises to identify lateral movement paths and exploitability.

    Python
    在 GitHub 上查看↗5,064
  • antswordproject/antswordAntSwordProject 的头像

    AntSwordProject/antSword

    4,620在 GitHub 上查看↗

    AntSword 是一个跨平台的 Web 管理器和渗透测试框架,专为多个远程网站环境的集中式管理而设计。它作为一个远程网站管理工具和 Web Shell 管理工具,允许用户从单个界面组织和控制不同的 Web 服务器。 该项目为安全研究人员提供了一个工具包,用于执行授权的安全审计并识别漏洞。它支持 Web 渗透测试和安全研究工作流,以分析 Web 应用行为并发现潜在的漏洞利用。 该系统涵盖了远程网站管理和跨平台 Web 管理的广泛功能,能够跨不同的操作系统和托管平台执行管理任务和安全检查。

    Serves as a software environment for simulating attacks to identify vulnerabilities during authorized audits.

    JavaScript
    在 GitHub 上查看↗4,620
  • htr-tech/nexphisherhtr-tech 的头像

    htr-tech/nexphisher

    3,829在 GitHub 上查看↗

    Nexphisher is a command-line security utility and social engineering simulation framework designed for capturing credentials during authorized security audits. It functions as a tool for credential harvesting and penetration testing to evaluate organizational resilience against phishing attacks. The system orchestrates the deployment of realistic login pages and integrates network tunneling to expose local web servers to the public internet. This allows for remote security testing and the execution of controlled social engineering simulations. The framework provides capabilities for template

    Provides a framework for conducting authorized security audits by deploying temporary deceptive web interfaces.

    Shellhtr-techlinuxphisher
    在 GitHub 上查看↗3,829
  • tuhinshubhra/red_hawkTuhinshubhra 的头像

    Tuhinshubhra/RED_HAWK

    3,695在 GitHub 上查看↗

    RED_HAWK is a penetration testing framework and reconnaissance suite designed for information gathering and vulnerability assessment. It provides a toolkit for infrastructure reconnaissance, technology stack detection, automated web spidering, and security scanning. The project distinguishes itself through a multi-stage reconnaissance pipeline that maps attack surfaces. This includes DNS-based infrastructure mapping to resolve network layouts and pattern-based detection to identify specific content management systems and server stacks. The system covers a broad range of capabilities includin

    Provides a comprehensive software environment for simulating attacks and identifying system vulnerabilities.

    PHPadmin-scannerbackups-findercloudflare-detection
    在 GitHub 上查看↗3,695
  • securethisshit/winpwnSecureThisShit 的头像

    SecureThisShit/WinPwn

    3,673在 GitHub 上查看↗

    WinPwn is a Windows penetration testing framework designed for conducting internal security assessments and privilege escalation. It functions as a suite for Active Directory security auditing, credential extraction, and the execution of privilege escalation scripts. The toolset enables the automation of SMB relay attacks to intercept and reuse authentication hashes. It provides specialized capabilities for retrieving passwords and hashes from system memory, registries, and browsers using obfuscated techniques to avoid detection. The framework covers broad capability areas including domain a

    Provides a comprehensive framework for conducting internal security assessments and privilege escalation on Windows environments.

    PowerShell
    在 GitHub 上查看↗3,673
  • samsar4/ethical-hacking-labsSamsar4 的头像

    Samsar4/Ethical-Hacking-Labs

    3,397在 GitHub 上查看↗

    Ethical-Hacking-Labs is a comprehensive cybersecurity training curriculum and lab suite designed for learning penetration testing, network analysis, and offensive security techniques. It provides a structured environment for practicing the full attack lifecycle, from initial reconnaissance and scanning to exploitation and post-compromise analysis. The project provides instructional materials and guided exercises that cover specific technical domains, including open source intelligence research and network security courseware. It includes a practical workbook for identifying system vulnerabili

    Provides a comprehensive framework for simulating cyberattacks across the full lifecycle from scanning to covering tracks.

    ethical-hacking-labshackinglinux
    在 GitHub 上查看↗3,397
  • seemoo-lab/nexmonseemoo-lab 的头像

    seemoo-lab/nexmon

    2,750在 GitHub 上查看↗

    Nexmon is a suite of operational tools designed for firmware patching, ROM extraction, frame injection, and enabling monitor mode on wireless hardware. It provides utilities to modify wireless chip firmware to unlock low-level hardware capabilities not supported by official drivers. The project enables the activation of monitor mode for capturing raw network packets with radiotap headers and allows for the transmission of custom-crafted wireless frames. It includes tools for dumping the read-only memory of wireless chips to facilitate reverse engineering and analysis of hardware behavior. Th

    Enables the injection of custom wireless frames to test network security vulnerabilities.

    Cbroadcomfirmwareframework
    在 GitHub 上查看↗2,750
  • sofianehamlaoui/lockdoor-frameworkSofianeHamlaoui 的头像

    SofianeHamlaoui/Lockdoor-Framework

    1,540在 GitHub 上查看↗

    Lockdoor-Framework is a modular penetration testing suite designed to facilitate comprehensive security assessments through a centralized command-line interface. It functions as an integrated platform for reconnaissance, vulnerability scanning, and the exploitation of target systems, providing a unified environment for managing complex security workflows. The framework distinguishes itself through a modular plugin architecture that allows for the extension of core capabilities without modifying the underlying codebase. It incorporates an automated reconnaissance pipeline to map attack surface

    Provides a modular suite for executing comprehensive security assessments, reconnaissance, and exploitation workflows within a unified command-line environment.

    Pythonblackarch-packagesblueteamingcyber-security
    在 GitHub 上查看↗1,540
  1. Home
  2. Security & Cryptography
  3. Vulnerability Assessment and Testing
  4. Penetration Testing Frameworks