All tags
Catalogue tag

#penetration-testing

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

25 records
Tagged “penetration-testing”Ranked by health index
Go · Maven
76Goodhealth index
praetorian-inc/titus
High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.
Go · Java★ 638Jul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 1.13.0
npm
75Goodhealth index
CyberStrikeus/CyberStrike
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
TypeScript · Python★ 1,266↓ 2,624/moJul 23, 2026
AGPL-3.0Jul 23, 2026 · metrics 1.13.0
PyPI
75Goodhealth index
usestrix/strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Python · TypeScript★ 43.2KJul 21, 2026
Apache-2.0Jul 21, 2026 · metrics 1.13.0
npm
71Goodhealth index
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript · TypeScript · CSS★ 763↓ 2,247/moJul 15, 2026
MITJul 15, 2026 · metrics 1.13.0
npm · RubyGems
71Goodhealth index
dradis/dradis-ce
Dradis Framework: Collaboration and reporting for IT Security teams
Ruby · HTML★ 827↓ 0/moJul 14, 2026
GPL-2.0Jul 14, 2026 · metrics 1.13.0
Go · npm
71Goodhealth index
xalgord/xalgorix
Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.
Go · TypeScript★ 768Jul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
npm
70Goodhealth index
KeygraphHQ/shannon
Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
TypeScript★ 45.9KJul 20, 2026
AGPL-3.0Jul 20, 2026 · metrics 1.13.0
npm
69Moderatehealth index
pensarai/apex
AI-powered offensive security testing using autonomous agents, directly in your terminal.
TypeScript★ 297↓ 10.1K/moJul 15, 2026
Apache-2.0Jul 15, 2026 · metrics 1.13.0
PyPI
68Moderatehealth index
gamehunterkaan/autopwn-suite
AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.
Python · JavaScript★ 1,093↓ 188/moJul 17, 2026
Custom licenseJul 17, 2026 · metrics 1.13.0
RubyGems
66Moderatehealth index
0dayinc/pwn
PWN is an open security automation framework that aims to stand on the shoulders of security giants, promoting trust and innovation.
Ruby★ 73↓ 0/moJul 14, 2026
MITJul 14, 2026 · metrics 1.13.0
Go
66Moderatehealth index
zan8in/afrog
A Security Tool for Bug Bounty, Pentest and Red Teaming.
Go · HTML★ 4,341Jul 18, 2026
MITJul 18, 2026 · metrics 1.13.0
Go
64Moderatehealth index
go-appsec/interactsh-lite
Dependency-minimal Interactsh protocol client and server for out-of-band testing (OOB / OAST)
Go★ 3↓ 0/moJul 14, 2026
MITJul 14, 2026 · metrics 1.13.0
Go
64Moderatehealth index
go-appsec/toolbox
Collaborative application security testing between humans and agents via CLI and MCP
Go★ 37Jul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
Go
61Moderatehealth index
go-harden/interactsh-lite
Dependency-minimal Interactsh protocol client and server for out-of-band testing (OOB / OAST)
Go★ 3Jul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
Go
60Moderatehealth index
ddddddO/packemon
Packet monster (っ‘-’)╮=͟͟͞͞◒ ヽ( '-'ヽ) TUI tool for sending packets of arbitrary input and monitoring packets on any network interfaces (default: eth0). Windows/macOS/Linux
Go★ 305Jul 20, 2026
BSD-2-ClauseJul 20, 2026 · metrics 1.13.0
Go
58Moderatehealth index
nodepassproject/nodepass
A secure, efficient TCP/UDP tunneling solution that delivers fast, reliable access across network restrictions using pre-established TCP/QUIC/WebSocket or HTTP/2 connections.
Go★ 267↓ 0/moJul 14, 2026
BSD-3-ClauseJul 14, 2026 · metrics 1.13.0
RubyGems
54Moderatehealth index
urbanadventurer/WhatWeb
Next generation web scanner
Ruby★ 6,735Jul 22, 2026
GPL-2.0Jul 22, 2026 · metrics 1.13.0
npm
53Moderatehealth index
Hyperyond/Hover
Open-source Vibe Testing suite: an MCP server for the coding agent you already run, a VS Code review cockpit, and CI. Your agent explores your app and crystallizes each flow into a plain @playwright/test spec you own — record == replay, runs in CI with zero AI.
TypeScript★ 11↓ 0/moJul 14, 2026
Apache-2.0Jul 14, 2026 · metrics 1.13.0
npm
52Moderatehealth index
3516634930/Payloader
渗透测试Payload速查平台 | Pentest Payload Quick Reference | XSS/SQLi/SSRF/RCE | React+TypeScript
TypeScript · JavaScript★ 463Jul 19, 2026
AGPL-3.0Jul 19, 2026 · metrics 1.13.0
Go
45At riskhealth index
safetylab/ShadowSecurityScanner
Free, open-source network vulnerability scanner & penetration testing tool that ranks findings by real-world exploitability (EPSS + CISA KEV). Single desktop app for Windows, macOS, Linux. No cloud, no telemetry. MIT.
Go★ 0Jul 21, 2026
MITJul 21, 2026 · metrics 1.13.0
npm
43At riskhealth index
nsasoft/nsauditor-ai
NSAuditor AI — Open-source, AI-powered network security scanner. 27 plugins, CVE matching, MITRE ATT&CK mapping, verified vulnerabilities, continuous monitoring, MCP integration. Zero data exfiltration. MIT licensed.
JavaScript★ 19↓ 5,644/moJul 15, 2026
MITJul 15, 2026 · metrics 1.13.0
PyPI
38At riskhealth index
hackerest/pwneye
Your ONVIF and RTSP camera companion for discovering and hacking real-world security cameras 🎥
Python★ 45Jul 18, 2026
GPL-3.0Jul 18, 2026 · metrics 1.13.0
npm
35At riskhealth index
nsasoft/nsauditor-ai-agent-skill
AI Agent Skill for NSAuditor AI — gives any AI coding agent built-in knowledge of NSAuditor's MCP tools, schemas, plugins, and security audit workflows. Works with Claude Code, Cursor, Windsurf, and any MCP-aware agent.
Mixed★ 3↓ 4,001/moJul 15, 2026
MITJul 15, 2026 · metrics 1.13.0
Go
34At riskhealth index
willygoid/fofa-grabber
A powerful Golang tool to fetch and export FOFA.info search results via API with real-time saving, concurrent requests, and multiple output formats (CSV, JSON, TXT)
Go★ 0Jul 17, 2026
MITJul 17, 2026 · metrics 1.13.0
Go
25Criticalhealth index
ps1-blacklist/wpfather
WPFather - WordPress Vulnerability Scanner & Security Recon Tool with 16 Modules | Zero Config Single Binary
Go★ 0Jul 16, 2026
Custom licenseJul 16, 2026 · metrics 1.13.0