All tags
Catalogue tag

#penetration-testing

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

41 records
Tagged “penetration-testing”Ranked by health index
PyPI · Go · npm
94Exceptionalhealth index
PurpleAILAB/Decepticon
Autonomous Hacking Agent for Red Team
Python · Cypher★ 5,348↓ 7,794/moAug 28, 2026
Apache-2.0Aug 28, 2026 · metrics 2.10.0
npm
91Excellenthealth index
CyberStrikeus/CyberStrike
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
TypeScript · Python★ 1,266↓ 2,624/moJul 23, 2026
AGPL-3.0Jul 23, 2026 · metrics 2.10.0
Go · Maven
91Excellenthealth index
praetorian-inc/titus
High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.
Go · Java★ 638Jul 19, 2026
Apache-2.0Jul 19, 2026 · metrics 2.10.0
PyPI
91Excellenthealth index
usestrix/strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Python · Go · TypeScript★ 48.3KAug 5, 2026
Apache-2.0Aug 5, 2026 · metrics 2.10.0
npm · RubyGems
90Excellenthealth index
dradis/dradis-ce
Dradis Framework: Collaboration and reporting for IT Security teams
Ruby · HTML★ 841Sep 5, 2026
GPL-2.0Sep 5, 2026 · metrics 2.10.0
npm
88Excellenthealth index
asamassekou10/ship-safe
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and DMCA-flagged AI dependencies.
JavaScript★ 830↓ 5,893/moSep 6, 2026
MITSep 6, 2026 · metrics 2.10.0
Go
87Excellenthealth index
goshs-labs/goshs
Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP callbacks · TLS · Auth · Share links. A powerful python3 -m http.server replacement.
Go · JavaScript★ 953Aug 13, 2026
MITAug 13, 2026 · metrics 2.10.0
npm
87Excellenthealth index
pensarai/apex
AI-powered offensive security testing using autonomous agents, directly in your terminal.
TypeScript★ 307↓ 7,921/moSep 6, 2026
Apache-2.0Sep 6, 2026 · metrics 2.10.0
Go
87Excellenthealth index
praetorian-inc/brutus
Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native nerva/naabu pipeline integration.
Go★ 304Aug 7, 2026
Apache-2.0Aug 7, 2026 · metrics 2.10.0
npm
84Excellenthealth index
KeygraphHQ/shannon
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
TypeScript★ 46.4K↓ 3,414/moAug 5, 2026
AGPL-3.0Aug 5, 2026 · metrics 2.10.0
PyPI
83Excellenthealth index
infobyte/faraday
Open Source Vulnerability Management Platform
Python★ 6,698↓ 917/moAug 29, 2026
GPL-3.0Aug 29, 2026 · metrics 2.10.0
Go · npm
83Excellenthealth index
xalgord/xalgorix
Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.
Go · TypeScript★ 768Jul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
RubyGems
81Excellenthealth index
0dayInc/pwn
PWN is an open security automation framework that aims to stand on the shoulders of security giants, promoting trust and innovation.
Ruby★ 78Sep 5, 2026
MITSep 5, 2026 · metrics 2.10.0
npm
78Goodhealth index
Null-Square/Null-CLi
Open-source AI pentest and compliance-readiness CLI by NullSquare.
TypeScript · JavaScript★ 81↓ 147/moAug 4, 2026
Custom licenseAug 4, 2026 · metrics 2.10.0
PyPI · crates.io
78Goodhealth index
maurosoria/dirsearch
Web path scanner
Python★ 14.6K↓ 32.4K/moAug 19, 2026
No licenseAug 19, 2026 · metrics 2.10.0
Go
77Goodhealth index
Ullaakut/nmap
Idiomatic nmap library for go developers
Go★ 1,045Jul 30, 2026
MITJul 30, 2026 · metrics 2.10.0
PyPI
77Goodhealth index
gamehunterkaan/autopwn-suite
AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.
Python · JavaScript★ 1,093↓ 188/moJul 17, 2026
Custom licenseJul 17, 2026 · metrics 2.10.0
Go
75Goodhealth index
RAJANAGORI/Nightingale
Nightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes preconfigured with all essential tools and utilities required for efficient Vulnerability Assessment and Penetration Testing (VAPT), streamlining the setup process for security professionals.
Dockerfile · Shell · Python★ 313Aug 4, 2026
GPL-3.0Aug 4, 2026 · metrics 2.10.0
Go
75Goodhealth index
go-appsec/interactsh-lite
Dependency-minimal Interactsh protocol client and server for out-of-band testing (OOB / OAST)
Go★ 3Sep 5, 2026
MITSep 5, 2026 · metrics 2.10.0
Go
75Goodhealth index
go-appsec/toolbox
Collaborative application security testing between humans and agents via CLI and MCP
Go★ 37Jul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
PyPI
73Goodhealth index
ASCIT31/Dark-Moon
Autonomous AI pentesting engine, continuous offensive security across web, cloud, identity, CI/CD, IaC, databases, Active Directory, Kubernetes and IoT firmware. Agentic reasoning plus real exploit execution deliver proof-based vulnerabilities. Privacy gateway: the LLM never sees your real IPs, hosts or creds, nothing leaves your perimeter.
Python · TypeScript · Shell★ 802Aug 4, 2026
GPL-3.0Aug 4, 2026 · metrics 2.10.0
Go
73Goodhealth index
zan8in/afrog
A Security Tool for Bug Bounty, Pentest and Red Teaming.
Go · HTML★ 4,371Aug 28, 2026
MITAug 28, 2026 · metrics 2.10.0
npm
71Goodhealth index
pentoshi007/clai
Free AI coding & pentesting agent for your terminal
TypeScript★ 9↓ 15K/moSep 5, 2026
MITSep 5, 2026 · metrics 2.10.0
npm
69Goodhealth index
KryptSec/oasis
Open-source AI security benchmarking CLI. Measure how AI models perform offensive security tasks with MITRE ATT&CK analysis and KSM scoring.
TypeScript★ 29↓ 39/moAug 28, 2026
MITAug 28, 2026 · metrics 2.10.0
Go
69Goodhealth index
go-harden/interactsh-lite
Dependency-minimal Interactsh protocol client and server for out-of-band testing (OOB / OAST)
Go★ 3Jul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
69Goodhealth index
mukul975/Anthropic-Cybersecurity-Skills
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Python★ 27.3KAug 5, 2026
Apache-2.0Aug 5, 2026 · metrics 2.10.0
Go
67Goodhealth index
sayseven7/frameseven
Offensive web security scanner — OWASP Top 10 · MCP server · CLI · Go
Go★ 11Aug 8, 2026
MITAug 8, 2026 · metrics 2.10.0
63Moderatehealth index
Hacking-the-Cloud/hackingthe.cloud
An encyclopedia for offensive and defensive security knowledge in cloud native technologies.
Dockerfile · HTML · CSS★ 2,738Aug 4, 2026
Custom licenseAug 4, 2026 · metrics 2.10.0
Go
63Moderatehealth index
ddddddO/packemon
Packet monster (っ‘-’)╮=͟͟͞͞◒ ヽ( '-'ヽ) TUI tool for sending packets of arbitrary input and monitoring packets on any network interfaces (default: eth0). Windows/macOS/Linux
Go★ 305Jul 20, 2026
BSD-2-ClauseJul 20, 2026 · metrics 2.10.0
npm
62Moderatehealth index
Hyperyond/Hover
Open-source Vibe Testing suite: an MCP server for the coding agent you already run, a VS Code review cockpit, and CI. Your agent explores your app and crystallizes each flow into a plain @playwright/test spec you own — record == replay, runs in CI with zero AI.
TypeScript★ 11↓ 742/moSep 5, 2026
Apache-2.0Sep 5, 2026 · metrics 2.10.0