All tags
Catalogue tag

#pentest

Every repository in the public record carrying this tag — from its GitHub topics or the keywords its package registries publish. Health is measured under the same versioned methodology as the rest of the record.

33 records
Tagged “pentest”Ranked by health index
PyPI · Go · npm
94Exceptionalhealth index
PurpleAILAB/Decepticon
Autonomous Hacking Agent for Red Team
Python · Cypher★ 5,348↓ 7,794/moAug 28, 2026
Apache-2.0Aug 28, 2026 · metrics 2.10.0
npm
91Excellenthealth index
CyberStrikeus/CyberStrike
Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK, OWASP WSTG, CIS Benchmarks. Post-exploit: Linux/Windows/macOS/AWS/Azure/K8s/CI-CD. Web UI + Cloudflare Tunnel. Your AI red team.
TypeScript · Python★ 1,266↓ 2,624/moJul 23, 2026
AGPL-3.0Jul 23, 2026 · metrics 2.10.0
PyPI
91Excellenthealth index
usestrix/strix
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Python · Go · TypeScript★ 48.3KAug 5, 2026
Apache-2.0Aug 5, 2026 · metrics 2.10.0
Go
87Excellenthealth index
CompassSecurity/pipeleek
Pipeleek scans CI/CD logs and artifacts to detect leaked secrets and pivot from them
Go★ 21Jul 19, 2026
AGPL-3.0Jul 19, 2026 · metrics 2.10.0
Go
87Excellenthealth index
praetorian-inc/brutus
Fast, zero-dependency credential testing tool in Go. Brute force SSH, MySQL, PostgreSQL, Redis, MongoDB, SMB, and 20+ protocols. Hydra alternative with native nerva/naabu pipeline integration.
Go★ 304Aug 7, 2026
Apache-2.0Aug 7, 2026 · metrics 2.10.0
Go
84Excellenthealth index
CompassSecurity/pipeleak
Pipeleek scans CI/CD logs and artifacts to detect leaked secrets and pivot from them
Go★ 21Jul 18, 2026
AGPL-3.0Jul 18, 2026 · metrics 2.10.0
npm
84Excellenthealth index
KeygraphHQ/shannon
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
TypeScript★ 46.4K↓ 3,414/moAug 5, 2026
AGPL-3.0Aug 5, 2026 · metrics 2.10.0
Go · npm
83Excellenthealth index
xalgord/xalgorix
Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.
Go · TypeScript★ 768Jul 17, 2026
MITJul 17, 2026 · metrics 2.10.0
npm
78Goodhealth index
Null-Square/Null-CLi
Open-source AI pentest and compliance-readiness CLI by NullSquare.
TypeScript · JavaScript★ 81↓ 147/moAug 4, 2026
Custom licenseAug 4, 2026 · metrics 2.10.0
Go
75Goodhealth index
Chocapikk/wpprobe
A fast WordPress plugin enumeration tool
Go★ 937Aug 29, 2026
MITAug 29, 2026 · metrics 2.10.0
Go
73Goodhealth index
zan8in/afrog
A Security Tool for Bug Bounty, Pentest and Red Teaming.
Go · HTML★ 4,371Aug 28, 2026
MITAug 28, 2026 · metrics 2.10.0
npm
71Goodhealth index
pentoshi007/clai
Free AI coding & pentesting agent for your terminal
TypeScript★ 9↓ 15K/moSep 5, 2026
MITSep 5, 2026 · metrics 2.10.0
PyPI
69Goodhealth index
GoSecure/pyrdp
RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact
Python★ 1,774Jul 17, 2026
GPL-3.0Jul 17, 2026 · metrics 2.10.0
PyPI
67Goodhealth index
raccioly/websec-validator
Local-first security recon that briefs your AI coding agent: facts + tailored probes, code-in / artifacts-out. No LLM, no server, no running app.
Python★ 2Jul 31, 2026
MITJul 31, 2026 · metrics 2.10.0
Go
67Goodhealth index
sayseven7/frameseven
Offensive web security scanner — OWASP Top 10 · MCP server · CLI · Go
Go★ 11Aug 8, 2026
MITAug 8, 2026 · metrics 2.10.0
PyPI
65Goodhealth index
ra1nb0rn/search_vulns
A modular tool to search for known vulnerabilities, exploits and more across various data sources
Python · CSS · JavaScript★ 91↓ 3,793/moJul 18, 2026
MITJul 18, 2026 · metrics 2.10.0
PyPI
63Moderatehealth index
manthanghasadiya/mcpsec
An AI-driven dynamic protocol fuzzer for the Model Context Protocol (MCP). Prove runtime exploitability by discovering state violations, transport crashes, and application-layer logic flaws (SSRF, LFI) before your AI agents do.
Python★ 22↓ 319/moJul 28, 2026
MITJul 28, 2026 · metrics 2.10.0
RubyGems
62Moderatehealth index
Hackplayers/evil-winrm
The ultimate WinRM shell for hacking/pentesting
Ruby★ 5,451Aug 28, 2026
LGPL-3.0Aug 28, 2026 · metrics 2.10.0
Go
56Moderatehealth index
glitchedgitz/grroxy
A cyber security toolkit blending manual testing with AI Agents
Go★ 137Aug 5, 2026
MITAug 5, 2026 · metrics 2.10.0
RubyGems
54Moderatehealth index
urbanadventurer/WhatWeb
Next generation web scanner
Ruby★ 6,801Aug 28, 2026
GPL-2.0Aug 28, 2026 · metrics 2.10.0
53Moderatehealth index
0xSteph/pentest-ai-agents
Turn Claude Code into your offensive security research assistant. Specialized AI subagents for authorized penetration testing plan engagements, analyze recon, research exploits, build detections, audit STIGs, and write reports.
Shell★ 2,067Aug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
npm
51Moderatehealth index
3516634930/Payloader
渗透测试Payload速查平台 | Pentest Payload Quick Reference | XSS/SQLi/SSRF/RCE | React+TypeScript
TypeScript · JavaScript★ 463Jul 19, 2026
AGPL-3.0Jul 19, 2026 · metrics 2.10.0
PyPI · npm
47Weakhealth index
l4rm4nd/PyADRecon-ADWS
An implementation of PyADRecon using ADWS instead of LDAP. Generates individual CSV files and a single XSLX + HTML report about your AD domain. Evades EDR detections through ADWS.
Python★ 55↓ 87/moAug 22, 2026
MITAug 22, 2026 · metrics 2.10.0
npm
45Weakhealth index
ArisRoman/cyberaudit-skill
Universal security audit skill for AI agents. 52 pure Markdown files encoding 15 years of pentest expertise — web & mobile security, OWASP-aligned, CVSS scoring, compliance checks, zero dependencies.
TypeScript · JavaScript★ 0↓ 2,331/moJul 25, 2026
No licenseJul 25, 2026 · metrics 2.10.0
Go
42Weakhealth index
safetylab/ShadowSecurityScanner
Free, open-source network vulnerability scanner & penetration testing tool that ranks findings by real-world exploitability (EPSS + CISA KEV). Single desktop app for Windows, macOS, Linux. No cloud, no telemetry. MIT.
Go★ 0Jul 21, 2026
MITJul 21, 2026 · metrics 2.10.0
37Weakhealth index
matro7sh/BypassAV
This map lists the essential techniques to bypass anti-virus and EDR
Mixed★ 3,402Aug 4, 2026
No licenseAug 4, 2026 · metrics 2.10.0
PyPI
31At Riskhealth index
aaaguirrep/offensive-docker
Offensive Docker is an image with the more used offensive tools to create an environment easily and quickly to launch assessment to the targets.
Dockerfile★ 767Aug 4, 2026
MITAug 4, 2026 · metrics 2.10.0
PyPI
31At Riskhealth index
choupit0/MassVulScan
A fast network scanning tool to detect open ports and security vulnerabilities (Compatible with Debian & Red Hat OS)
Shell · HTML · XSLT★ 128Aug 4, 2026
GPL-3.0Aug 4, 2026 · metrics 2.10.0
PyPI · npm
29At Riskhealth index
Stiimy/briar
🥀 Autonomous AI Pentester — find vulns before hackers do. Free, open source, Ollama-powered.
Python★ 1↓ 78/moJul 17, 2026
Custom licenseJul 17, 2026 · metrics 2.10.0
22At Riskhealth index
Frissi0n/GTFONow
Automatic privilege escalation for misconfigured capabilities, sudo and suid binaries using GTFOBins.
Python★ 638Aug 3, 2026
MITAug 3, 2026 · metrics 2.10.0