03 Aug 2026
Java
★ 457
ShotDroid v2 is a penetration testing tool designed for Android devices that features file retrieval from device storage, an integrated keylogger with reverse shell capabilities, and the ability to capture images from the device's front camera. Notable functionalities include the option to conceal apps in the file manager, customization of directories and HTML templates for webcam captures, and a focus on educational use within legal boundaries.
03 Aug 2026
Python
★ 89
Sexettintool is a multifaceted cybersecurity tool designed for educational and ethical hacking purposes, enabling users to execute various automated exploits and security assessments. Key features include exploit scanning with Searchsploit, firewall detection via wafw00f, brute force automation with ncrack, and vulnerability analysis using nikto and lynis, among others. The tool is structured to enhance cybersecurity awareness while retaining a focus on responsible usage, with comprehensive support for Linux users and potential Docker deployment.
03 Aug 2026
Python
★ 11
Selene is a Python-based script designed to facilitate the dumping of MySQL databases using specified connection parameters such as host, username, and database name. Its primary use case is to provide a straightforward interface for users to export MySQL database data with minimal command-line input. Notable features include a user-friendly command structure and the ability to create a system-wide command symlink for easy access.
03 Aug 2026
Python
★ 115
SBSCAN is a penetration testing tool specifically designed for the Spring framework, capable of conducting unauthorized scans and sensitive information detection on Spring Boot applications, as well as identifying and validating related vulnerabilities. Notable features include an extensive dictionary for sensitive paths, fingerprint detection capabilities to optimize resource usage, modular architecture for user-defined extensions, and comprehensive support for various types of vulnerability checks, including the latest CVEs. The tool also implements functionality for noise reduction in results, allowing users to focus on successful detections, and supports various scanning configurations such as URL or file-based targets, proxy settings, and multithreading.
03 Aug 2026
Python
★ 11
Saldi Script is a versatile testing tool designed for security professionals to conduct various web application attacks, including DDoS, SQL injection, XSS, and data exfiltration. Key features include the ability to bypass Web Application Firewalls (WAF), execute reverse shell commands, and engage in phishing attacks, all aimed at evaluating the robustness of website security. The tool requires Python 3.10 and specific dependencies for operation, emphasizing its use as an educational resource for ethical hacking practices.
03 Aug 2026
Shell
★ 46
The "s3-buckets-aio-pwn" tool is designed to identify vulnerable Amazon S3 buckets as part of penetration testing and bug bounty efforts. It uniquely allows users to scan multiple S3 bucket entries from a text file while employing various attack scenarios to assess their vulnerability. Key features include its command-line usage, integration with AWS CLI, and the capability to quickly filter out false positives during vulnerability assessments.
03 Aug 2026
Rust
★ 93
Rust-Hells-Gate is a proof-of-concept tool designed for evading Endpoint Detection and Response (EDR) systems through the use of direct syscalls in Rust. It specifically implements the Hell's Gate technique, allowing users to bypass EDR hooks by accessing the Process Environment Block (PEB) to resolve function pointers from ntdll.dll, thereby minimizing detection by common security measures. Notable features include its lightweight implementation approach and the potential for extension into a fully functional malware loader.
03 Aug 2026
PHP
★ 70
Rome WebShell is a lightweight PHP webshell designed for educational use, featuring a fully interactive file explorer that allows users to browse directories and upload files directly from their browser. It enables command execution without URL encoding while offering MD5 password protection for access control, alongside a customizable and responsive FlatUI interface. Additionally, the tool includes an obfuscated version to enhance security against detection.
03 Aug 2026
Python
★ 304
The Rogue Toolkit is a cybersecurity tool designed for advanced users to simulate malicious activity and test network defenses. Its primary use case is to aid in penetration testing and security assessments, allowing for customized execution of various attack scenarios. Notable features include extensive documentation for argument configurations and example use cases, enabling tailored deployments in various environments.
03 Aug 2026
JavaScript
★ 104
rfparty-xyz is a visualization tool designed to enhance the understanding of Bluetooth Low Energy (BLE) interactions. Its primary use case revolves around providing insights into BLE data through user-friendly displays, with complementary data collection capabilities available via rfparty-monitor. Notable features include cross-platform compatibility and support for mobile usage with an Android version.
03 Aug 2026
JavaScript
★ 122
rfparty-monitor is a wireless situational awareness and debugging tool that allows users to visualize and analyze Bluetooth Low Energy (BLE) data, along with GPS and Wi-Fi logs. It supports diverse platforms such as Android and Linux, and features capabilities like log retrieval and GPX conversion, making it suitable for both casual users and security professionals focusing on wireless monitoring and intrusion detection. Notable features include support for various GPS sources, a flexible installation process, and a roadmap for future enhancements like protocol improvements and real-time sharing alerts.
03 Aug 2026
Go
★ 14
r3conwhal3 is a multifunctional reconnaissance tool designed for web application data collection and analysis, employing a concurrency-based approach to enhance performance and resource efficiency. Its primary use case includes performing both passive and active reconnaissance, with capabilities to enumerate subdomains, conduct vulnerability scans, and manage custom configurations through an environment file. Notable features include a comprehensive execution chain, support for Docker deployment, and the ability to save output results for future reference.
03 Aug 2026
Python
★ 100
pync is a Python library that mimics the functionality of Netcat, enabling arbitrary TCP and UDP connections and listening capabilities. Its primary use case includes creating TCP proxies, scripting HTTP clients and servers, and performing network daemon testing. Notable features include a comprehensive command-line interface, extensive networking options, and the ability to execute remote commands, making it suitable for various network-related tasks in Python development.
03 Aug 2026
Python
★ 526
PyMeta is a Python3 tool designed for penetration testers and red teamers to conduct metadata analysis on files downloaded from web domains using tailored Google and Bing searches. This tool efficiently retrieves file types such as PDFs and documents, extracts their metadata via exiftool, and compiles the results into a CSV report, making it easier to uncover sensitive information like user accounts and software versions. Notable features include multi-threaded file downloads, customizable search engines, and the ability to process locally stored files.
03 Aug 2026
PowerShell
★ 201
PowerLadon is a modular penetration testing tool designed for network reconnaissance, vulnerability scanning, and exploitation, offering capabilities for batch processing across various IP segments. It features extensive support for different protocols, built-in modules for high-risk vulnerabilities, password auditing, and remote command execution, while allowing users to customize and develop their own plugins. Its ease of use and compatibility with PowerShell and Cobalt Strike enhance its versatility in both internal and external network penetration tasks.
03 Aug 2026
Python
★ 19
Penstaller is a Python automation tool that streamlines the setup of essential bug bounty and penetration testing tools on a clean system with a single command. It automates the installation of critical programming languages and various pentesting utilities, facilitating a rapid and efficient environment preparation for both novice and experienced security testers. Notable features include a comprehensive list of tools covering different aspects of security testing, along with recommendations for additional manual installations of wordlists.
03 Aug 2026
Python
★ 637
Overlord is a Python-based command-line interface (CLI) tool designed for automating the setup of Red Teaming infrastructure. It allows users to easily deploy components such as command-and-control servers, email servers, and phishing servers on cloud providers like AWS and Digital Ocean, streamlining the process of creating a comprehensive penetration testing environment. Notable features include modular input handling and integration with Terraform, leveraging the Red-Baron project for infrastructure management.
03 Aug 2026
Shell
★ 668
Open-Redirect-Payloads is a tool designed to generate exploit payloads for testing Open Redirect vulnerabilities within web applications. Its primary use case is to assist security professionals in identifying and mitigating open redirect issues by generating URL payloads targeting specific whitelisted domains. Notable features include a simple script (make-payloads.sh) that allows users to customize payload generation based on specified domains.
03 Aug 2026
Python
★ 578
Nullinux is a penetration testing tool designed for Linux environments, specifically tailored for enumerating OS and domain information via SMB protocols. It features capabilities such as single and multi-host enumeration, user and group enumeration, and multi-threaded RID cycling, all while employing a null session approach if no credentials are provided. Additionally, Nullinux generates a formatted output file devoid of duplicates to facilitate further exploitation activities.
03 Aug 2026
Java
★ 393
Nuclei-plus is an enhanced version of the Nuclei tool designed for high-speed scanning across multiple targets with customizable templates, ensuring zero false positives. It supports various protocols such as TCP, DNS, and HTTP, and includes features like project management, configuration management, and template editing, making it suitable for comprehensive security assessments. The tool further allows internationalization and multiple network engine interfaces, enhancing user flexibility and control in security checks.
03 Aug 2026
C#
★ 17
NetExec is an open-source network exploitation tool that evolved from the original CrackMapExec, aimed at providing a community-driven framework for post-exploitation activities in network environments. Its primary use case is to facilitate the automation of network attacks and assessments, integrating a suite of tools for a comprehensive assessment workflow. Notable features include ease of installation via pipx, community contributions for continuous improvement, and an active support channel through Discord.
03 Aug 2026
Shell
★ 10
Minerva is an automated reconnaissance and penetration testing script that streamlines the assessment of a target by integrating multiple tools for tasks such as Nmap scanning, OSINT gathering, and vulnerability enumeration. Notable features include automated Google Dorking for targeting potential admin pages and the use of established tools like theHarvester, amass, and nikto for comprehensive analysis. This tool simplifies the penetration testing workflow, making it accessible for users to execute complex assessments with minimal setup.
03 Aug 2026
C
★ 16
Macgonuts is a versatile ARP/NDP tool designed for network address spoofing, supporting both IPv4 and IPv6 protocols. It aims to provide a lightweight, user-friendly interface for ethical hacking and pentesting while allowing developers to leverage its functionalities via C libraries or bindings in Go and Python. Compatible with Linux and FreeBSD, Macgonuts emphasizes responsible use and ethical practices in network security assessments.
03 Aug 2026
Python
★ 115
LFITester is a Python3 tool designed for testing server vulnerabilities to Local File Inclusion (LFI) attacks, primarily running on Linux/Unix systems but compatible with Windows as well. Key features include support for various attack vectors like Path Traversal, PHP Filters, and Remote Code Execution through methods such as log poisoning and session file exploitation. The tool provides a comprehensive command-line interface that allows users to automate LFI testing and customize payloads for effective penetration testing.
03 Aug 2026
Python
★ 27
kcbrute is a brute-force tool designed for testing the security of Keycloak Admin/User Console login flows by attacking the OpenID Authorization Endpoint. It allows users to specify a target URL, along with lists of usernames and passwords, and features options for threading, verbosity, and behavioral controls such as early stopping upon a successful login attempt. This tool is intended strictly for ethical security testing, with a disclaimer regarding potential account locking due to brute-force detection mechanisms.