Python Pentest

Open-source Python projects categorized as Pentest

Top 23 Python Pentest Projects

  • PayloadsAllTheThings

    A list of useful payloads and bypass for Web Application Security and Pentest/CTF

  • Project mention: php shell not executed in wordpress | /r/hacking | 2023-12-08

    Also https://github.com/swisskyrepo/PayloadsAllTheThings I'm sure there's a few test php files in here for filter bypasses too

  • objection

    📱 objection - runtime mobile exploration

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • DefaultCreds-cheat-sheet

    One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password 🛡️

  • Villain

    Villain is a C2 framework that can handle multiple TCP socket & HoaxShell-based reverse shells, enhance their functionality with additional features (commands, utilities etc) and share them among connected sibling servers (Villain instances running on different machines).

  • patator

    Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

  • pentest-wiki

    PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others.

  • snoop

    Snoop — инструмент разведки на основе открытых данных (OSINT world)

  • Project mention: Osint update of the Snoop Project tool search for user by nickname | news.ycombinator.com | 2024-01-02
  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
  • CloudFlair

    🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.

  • CloudFail

    Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network

  • macro_pack

    macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for pentest, demo, and social engineering assessments. The goal of macro_pack is to simplify exploitation, antimalware bypass, and automatize the process from malicious macro and script generation to final document generation. It also provides a lot of helpful features useful for redteam or security research.

  • reconspider

    🔎 Most Advanced Open Source Intelligence (OSINT) Framework for scanning IP Address, Emails, Websites, Organizations.

  • pwn_jenkins

    Notes about attacking Jenkins servers

  • odat

    ODAT: Oracle Database Attacking Tool

  • pyrdp

    RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact

  • Project mention: Researchers watched 100 hours of hackers hacking honeypot computers | news.ycombinator.com | 2023-08-10

    The RDP interception tool used by the researchers: https://github.com/gosecure/pyrdp

  • GraphQLmap

    GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)

  • Redcloud

    Automated Red Team Infrastructure deployement using Docker

  • SysReptor

    Fully customisable, offensive security reporting solution designed for pentesters, red teamers and other security-related people alike.

  • enum4linux-ng

    A next generation version of enum4linux (a Windows/Samba enumeration tool) with additional features like JSON/YAML export. Aimed for security professionals and CTF players.

  • BlackMamba

    C2/post-exploitation framework

  • DumpsterFire

    "Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.

  • BeeLogger

    Generate Gmail Emailing Keyloggers to Windows.

  • VcenterKit

    Vcenter综合渗透利用工具包 | Vcenter Comprehensive Penetration and Exploitation Toolkit

  • Project mention: VcenterKit: Vcenter综合渗透利用工具包 | Vcenter Comprehensive Penetration and Exploitation Toolkit | /r/blueteamsec | 2023-08-26
  • habu

    Hacking Toolkit

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

Python Pentest related posts

  • Osint update of the Snoop Project tool search for user by nickname

    1 project | news.ycombinator.com | 2 Jan 2024
  • php shell not executed in wordpress

    1 project | /r/hacking | 8 Dec 2023
  • Updated OSINT tool to search for user by nickname

    1 project | news.ycombinator.com | 29 Oct 2023
  • XXE-XML External Entities Attacks

    2 projects | dev.to | 25 Oct 2023
  • Snoop Project OSINT tool search by username on 3200 sites

    1 project | news.ycombinator.com | 14 Sep 2023
  • Researchers watched 100 hours of hackers hacking honeypot computers

    2 projects | news.ycombinator.com | 10 Aug 2023
  • New Attack Surface Discovery tool : OrgASM

    1 project | /r/cybersecurity | 31 May 2023
  • A note from our sponsor - InfluxDB
    www.influxdata.com | 20 May 2024
    Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality. Learn more →

Index

What are some of the best open-source Pentest projects in Python? This list will help you:

Project Stars
1 PayloadsAllTheThings 57,207
2 objection 7,050
3 DefaultCreds-cheat-sheet 5,324
4 Villain 3,590
5 patator 3,475
6 pentest-wiki 3,332
7 snoop 2,709
8 CloudFlair 2,407
9 CloudFail 2,153
10 macro_pack 2,045
11 reconspider 1,918
12 pwn_jenkins 1,899
13 odat 1,565
14 pyrdp 1,439
15 GraphQLmap 1,306
16 Redcloud 1,184
17 SysReptor 1,152
18 enum4linux-ng 1,037
19 BlackMamba 990
20 DumpsterFire 959
21 BeeLogger 958
22 VcenterKit 894
23 habu 858

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com