An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
-
Updated
May 11, 2026 - Shell
8000
An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
Automated brute-forcing attack tool.
A script for installing private Burp Collaborator with free Let's Encrypt SSL-certificate
CHOMTE.SH is a powerful shell script designed to automate reconnaissance tasks during penetration testing. It utilizes various Go-based tools to gather information and identify the attack surface, making it a valuable asset for bug bounty hunters and penetration testers.
Discover the attack surface and prioritize risks with our continuous Attack Surface Management (ASM) platform - Sn1per Professional #pentest #redteam #bugbounty
ADAT is a small tool used to assist CTF players and Penetration testers with easy commands to run against an Active Directory Domain Controller. This tool is is best utilized using a set of known credentials against the host.
Automated Web Recon Shell Scripts
The only OSCP preparation repository you need: notes, tooling, reporting, prep-list, methodology, and security resources.
Lightweight Kali Linux Docker images with curated CLI penetration testing tools for headless environments
CamHawk is a camera phishing tool that tricks users into granting webcam access. Once permission is granted, the tool captures images from the webcam and sends them to your machine.
Step-by-step guide to install, configure, and harden Kali Linux for ethical hacking , penetration testing , and cybersecurity research . Includes post-install tweaks , driver fixes , tools setup , and zsh customizations .
This tool will quickly search for exploitable binaries with SUID bit set in Linux and will output the method of exploitation from GTFObins
IP Sweeper Script is a script that will ping all the IP addresses in the given range and filter out the IPs that responded. This script is a very popular script and i know it, but this project is a detailed explanation of it.
Pointer is a Fast Simple Lightweight Tool for Endpoint Discovery.
YARA rule-based automation system to detect network attacks at byte-level
A collection of installation scripts for common security testing, penetration testing, and forensics tools.
A bash script that automates port scanning on specified target host(s). The aim of the scripts is reducing scan time, increasing scan efficiency and automating the workflow.
Simple ADB toolkit to penetrate Android device using Android Debug Bridge with over 35 features.
StealthNewSQL : The Ultimate NewSQL Injection Tool - Your All-in-One Solution for NewSQL Database Security! 🛡️ Uncover, exploit, and secure NewSQL database vulnerabilities with this feature-packed command-line tool. Whether you're a penetration tester, security researcher, or developer, StealthNewSQL equips you with the ultimate power! 💥
Auto Recon is a Bash script for automating the reconnaissance phase of penetration testing. It performs various types of scans to gather information about the target domain, including IP details, domain reconnaissance, vulnerability scanning, network mapping, application fingerprinting, and Google dorks.
Add a description, image, and links to the penetration-testing-tools topic page so that developers can more easily learn about it.
To associate your repository with the penetration-testing-tools topic, visit your repo's landing page and select "manage topics."