A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.
Top PENTEST GitHub Repositories & Tools (2026)
Discover the most starred and trending open source tools tagged with #pentest.
Hunt down social media accounts by username across social networks
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Fast web fuzzer written in Go
Plugin for JADX to integrate MCP server
A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI
Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials across 30+ protocols.
802.11 Attack Tool
:key: Hash type identifier (CLI & lib)
Dradis Framework: Collaboration and reporting for IT Security teams
ScanT3r - Module based Bug Bounty Automation Tool ( use Lotus instead github.com/bugBlocker/lotus )
Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With built-in command automation, output parsing, and AI‑assisted summaries, it delivers faster, more structured, and high‑quality security assessments.
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.
AI-powered open-source platform for Attack Surface Management (OASM)
Radio frequency scanner with recon and offensive capabilities
Open-source adversarial testing engine, SDK, and CLI for AI agents. Runs locally or against the Humanbound Platform.
Program for determining types of files for Windows, Linux and MacOS.