ScanReview
Ethical testing frameworks and tools used to validate security findings.
Open-source exploitation frameworks and penetration testing tools for ethical hacking — validate security findings and understand real-world impact.
Full-featured platforms for developing, testing, and executing exploit modules across networks and applications.
Automated detection and exploitation of SQL injection vulnerabilities across database backends.
Automatic SQL injection and database takeover — fingerprinting, data extraction, and OS shell access.
GitHub →Advanced SQL injection tool with blind, error-based, time-based, and stacked query detection and exploitation.
GitHub →Java-based automatic SQL injection with a GUI — supports 40+ database engines and multiple injection methods.
GitHub →Automated NoSQL database enumeration and exploitation — targets MongoDB and CouchDB injection flaws.
GitHub →
Online brute-force tools and offline hash crackers for testing password and authentication strength.
Fast network login cracker — supports 50+ protocols including SSH, FTP, HTTP, SMB, RDP, and databases.
GitHub →Fast password cracker — supports hundreds of hash and cipher types with community-enhanced "jumbo" edition.
GitHub →World's fastest password cracker — GPU-accelerated with 300+ hash types and advanced rule-based attacks.
GitHub →Speedy, parallel, modular login brute-forcer — supports most remote services with thread-level parallelism.
GitHub →Tools for exploiting browser-side vulnerabilities, command injection flaws, and web application weaknesses.
Tools for credential extraction, lateral movement, privilege escalation, and Active Directory enumeration after initial access.
Credential extraction from Windows — dumps passwords, hashes, PINs, and Kerberos tickets from memory.
GitHub →PowerShell post-exploitation framework — modules for recon, persistence, exfiltration, and privilege escalation.
GitHub →Active Directory attack path mapping — graph analysis reveals hidden escalation and lateral movement paths.
GitHub →Windows Remote Management shell — post-exploitation access to Windows hosts using WinRM with pass-the-hash.
GitHub →Low-level tools for reverse engineering, exploit development, and binary vulnerability analysis.
CTF and exploit development library — shellcraft, ROP chain building, networking, and ELF parsing utilities.
GitHub →Gadget finder for Return-Oriented Programming — extracts usable instruction sequences from binaries and libraries.
GitHub →Python Exploit Development Assistance for GDB — enhances debugging with exploit-focused commands and visuals.
GitHub →Tools for intercepting, poisoning, and manipulating network traffic — LLMNR/NBT-NS spoofing, MITM, and relay attacks.
LLMNR, NBT-NS, and MDNS poisoner — captures NTLMv2 hashes and serves rogue auth for network credential harvesting.
GitHub →Swiss army knife for network attacks — MITM, HTTP/HTTPS proxy, DNS spoofing, WiFi attacks, and packet manipulation.
GitHub →IPv6 DHCP takeover tool — exploits default Windows IPv6 preference to redirect authentication and capture credentials.
GitHub →