A curated, categorized list of offensive-security, reconnaissance, fuzzing, exploitation, post‑exploit and tooling repositories you can reference for research, testing, or lab exercises. Each entry keeps the original link.
Table of Contents
Recon & Info Gathering
Scanners & Large-Scale Discovery
Fuzzing & Parameter Testing
Web Application & API Tools
Exploitation & PoC Collections
Post-Exploitation & RATs
Internal Network / Lateral Movement
Evasion, Persistence & Bypass
Mobile & Frida
Containers, Cloud & DevTools
Utilities, Frameworks & Misc
1. Recon & Info Gathering
Findomain — Good domain discovery tool.
https://github.com/Findomain/Findomainblackbird — Search users across 130 sites.
https://github.com/p1ngul1n0/blackbirdzpscan — Recon / information-gathering tool.
https://github.com/niudaii/zpscancvetrends — Crawler & push program for real-time vulnerability trends.
https://github.com/VulnTotal-Team/cvetrendsgvision — Reverse image search to detect landmarks / locations.
https://github.com/GONZOsint/gvisionDarkScrape — Darkweb intelligence data-scraper.
https://github.com/itsmehacker/DarkScrapeAppInfoScanner — Mobile app information collection.
https://github.com/kelvinBen/AppInfoScannerblackbird (duplicate note) — listed above.
2. Scanners & Large-Scale Discovery
ATSCAN — Search & large-scale exploitation scanner.
https://github.com/AlisamTechnology/ATSCANafrog — Vulnerability scanner with 600+ PoCs; high-performance customizable scanner.
https://github.com/zan8in/afrogkscan — Pure-Go all-in-one scanner.
https://github.com/lcvvvv/kscanfscan — Internal network comprehensive scanner.
https://github.com/shadow1ng/fscanAntenna — Vulnerability scanning tool by 58.com security team.
https://github.com/wuba/AntennaNucleiTP — Automatic PoC updater.
https://github.com/ExpLangcn/NucleiTPBanli (Bnali) — High‑risk asset identification & high‑risk vulnerability scanning.
https://github.com/Goqi/BanliDirscan — High‑concurrency directory scanner in Go.
https://github.com/corunb/Dirscantlsx — TLS information grabber.
https://github.com/projectdiscovery/tlsx
3. Fuzzing & Parameter Testing
GooFuzz — Fuzzing tool.
https://github.com/m3n0sd0n4ld/GooFuzzScalpel — Web/API complex-parameter fuzzing.
https://github.com/StarCrossPortal/scalpelXSStrike — XSS scanner & fuzzing for cross-site scripting.
https://github.com/s0md3v/XSStrikefuxploider — File upload vulnerability scanner & exploitation tool.
https://github.com/almandin/fuxploider
4. Web Application & API Tools
sqlmap-gtk — Graphical sqlmap frontend.
https://github.com/needle-wang/sqlmap-gtk.gitSerein — Graphical automated vulnerability scanning & exploitation tool.
https://github.com/W01fh4cker/SereinSec-Tools — Multifunctional web application penetration system.
https://github.com/jwt1399/Sec-Toolsswagger-exp — API information-leak exploitation tool.
https://github.com/lijiejie/swagger-expweb-brutator — Middleware endpoint brute-forcer.
https://github.com/koutto/web-brutatorscalpel — (listed in fuzzing) complex parameter fuzzing for web/API.
https://github.com/StarCrossPortal/scalpelsucker — Add fake vulnerabilities to any HTTP service to deceive scanners.
https://github.com/Ciyfly/sucker
5. Exploitation & PoC Collections
0day — Collections of various vulnerability exps & PoCs.
https://github.com/helloexp/0dayAdvanced-SQL-Injection-Cheatsheet — Advanced SQL injection notes & cheatsheet.
https://github.com/kleiton0x00/Advanced-SQL-Injection-Cheatsheetblenny — Embed payloads into executable icon resources.
https://github.com/frank2/blennyJsleak — Source-code sensitive-information scanner.
https://github.com/channyein1337/jsleak
6. Post-Exploitation & RATs
Behinder (Ice Scorpion) — Webshell/backdoor framework.
https://github.com/rebeyond/BehinderAhMyth — GUI remote access tool (Android RAT, aesthetic UI).
https://github.com/Morsmalleo/AhMythBlackNET — Web-based remote control framework.
https://github.com/BlackHacker511/BlackNETAIRAVAT — Web-based remote control (RAT).
https://github.com/Th30neAnd0nly/AIRAVATTele-Rat — Telegram-bot remote control RAT.
https://github.com/TeamDarkAnon/Tele-RatTelegram-RAT — Telegram-bot remote control RAT (alt).
https://github.com/Bainky/Telegram-RATToRat — Remote control over Tor.
https://github.com/lu4p/ToRatDRat — Decentralized remote control tool.
https://github.com/SpenserCai/DRatPandora — Open-source botnet.
https://github.com/swagkarna/PandoraGrabcam — Terminal webcam grabber.
https://github.com/noob-hackers/grabcamCppWeixinHunter — Obtain phone numbers / WeChat IDs logged in on a computer.
https://github.com/baiyies/CppWeixinHunterSMSBoom — Python short-burst SMS program.
https://github.com/OpenEthan/SMSBoom
7. Internal Network / Lateral Movement
Aopo — Internal network automated reconnaissance (auto "dotting" / mapping).
https://github.com/ExpLangcn/AopoWMIHACKER — Evasion & lateral-movement command testing tool (WMI).
https://github.com/rootclay/WMIHACKERRequestTemplate — Minimal-packet post-exploitation internal network tool.
https://github.com/1n7erface/RequestTemplatenps — Lightweight internal network tunneling / proxy server.
https://github.com/ehang-io/npspierced — DingTalk internal network tunneling (punch-through).
https://github.com/open-dingtalk/pierced
8. Evasion, Persistence & Bypass
av_evasion_tool — AV evasion / packer / bypass generator.
https://github.com/1y0n/av_evasion_toolschtask-bypass — Task-scheduler persistence bypass for stealthy privilege maintenance.
https://github.com/H4de5-7/schtask-bypassWMIHACKER — (listed above) lateral movement / evasion testing.
https://github.com/rootclay/WMIHACKERwaf-bypass — WAF bypass tools.
https://github.com/nemesida-waf/waf-bypass
9. Mobile & Frida
frida-skeleton — Frida-based Android hooking framework.
https://github.com/Margular/frida-skeletonCutter (rizin) — Open-source reverse-engineering platform.
https://github.com/rizinorg/cutteri-Haklab — Termux hacker experiment kit.
https://github.com/ivam3/i-Haklab
10. Containers, Cloud & DevOps Tools
veinmind-tools — Container security toolkit.
https://github.com/chaitin/veinmind-toolssiusiu — Common pentest tools packaged in Docker.
https://github.com/ShangRui-hash/siusiuScrapy — Fast web-crawling framework in Python (useful for reconnaissance).
https://github.com/scrapy/scrapySavior — Penetration test report auto-generator.
https://github.com/Mustard404/Savior
11. Utilities, Frameworks & Misc
Viper — Graphical penetration tool.
https://github.com/FunnyWolf/ViperYAKIT — Single-operator (soldier) toolkit.
https://github.com/yaklang/yakitSocialEngineeringDictionaryGenerator — Social engineering password dictionary generator.
https://github.com/zgjx6/SocialEngineeringDictionaryGeneratorPrintNotifyPotato — Potato-style privilege escalation (PrintNotifyPotato).
https://github.com/BeichenDream/PrintNotifyPotatoAttackSurfaceMapper — Automated penetration testing mapper.
https://github.com/superhedgy/AttackSurfaceMapperAll-Defense-Tool — Aggregated offensive/defensive tool collection.
https://github.com/guchangan1/All-Defense-ToolPhoenixC2 — Open-source C2 framework.
https://github.com/screamz2k/PhoenixC2Advanced SQL & other references — assorted cheatsheets and notes listed above.






0 Comments