awesome-pentest
github.com/al1ex/awesome-pentest ↗Collection of penetration testing tools
Use this list with your AI agent
Add the Context Awesome MCP server to Claude, Cursor, or any MCP client, then ask:
"Show me network reconnaissance tools resources from awesome-pentest"
Installation instructions →What's inside
Hex Editors
- 0xED
Native macOS hex editor that supports plug-ins to display custom data types.
- Bless
High quality, full featured, cross-platform graphical hex editor written in Gtk#.
- Frhed
Binary file editor for Windows.
- hexedit
Simple, fast, console-based hex editor.
- HexEdit.js
Browser-based hex editing.
- Hex Fiend
Fast, open source, hex editor for macOS with support for viewing binary diffs.
Periodicals
- 2600: The Hacker Quarterly
American publication about technology and computer "underground" culture.
Conferences and Events
- 44Con
Annual Security Conference held in London.
- AppSecUSA
Annual conference organized by OWASP.
- BalCCon
Balkan Computer Congress, annually held in Novi Sad, Serbia.
- Black Hat
Annual security conference in Las Vegas.
- BruCON
Annual security conference in Belgium.
- BSides
Framework for organising and holding security conferences.
Network Tools
- ACLightNetwork Reconnaissance Tools
Script for advanced discovery of sensitive Privileged Accounts - includes Shadow Admins.
- Aircrack-ngWireless Network Tools
Set of tools for auditing wireless networks.
- AirgeddonWireless Network Tools
Multi-use bash script for Linux systems to audit wireless networks.
- AneviconDDoS Tools
Powerful UDP-based load generator, written in Rust.
- BetterCAPProxies and Machine-in-the-Middle (MITM) Tools
Modular, portable and easily extensible MITM framework.
- BoopSuiteWireless Network Tools
Suite of tools written in Python for wireless auditing.
Network Vulnerability Scanners
- ACSTISWeb Vulnerability Scanners
Automated client-side template injection (sandbox escape/bypass) detection for AngularJS.
- ArachniWeb Vulnerability Scanners
Scriptable framework for evaluating the security of web applications.
- cms-explorerWeb Vulnerability Scanners
Reveal the specific modules, plugins, components and themes that various websites powered by content management systems are running.
Windows Utilities
- Active Directory and Privilege Escalation (ADAPE)
Umbrella script that automates numerous useful PowerShell modules to discover security misconfigurations and attempt privilege escalation against Active Directory.
- Bloodhound
Graphical Active Directory trust relationship explorer.
- Commando VM
Automated installation of over 140 Windows software packages for penetration testing and red teaming.
- Covenant
ASP.NET Core application that serves as a collaborative command and control platform for red teamers.
- DeathStar
Python script that uses Empire's RESTful API to automate gaining Domain Admin rights in Active Directory environments.
- Empire
Pure PowerShell post-exploitation agent.
Books
- Advanced Penetration Testing by Wil Allsopp, 2017Penetration Testing Books
- Advanced Penetration Testing for Highly-Secured Environments by Lee Allen, 2012Penetration Testing Books
- Advanced Persistent Threat Hacking: The Art and Science of Hacking Any Organization by Tyler Wrightson, 2014Penetration Testing Books
- Android Hacker's Handbook by Joshua J. Drake et al., 2014Hacker's Handbook Series Books
- Black Hat Python: Python Programming for Hackers and Pentesters by Justin Seitz, 2014Penetration Testing Books
- Btfm: Blue Team Field Manual by Alan J White & Ben Clark, 2017Penetration Testing Books
Online Resources
- Android ExploitsOther Lists Online
Guide on Android Exploitation and Hacks.
- Android SecurityOther Lists Online
Collection of Android security related resources.
- AppSecOther Lists Online
Resources for learning about application security.
- Awesome AwesomnessOther Lists Online
The List of the Lists.
- Awesome LockpickingOther Lists Online
Awesome guides, tools, and other resources about the security and compromise of locks, safes, and keys.
- Blue TeamOther Lists Online
Awesome resources, tools, and other shiny things for cybersecurity blue teams.
Showing a sample of 498 resources. View the full list on GitHub →