
Thick-Client-Pentest-Checklist
A OWASP Based Checklist With 80+ Test Cases

A OWASP Based Checklist With 80+ Test Cases

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

A curated list of resources related to Industrial Control System (ICS) security.

Offensive 802.11 auditing tool that automates WPA/WPA2 handshake and PMKID capture using deauthentication, rogue-client, and channel-switch attacks,…

Passive network security sniffer that analyzes 28 protocols (ARP, STP, OSPF, VLAN, SCADA) to detect vulnerabilities in network equipment without…

An automated Wireless RogueAP MITM attack framework.

A reconnaissance tool for capturing and displaying SSIDs from device's Preferred Network List.

A script to configure a TP-Link MR3040 running OpenWRT into a simple, yet powerful penetration-testing "dropbox".

Passive hybrid fingerprinting engine — identify hosts without sending a single packet

NetRaptor is a GUI-based ARP poisoning tool built with Python that allows you to scan a network, select a target and gateway, and perform a…

cSploit - The most complete and advanced IT security professional toolkit on Android.

dSploit - The most complete and advanced IT security professional toolkit on Android.

Educational reverse engineering study of a Unity/IL2CPP Android game. Documents gateway protocol decoding, native anti-tampering SDK analysis, SSL…

Framework designed to automate various wireless networks attacks (the project was presented on Pentester Academy TV's toolbox in 2017).


📡 A python program to create a fake AP and sniff data.

Cross-platform network packet generator with full layer spoofing, pattern-based address randomization, and flood detection evasion for stress-testing…

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.