
hackingtool
All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

A collection of more than 170+ tools, scripts, cheatsheets and other loots that I've developed over years for Red Teaming/Pentesting/IT Security…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Weaponized Browser-in-the-Middle (BitM) for Penetration Testers

Rogue access point toolkit for WiFi penetration testing, deploying evil portal phishing payloads to capture credentials and perform social…

Tools and Techniques for Red Team / Penetration Testing

Simulate realistic phishing campaigns with credential harvesting, email tracking, and landing page cloning for security awareness training and…

PenBox - A Penetration Testing Framework - The Tool With All The Tools , The Hacker's Repo

PEGASUS-NEO is a comprehensive penetration testing framework designed for security professionals and ethical hackers. It combines multiple security…

Go-based network exploitation and MITM framework for authorized penetration testing, network reconnaissance, traffic interception, wireless security…

Proof-of-concept exploit for CVE-2024-21413 using Moniker Link in HTML email to trigger SMB connection and capture netNTLMv2 hashes via Responder.…

Proof-of-concept exploit for CVE-2024-42008, a Cross-Site Scripting vulnerability in RoundCube webmail. Delivers XSS payloads via contact forms to…

The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.


Modlishka. Reverse Proxy.

Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names

Automated WPA/WPA2 phishing tool that captures handshakes, spawns a rogue access point, and lures users to a captive portal to harvest credentials…

Social engineering attack vector and exploitation framework for hijacking user sessions via QR code login, targeting web applications like WhatsApp,…