Collection of cheat sheets useful for pentesting
β670Jun 27, 2024Updated 2 years ago
Alternatives and similar repositories for awesome-pentest-cheat-sheets
Users that are interested in awesome-pentest-cheat-sheets are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- one-stop resource for all things offensive security.β182Apr 21, 2026Updated 3 months ago
- A Golang package for scanning private and public IPs for open TCP ports ποΈβ118Mar 13, 2025Updated last year
- Awesome secure by default libraries to help you eliminate bug classes!β713Dec 6, 2025Updated 7 months ago
- Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.β613Jun 2, 2026Updated last month
- Secutils.dev is an open-source, versatile, yet simple security toolbox for engineers and researchersβ101Updated this week
- Virtual machines for every use case on DigitalOcean β’ AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokensβ169Nov 29, 2024Updated last year
- YouShallNotPass brings an added level of execution security to mission-critical CI/CD Systems.β36Jan 1, 2024Updated 2 years ago
- Collection of the cheat sheets useful for pentestingβ4,359Feb 16, 2024Updated 2 years ago
- A Powerful Network Reconnaissance Tool for Security Professionalsβ107Dec 29, 2024Updated last year
- FlowMate, a BurpSuite extension that brings taint analysis to web applications, by tracking all parameters send to a target application aβ¦β168Oct 28, 2025Updated 8 months ago
- Modular web-application honeypot platform built using go and ginβ63May 8, 2024Updated 2 years ago
- APIDetector: Efficiently scan for exposed Swagger endpoints across web domains and subdomains. Supports HTTP/HTTPS, multi-threading, and β¦β378Mar 28, 2025Updated last year
- Gram is Klarna's own threat model diagramming toolβ335Updated this week
- Web Security Scannerβ387Nov 13, 2025Updated 8 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer β’ AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- secator - the pentester's swiss knifeβ1,302Updated this week
- EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.β35Jan 4, 2026Updated 6 months ago
- List of free cybersecurity holiday events, CTFs, and Advent challenges where you can learn, practice hacking skills, and win prizes.β30Dec 3, 2025Updated 7 months ago
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.β41Dec 12, 2023Updated 2 years ago
- Web Server Vulnerability Scanning Toolβ38Mar 11, 2025Updated last year
- Tools and Techniques for Red Team / Penetration Testingβ9,502Apr 18, 2026Updated 3 months ago
- Unauthenticated enumeration of AWS IAM Roles.β28Apr 18, 2026Updated 3 months ago
- FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).β182Jul 8, 2024Updated 2 years ago
- SessionProbe is a multi-threaded tool designed for penetration testing and bug bounty hunting. It evaluates user privileges in web applicβ¦β467Mar 28, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways β’ AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Python tool to compare and analyse Nmap XML files to create a spreadsheet with results. Can also be used to create a markdown report usinβ¦β25Nov 12, 2024Updated last year
- A comprehensive, step-by-step penetration testing checklist for ethical hackers. Covers pre-engagement, information gathering, analysis, β¦β140Nov 19, 2024Updated last year
- Fast and easy to use CLI-based file encryption program π¦β13Oct 12, 2025Updated 9 months ago
- This GitHub Action sends a reverse shell from a runner via Azure Storage Account blobsβ40Sep 25, 2024Updated last year
- β570Mar 28, 2024Updated 2 years ago
- Automated web vulnerability scanning with LLM agentsβ479Jun 18, 2025Updated last year
- game of active directoryβ8,066Mar 12, 2026Updated 4 months ago
- A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.β267Dec 18, 2025Updated 7 months ago
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accountsβ62May 15, 2023Updated 3 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer β’ AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Multilingual library made for validation, various form fields, such as: email, telephone, password, cpf, cnpj, credit card, magic numbersβ¦β19Feb 15, 2025Updated last year
- Learn AI security through a series of vulnerable LLM CTF challenges. No sign ups, no cloud fees, run everything locally on your system.β354Aug 22, 2024Updated last year
- An offensive postexploitation tool that will give you complete control over the Outlook desktop application and therefore to the emails cβ¦β166Oct 9, 2024Updated last year
- Burp Suite Configuration Tweakβ13Mar 15, 2024Updated 2 years ago
- Spotter is a comprehensive Kubernetes security scanner that uses CEL-based rules to identify security vulnerabilities, misconfigurations,β¦β76Sep 13, 2025Updated 10 months ago
- Customized CVE FEED Notifierβ113Jul 3, 2026Updated 3 weeks ago
- π‘οΈ High-performance WAF & CDN detection tool. Identify protection layers (Cloudflare, Akamai, AWS, Fastly, and more), run effectiveness β¦β114Mar 9, 2026Updated 4 months ago