Collection of cheat sheets useful for pentesting
☆681Jun 27, 2024Updated 2 years ago
Alternatives and similar repositories for awesome-pentest-cheat-sheets
Users that are interested in awesome-pentest-cheat-sheets are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- one-stop resource for all things offensive security.☆184Apr 21, 2026Updated 3 months ago
- A Golang package for scanning private and public IPs for open TCP ports 👁️☆118Mar 13, 2025Updated last year
- Awesome secure by default libraries to help you eliminate bug classes!☆718Dec 6, 2025Updated 8 months ago
- Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.☆618Jun 2, 2026Updated 2 months ago
- Secutils.dev is an open-source, versatile, yet simple security toolbox for engineers and researchers☆101Jul 19, 2026Updated 3 weeks ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens☆171Nov 29, 2024Updated last year
- YouShallNotPass brings an added level of execution security to mission-critical CI/CD Systems.☆36Jan 1, 2024Updated 2 years ago
- Collection of the cheat sheets useful for pentesting☆4,361Feb 16, 2024Updated 2 years ago
- A Powerful Network Reconnaissance Tool for Security Professionals☆107Dec 29, 2024Updated last year
- FlowMate, a BurpSuite extension that brings taint analysis to web applications, by tracking all parameters send to a target application a…☆168Oct 28, 2025Updated 9 months ago
- Modular web-application honeypot platform built using go and gin☆63May 8, 2024Updated 2 years ago
- APIDetector: Efficiently scan for exposed Swagger endpoints across web domains and subdomains. Supports HTTP/HTTPS, multi-threading, and …☆379Mar 28, 2025Updated last year
- Gram is Klarna's own threat model diagramming tool☆335Updated this week
- Web Security Scanner☆386Nov 13, 2025Updated 9 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- secator - the pentester's swiss knife☆1,305Updated this week
- EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.☆35Jan 4, 2026Updated 7 months ago
- List of free cybersecurity holiday events, CTFs, and Advent challenges where you can learn, practice hacking skills, and win prizes.☆30Dec 3, 2025Updated 8 months ago
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.☆41Dec 12, 2023Updated 2 years ago
- Web Server Vulnerability Scanning Tool☆38Mar 11, 2025Updated last year
- Tools and Techniques for Red Team / Penetration Testing☆9,617Apr 18, 2026Updated 3 months ago
- Unauthenticated enumeration of AWS IAM Roles.☆28Apr 18, 2026Updated 3 months ago
- FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).☆182Jul 8, 2024Updated 2 years ago
- SessionProbe is a multi-threaded tool designed for penetration testing and bug bounty hunting. It evaluates user privileges in web applic…☆467Mar 28, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Python tool to compare and analyse Nmap XML files to create a spreadsheet with results. Can also be used to create a markdown report usin…☆25Nov 12, 2024Updated last year
- A comprehensive, step-by-step penetration testing checklist for ethical hackers. Covers pre-engagement, information gathering, analysis, …☆145Nov 19, 2024Updated last year
- Fast and easy to use CLI-based file encryption program 📦☆13Oct 12, 2025Updated 10 months ago
- This GitHub Action sends a reverse shell from a runner via Azure Storage Account blobs☆40Sep 25, 2024Updated last year
- ☆571Mar 28, 2024Updated 2 years ago
- Automated web vulnerability scanning with LLM agents☆479Jun 18, 2025Updated last year
- game of active directory☆8,182Mar 12, 2026Updated 5 months ago
- A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.☆274Dec 18, 2025Updated 7 months ago
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accounts☆62May 15, 2023Updated 3 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Multilingual library made for validation, various form fields, such as: email, telephone, password, cpf, cnpj, credit card, magic numbers…☆19Feb 15, 2025Updated last year
- Learn AI security through a series of vulnerable LLM CTF challenges. No sign ups, no cloud fees, run everything locally on your system.☆355Aug 22, 2024Updated last year
- An offensive postexploitation tool that will give you complete control over the Outlook desktop application and therefore to the emails c…☆166Oct 9, 2024Updated last year
- Burp Suite Configuration Tweak☆13Mar 15, 2024Updated 2 years ago
- Spotter is a comprehensive Kubernetes security scanner that uses CEL-based rules to identify security vulnerabilities, misconfigurations,…☆76Sep 13, 2025Updated 11 months ago
- Customized CVE FEED Notifier☆114Jul 3, 2026Updated last month
- 🛡️ High-performance WAF & CDN detection tool. Identify protection layers (Cloudflare, Akamai, AWS, Fastly, and more), run effectiveness …☆115Updated this week