Collection of cheat sheets useful for pentesting
β701Jun 27, 2024Updated 2 years ago
Alternatives and similar repositories for awesome-pentest-cheat-sheets
Users that are interested in awesome-pentest-cheat-sheets are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- one-stop resource for all things offensive security.β186Sep 10, 2026Updated last week
- A Golang package for scanning private and public IPs for open TCP ports ποΈβ118Mar 13, 2025Updated last year
- Awesome secure by default libraries to help you eliminate bug classes!β725Dec 6, 2025Updated 9 months ago
- Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.β631Jun 2, 2026Updated 3 months ago
- Secutils.dev is an open-source, versatile, yet simple security toolbox for engineers and researchersβ101Aug 22, 2026Updated last month
- Deploy to Railway using AI coding agents - Free Credits Offer β’ AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokensβ172Nov 29, 2024Updated last year
- YouShallNotPass brings an added level of execution security to mission-critical CI/CD Systems.β36Jan 1, 2024Updated 2 years ago
- The MPT (Mobile Pentest Toolkit) is a must-have solution for your android penetration testing workflow.β95May 15, 2026Updated 4 months ago
- Collection of the cheat sheets useful for pentestingβ4,370Feb 16, 2024Updated 2 years ago
- A Powerful Network Reconnaissance Tool for Security Professionalsβ108Dec 29, 2024Updated last year
- FlowMate, a BurpSuite extension that brings taint analysis to web applications, by tracking all parameters send to a target application aβ¦β168Oct 28, 2025Updated 10 months ago
- Modular web-application honeypot platform built using go and ginβ63May 8, 2024Updated 2 years ago
- APIDetector: Efficiently scan for exposed Swagger endpoints across web domains and subdomains. Supports HTTP/HTTPS, multi-threading, and β¦β380Mar 28, 2025Updated last year
- Gram is Klarna's own threat model diagramming toolβ336Updated this week
- Managed Kubernetes at scale on DigitalOcean β’ AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Web Security Scannerβ387Nov 13, 2025Updated 10 months ago
- secator - the pentester's swiss knifeβ1,311Updated this week
- EZGHSA is a command-line tool for summarizing and filtering vulnerability alerts on Github repositories.β35Jan 4, 2026Updated 8 months ago
- List of free cybersecurity holiday events, CTFs, and Advent challenges where you can learn, practice hacking skills, and win prizes.β32Dec 3, 2025Updated 9 months ago
- Simple Command Line Tool to Enumerate Slack Workspace Names from Slack Webhook URLs.β41Dec 12, 2023Updated 2 years ago
- Web Server Vulnerability Scanning Toolβ37Mar 11, 2025Updated last year
- Unauthenticated enumeration of AWS IAM Roles.β28Apr 18, 2026Updated 5 months ago
- Tools and Techniques for Red Team / Penetration Testingβ9,741Apr 18, 2026Updated 5 months ago
- SessionProbe is a multi-threaded tool designed for penetration testing and bug bounty hunting. It evaluates user privileges in web applicβ¦β466Mar 28, 2024Updated 2 years ago
- GPUs on demand by Runpod - Special Offer Available β’ AdRun AI, ML, and HPC workloads on powerful cloud GPUsβwithout limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).β184Jul 8, 2024Updated 2 years ago
- Python tool to compare and analyse Nmap XML files to create a spreadsheet with results. Can also be used to create a markdown report usinβ¦β26Nov 12, 2024Updated last year
- A comprehensive, step-by-step penetration testing checklist for ethical hackers. Covers pre-engagement, information gathering, analysis, β¦β152Nov 19, 2024Updated last year
- Fast and easy to use CLI-based file encryption programβ12Aug 24, 2026Updated 3 weeks ago
- This GitHub Action sends a reverse shell from a runner via Azure Storage Account blobsβ40Sep 25, 2024Updated last year
- β571Mar 28, 2024Updated 2 years ago
- Automated web vulnerability scanning with LLM agentsβ480Jun 18, 2025Updated last year
- A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.β277Dec 18, 2025Updated 9 months ago
- game of active directoryβ8,367Mar 12, 2026Updated 6 months ago
- Virtual machines for every use case on DigitalOcean β’ AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Tools that checks for misconfigured access to Github OIDC from AWS roles and GCP service accountsβ62May 15, 2023Updated 3 years ago
- Multilingual library made for validation, various form fields, such as: email, telephone, password, cpf, cnpj, credit card, magic numbersβ¦β20Feb 15, 2025Updated last year
- Learn AI security through a series of vulnerable LLM CTF challenges. No sign ups, no cloud fees, run everything locally on your system.β365Aug 22, 2024Updated 2 years ago
- Spotter is a comprehensive Kubernetes security scanner that uses CEL-based rules to identify security vulnerabilities, misconfigurations,β¦β76Sep 13, 2025Updated last year
- An offensive postexploitation tool that will give you complete control over the Outlook desktop application and therefore to the emails cβ¦β166Oct 9, 2024Updated last year
- Burp Suite Configuration Tweakβ13Mar 15, 2024Updated 2 years ago
- Customized CVE FEED Notifierβ114Jul 3, 2026Updated 2 months ago