GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.
☆13,673May 27, 2026Updated 3 months ago
Alternatives and similar repositories for GTFOBins.github.io
Users that are interested in GTFOBins.github.io are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)☆8,813Updated this week
- PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)☆20,543Updated this week
- Scripted Local Linux Enumeration & Privilege Escalation Checks☆8,034Sep 6, 2023Updated 3 years ago
- A list of useful payloads and bypass for Web Application Security and Pentest/CTF☆80,936Aug 27, 2026Updated 3 weeks ago
- Impacket is a collection of Python classes for working with network protocols.☆16,095Updated this week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in …☆73,571Updated this week
- Monitor linux processes without root permissions☆6,180Mar 1, 2026Updated 6 months ago
- Nishang - Offensive PowerShell for red team, penetration testing and offensive security.☆10,109Apr 25, 2024Updated 2 years ago
- Linux privilege escalation auditing tool☆6,614Mar 20, 2026Updated 5 months ago
- PowerSploit - A PowerShell Post-Exploitation Framework☆13,084Aug 17, 2020Updated 6 years ago
- Linux enumeration tool for pentesting and CTFs with verbosity levels☆3,986May 3, 2026Updated 4 months ago
- The ultimate WinRM shell for hacking/pentesting☆5,508Sep 4, 2026Updated 2 weeks ago
- Fast web fuzzer written in Go☆16,686Sep 9, 2026Updated last week
- A swiss army knife for pentesting networks☆9,163Dec 6, 2023Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and n…☆12,276Updated this week
- Six Degrees of Domain Admin☆10,614Mar 2, 2026Updated 6 months ago
- Trying to tame the three-headed dog.☆5,170May 21, 2026Updated 3 months ago
- Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabl…☆31,342Updated this week
- Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv…☆6,589Jun 10, 2026Updated 3 months ago
- CTF framework and exploit development library☆13,703Sep 3, 2026Updated 2 weeks ago
- Adversary Emulation Framework☆11,850Updated this week
- Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensi…☆4,701Jan 10, 2025Updated last year
- A little tool to play with Windows security☆21,844Apr 17, 2026Updated 5 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Small and highly portable detection tests based on MITRE's ATT&CK.☆12,549Updated this week
- Windows Exploit Suggester - Next Generation☆4,935Updated this week
- AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.☆6,112Jan 28, 2026Updated 7 months ago
- A tool to perform Kerberos pre-auth bruteforcing☆3,447Aug 20, 2024Updated 2 years ago
- Directory/File, DNS and VHost busting tool written in Go☆14,125Sep 9, 2026Updated last week
- In-depth attack surface mapping and asset discovery☆15,175Jul 19, 2026Updated last month
- A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.☆9,062Dec 4, 2025Updated 9 months ago
- This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on th…☆4,231May 11, 2023Updated 3 years ago
- Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.☆5,304Sep 8, 2026Updated last week
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- RSA attack tool (mainly for ctf) - retrieve private key from weak public key and/or uncipher data☆7,127Updated this week
- A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts t…☆2,827Dec 18, 2021Updated 4 years ago
- This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.☆10,716May 7, 2026Updated 4 months ago
- JAWS - Just Another Windows (Enum) Script☆2,002Apr 19, 2021Updated 5 years ago
- Web path scanner☆14,731Updated this week
- Server-Side Template Injection and Code Injection Detection and Exploitation Tool☆4,202Apr 21, 2024Updated 2 years ago
- Covenant is a collaborative .NET C2 framework for red teamers.☆4,736Jul 18, 2024Updated 2 years ago