π GoatOS - A lightweight Linux distribution focused on Web & API penetration testing. Built on Debian with GNOME, featuring nuclei, httpx, ffuf, Burp Suite, and curated tools. Unlike Kali/Parrot, we focus exclusively on web security.
β18Dec 26, 2025Updated 6 months ago
Alternatives and similar repositories for GoatOS
Users that are interested in GoatOS are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Framework Automatizado de Reconocimiento y ExplotaciΓ³nβ17Mar 8, 2026Updated 4 months ago
- C programs for sockets, reverse shell, shellcode execution, and process injection.β24Dec 10, 2025Updated 7 months ago
- GitHub - therealilyas/pentest-toolkit: PentestKit β Advanced penetration testing toolkit in Python & Bash for bug bounty and ethical hackβ¦β33Feb 26, 2026Updated 4 months ago
- JSHawk is a powerful, context-aware JavaScript security scanner that hunts for exposed credentials, API keys, and sensitive information iβ¦β17Apr 13, 2026Updated 3 months ago
- A production-ready, enterprise-grade MDR framework that transforms chaotic security alerts into structured, actionable intelligence.β23Feb 14, 2026Updated 5 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer β’ AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- This C# tool sprays for admin access over the entire domainβ89Dec 7, 2025Updated 7 months ago
- β79Jan 1, 2026Updated 6 months ago
- GhostBuilder is a powerful payload generator tool designed for ethical hacking, red-teaming, penetration testing, and security researchβ26Jun 12, 2026Updated last month
- PowerShell tool for auditing Microsoft Entra ID Conditional Access policies and MFA complianceβ45Aug 2, 2025Updated 11 months ago
- ε ζζ¨ι©¬ζ ·ζ¬β107Oct 11, 2025Updated 9 months ago
- Rust-powered HTTP Request Smuggling Scanner.β125Updated this week
- This tool is a modern evolution of older PoCs like those for CVE-2017-7921 and ICSA-17-124-01, updated for 2025 with live console output,β¦β19Nov 19, 2025Updated 8 months ago
- An Implementation of LoRa for EmComm (Emergency Communication) or (TacComm) Tactical Communicationβ20Jul 23, 2025Updated 11 months ago
- A powerful URL parameter and request fuzzing tool that processes URLs or Burp Suite raw requests, replacing values with custom payloads wβ¦β21Apr 12, 2026Updated 3 months ago
- GPU virtual machines on DigitalOcean Gradient AI β’ AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Automatically look for paramater reflections in the HTTP responseβ17Apr 30, 2025Updated last year
- Fortinet FortiClientEMS improper access controlβ36Apr 20, 2026Updated 3 months ago
- PowerShell scripts for Windows system administrationβ22Mar 5, 2026Updated 4 months ago
- Sniffs outbound traffic for suspicious, beacon-like callbacks, because if it keeps coming back on schedule, it's probably not breakfast.β20Jan 22, 2026Updated 5 months ago
- A comprehensive MCP server for Windows digital forensics on KALI Linuxβ19May 21, 2026Updated last month
- Import and export custom Sysmon configurations using an interactive GUI that lets you build event rules, manage filters, and generate cleβ¦β31Mar 10, 2026Updated 4 months ago
- Tools & TTP's for Active Directory Red Teamingβ32Dec 22, 2024Updated last year
- Cobalt Strike module x loader x profile x wike / A public collection of open resources for Cobalt Strike (only legal use in Red Team and β¦β125Jun 6, 2026Updated last month
- KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Microβ¦β157Apr 1, 2026Updated 3 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI β’ AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- ReconRoyale challenges, bug bounty experiments, and penetration testing notes | Red Team, subdomain, and cloud asset discoveryβ18Apr 2, 2026Updated 3 months ago
- An Obsidian-Based Second Brain for CyberSecurity Analysts and Professionalsβ59Feb 18, 2026Updated 5 months ago
- LEGION2 - A free and open-source penetration testing tool. Forked from an earlier version of LEGION, which was originally created by Gothβ¦β27Jun 22, 2026Updated 3 weeks ago
- π Chrome Extension - Detect hardcoded tokens, API keys & secrets in JavaScript filesβ46Dec 15, 2025Updated 7 months ago
- A curated collection of my security research and bug bounty writeups, documenting real-world vulnerabilities, exploitation methodsβ26Updated this week
- Web File Managerβ11Jul 2, 2026Updated 2 weeks ago
- Next-generation intelligent Web Fuzzer & Directory Scanner written in Go. Features WAF detection, secret scanning, auto-calibration, and β¦β26Mar 26, 2026Updated 3 months ago
- β11May 16, 2025Updated last year
- Unofficial MCP server for accessing your HackerOne reports, programs, scope, and earnings from Claude Codeβ40Apr 1, 2026Updated 3 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer β’ AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- β24Oct 8, 2025Updated 9 months ago
- Maximize your bug bounty hunting efficiency with exp0s3d - the open-source tool that automates initial reconnaissance and vulnerability dβ¦β89Mar 20, 2025Updated last year
- Penetration Testing Notes of OSCP made for Obsidianβ49May 2, 2026Updated 2 months ago
- ProfileHound - BloodHound OpenGraph collector for user profiles stored on domain machines. Make informed decisions about looting secrets β¦β163Jul 8, 2026Updated last week
- A web application testing tool built for capturing and modifying http/https requests.β23Updated this week
- Single source of truth for GenAI and agentic AI security incidents, mapped to OWASP LLM Top 10, OWASP Agentic Top 10 (ASI), NIST AI RMF, β¦β27Updated this week
- A lightweight Command and Control (C2) framework built for offensive security research and red teaming (Post Exploitation).β68Dec 17, 2025Updated 7 months ago