Penetration testing tools cheat sheet, a quick reference high level overview for typical penetration testing engagements. Convenient commands for your pentesting / red-teaming engagements, OSCP and CTFs.
☆104Oct 13, 2025Updated 10 months ago
Alternatives and similar repositories for Offensive-Enumeration
Users that are interested in Offensive-Enumeration are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A proper approach to pentest a Web application with the mixture of all useful payloads and complete testing guidance of attacks. Designed…☆121Feb 12, 2025Updated last year
- Scripts that are intended to help you in your pen-testing and bug-hunting efforts by automating various manual tasks, making your work mo…☆104Jul 12, 2026Updated last month
- List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.☆454Mar 16, 2026Updated 5 months ago
- Passive Reconnaissance Techniques Approach helps for penetration testing and bug bounty hunting by gathering information about a target s…☆20Aug 19, 2025Updated last year
- Collection of Penetration Testing Interview Questions across various domains, including Information Security, Network Security, Web Secur…☆77Jul 14, 2026Updated last month
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- This script was developped to assist in SpearPhishing campaign during Red Team operations. It can be used to generate random name based o…☆13Feb 6, 2023Updated 3 years ago
- ☆17Apr 5, 2021Updated 5 years ago
- ☆13Aug 31, 2020Updated 6 years ago
- ☆13Jan 4, 2022Updated 4 years ago
- Extract endpoints marked as disallow in robots files to generate wordlists.☆60Mar 2, 2022Updated 4 years ago
- Reconnaisance Tool☆12Jun 4, 2020Updated 6 years ago
- ☆11Dec 17, 2023Updated 2 years ago
- DirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it☆13Mar 5, 2021Updated 5 years ago
- A simple bug bounty utility tool to remove uninteresting entries from a list of URLs.☆13Jul 22, 2024Updated 2 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- A curated list of censorship circumvention tools☆21Oct 6, 2024Updated last year
- Autorev.sh generates reverse shell codes for reverse shell . Supports linux and windows☆17Apr 8, 2022Updated 4 years ago
- Burp Suite extension for extracting metadata from files☆20Dec 29, 2020Updated 5 years ago
- c0vertX - The Art of Hiding Messages in Plain Sight☆10Oct 31, 2022Updated 3 years ago
- A substitute repository put up on public demand for the original Awesome WAF repository (https://github.com/0xInfection/Awesome-WAF) whic…☆14May 3, 2019Updated 7 years ago
- Kaspersky Security Center: custom decoders and rules for Wazuh SIEM☆27Aug 16, 2024Updated 2 years ago
- My Gitbook CyberSec Notes☆21Oct 22, 2025Updated 10 months ago
- 👾 blockchain starting kit - rust edition☆26Oct 14, 2024Updated last year
- Удобная установка, настройка и управление Zapret2 через claude code или codex.☆27Mar 28, 2026Updated 5 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- A script to test for subdomain takeovers from a list of domains☆12Feb 18, 2023Updated 3 years ago
- Ant is a post-exploitation tool designed to automate the deployment of tunnels and port forwarding based on a predefined topology configu…☆17Jan 31, 2024Updated 2 years ago
- Commands, snippets, exploits, tools, lists, collections and techniques I used on my journey to becoming an OSCP.☆320Mar 10, 2021Updated 5 years ago
- Compiling a list of free learning resources in different areas of tech☆14Jul 19, 2023Updated 3 years ago
- ☆27Jan 27, 2022Updated 4 years ago
- IP/FQDN data structure helper with randomization of hosts and ports based on masscan internal logic☆72Updated this week
- For finding secrets, tokens and other common mistakes made by developers.☆12Oct 21, 2025Updated 10 months ago
- Wireless Pentest☆18Apr 5, 2018Updated 8 years ago
- ☆21Aug 28, 2022Updated 4 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- A Discord bot custom-built for the HoloPro fans server, but can be hosted for use on other Hololive servers as well!☆10Jun 18, 2023Updated 3 years ago
- Sample Obsidian's vault for web pentesting☆114Aug 8, 2024Updated 2 years ago
- Bypass 4xx HTTP response status codes and more. Based on PycURL.☆16Jun 27, 2022Updated 4 years ago
- A command line tool that reads from stdin and strips ANSI color codes from the input.☆10Feb 11, 2023Updated 3 years ago
- Everything about xss protection technology☆15Oct 22, 2019Updated 6 years ago
- H&E- Burp Highlighter and Extractor☆18Mar 29, 2023Updated 3 years ago
- Burp suite extension to find sensitive information by checking incoming text OR binary websocket messages☆60Jul 17, 2026Updated last month