Go Pentesting

Open-source Go projects categorized as Pentesting

Top 23 Go Pentesting Projects

  1. ffuf

    Fast web fuzzer written in Go

    Project mention: Bug Bounty Hidden Treasures | dev.to | 2025-03-26

    I utilized ffuf to enumerate directories since it's faster and also has great flags that can help you get the results you want. I discovered quite a number of directories that looked like normal stuff and un interesting. I then discovered one called "/system/ which seemed more interesting and fun to probe further. I fuzzed it, and then I discovered an endpoint "/system/auth" that allowed users to authenticate to the application via a login form, as shown below.

  2. CodeRabbit

    CodeRabbit: AI Code Reviews for Developers. Revolutionize your code reviews with AI. CodeRabbit offers PR summaries, code walkthroughs, 1-click suggestions, and AST-based analysis. Boost productivity and code quality across all major languages with each PR.

    CodeRabbit logo
  3. gobuster

    Directory/File, DNS and VHost busting tool written in Go

    Project mention: Ask HN: How to find subdomains and paths for a website | news.ycombinator.com | 2024-06-01

    Are you looking for something like Gobuster?

    https://github.com/OJ/gobuster

  4. hetty

    An HTTP toolkit for security research.

  5. osmedeus

    A Workflow Engine for Offensive Security

  6. pspy

    Monitor linux processes without root permissions

  7. hakrawler

    Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

  8. Cameradar

    Cameradar hacks its way into RTSP videosurveillance cameras

  9. InfluxDB

    InfluxDB high-performance time series database. Collect, organize, and act on massive volumes of high-resolution data to power real-time intelligent systems.

    InfluxDB logo
  10. ligolo-ng

    An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.

  11. Stowaway

    👻Stowaway -- Multi-hop Proxy Tool for pentesters

  12. ksubdomain

    无状态子域名爆破工具

  13. ruler

    A tool to abuse Exchange services

  14. cariddi

    Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

  15. gitjacker

    🔪 :octocat: Leak git repositories from misconfigured websites

  16. metabigor

    OSINT tools and more but without API key

  17. nomore403

    Tool to bypass 403/40X response codes.

  18. pretender

    Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing. (by RedTeamPentesting)

  19. reverse_ssh

    SSH based reverse shell

    Project mention: Reverse SSH – Have your SSH daemon connect back to you | news.ycombinator.com | 2024-05-29
  20. scilla

    Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration

  21. CloudBrute

    Awesome cloud enumerator

    Project mention: ⛈️ Cloud Penetration Testing: A Practical Guide to Securing Your Cloud Infrastructure | dev.to | 2024-12-03

    # Clone and setup CloudBrute git clone https://github.com/0xsha/CloudBrute cd CloudBrute # Run a scan against a target domain ./CloudBrute -d target.com -k wordlist.txt -m storage -t 80

  22. cent

    Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place (by xm1k3)

  23. gosearch

    🔍 Search anyone's digital footprint across 300+ websites (by ibnaleem)

    Project mention: Show HN: Osint tool for searching people's digital footprint | news.ycombinator.com | 2025-01-11
  24. shortscan

    An IIS short filename enumeration tool

  25. nmap-formatter

    A tool that allows you to convert NMAP results to html, csv, json, markdown, graphviz (dot), sqlite, excel and d2-lang. Simply put it's nmap converter.

  26. SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

Go Pentesting discussion

Log in or Post with

Go Pentesting related posts

  • Bug Bounty Hidden Treasures

    1 project | dev.to | 26 Mar 2025
  • How to Explore an Exposed .git

    1 project | dev.to | 22 Aug 2024
  • Ask HN: How to find subdomains and paths for a website

    3 projects | news.ycombinator.com | 1 Jun 2024
  • Show HN: Pfuzz, a web fuzzer following the Unix philosophy

    6 projects | news.ycombinator.com | 21 Jan 2024
  • Fast web fuzzer written in Go

    1 project | news.ycombinator.com | 24 Dec 2023
  • Stowaway -- Multi-hop Proxy Tool for pentesters

    1 project | /r/hacking | 13 Nov 2023
  • Ask HN: What's the big deal with Go (Golang)?

    3 projects | news.ycombinator.com | 12 Oct 2023
  • A note from our sponsor - InfluxDB
    influxdata.com | 17 Apr 2025
    Collect, organize, and act on massive volumes of high-resolution data to power real-time intelligent systems. Learn more →

Index

What are some of the best open-source Pentesting projects in Go? This list will help you:

# Project Stars
1 ffuf 13,743
2 gobuster 11,361
3 hetty 6,840
4 osmedeus 5,549
5 pspy 5,346
6 hakrawler 4,641
7 Cameradar 4,291
8 ligolo-ng 3,344
9 Stowaway 2,978
10 ksubdomain 2,289
11 ruler 2,220
12 cariddi 1,643
13 gitjacker 1,563
14 metabigor 1,317
15 nomore403 1,231
16 pretender 1,088
17 reverse_ssh 1,064
18 scilla 1,006
19 CloudBrute 999
20 cent 972
21 gosearch 958
22 shortscan 910
23 nmap-formatter 677

Sponsored
CodeRabbit: AI Code Reviews for Developers
Revolutionize your code reviews with AI. CodeRabbit offers PR summaries, code walkthroughs, 1-click suggestions, and AST-based analysis. Boost productivity and code quality across all major languages with each PR.
coderabbit.ai