SaaSHub helps you find the best software and product alternatives Learn more →
Top 23 Python Pentest Projects
-
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
if you've never worked on SQL injection that's fine there is a PWNSOME REPOSITORY(get it? pwn + awesome) called[ Payload All The Things (https://github.com/swisskyrepo/PayloadsAllTheThings) it has different payloads for different web vulnerabilities.
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
-
Project mention: Wanted to spy on my dog, ended up spying on TP-Link | news.ycombinator.com | 2025-09-15
-
DefaultCreds-cheat-sheet
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
-
-
Villain
Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).
-
Project mention: Snoop Project Update (search for usernames on 5k websites) | news.ycombinator.com | 2026-01-01
-
-
pentest-wiki
PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others.
-
CloudFlair
🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.
-
reconspider
🔎 Most Advanced Open Source Intelligence (OSINT) Framework for scanning IP Address, Emails, Websites, Organizations.
-
CloudFail
Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network
-
SysReptor
A customizable and powerful penetration testing reporting platform for offensive security professionals. Simplify, customize, and automate your pentest reports with ease.
-
-
pyrdp
RDP monster-in-the-middle (mitm) and library for Python with the ability to watch connections live or after the fact
-
-
GraphQLmap
GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)
-
enum4linux-ng
A next generation version of enum4linux (a Windows/Samba enumeration tool) with additional features like JSON/YAML export. Aimed for security professionals and CTF players.
-
-
-
-
-
-
DumpsterFire
"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.
Python Pentest discussion
Python Pentest related posts
-
Snoop Project Update (search for usernames on 5k websites)
-
Irish-Name-Repo 2 - picoCTF '19 (web)
-
List of Useful Payloads and Bypass for Web Application Security and Pentest/CTF
-
PayloadsAllTheThings: Essential Payloads and Bypass for Web Security and CTFs
-
Hack The Box Writeup: Heist
-
Osint update of the Snoop Project tool search for user by nickname
-
php shell not executed in wordpress
-
A note from our sponsor - SaaSHub
www.saashub.com | 12 Jun 2026
Index
What are some of the best open-source Pentest projects in Python? This list will help you:
| # | Project | Stars |
|---|---|---|
| 1 | PayloadsAllTheThings | 78,311 |
| 2 | objection | 9,188 |
| 3 | DefaultCreds-cheat-sheet | 6,600 |
| 4 | NetExec | 5,585 |
| 5 | Villain | 4,382 |
| 6 | snoop | 3,944 |
| 7 | patator | 3,883 |
| 8 | pentest-wiki | 3,743 |
| 9 | CloudFlair | 2,949 |
| 10 | reconspider | 2,621 |
| 11 | CloudFail | 2,528 |
| 12 | SysReptor | 2,491 |
| 13 | pwn_jenkins | 2,092 |
| 14 | pyrdp | 1,768 |
| 15 | odat | 1,761 |
| 16 | GraphQLmap | 1,668 |
| 17 | enum4linux-ng | 1,591 |
| 18 | SSTImap | 1,530 |
| 19 | Redcloud | 1,272 |
| 20 | VcenterKit | 1,254 |
| 21 | BeeLogger | 1,152 |
| 22 | pywerview | 1,124 |
| 23 | DumpsterFire | 1,035 |