Python Pentesting

Open-source Python projects categorized as Pentesting

Top 23 Python Pentesting Projects

  1. sherlock

    Hunt down social media accounts by username across social networks

    Project mention: Sherlock: Hunt down social media accounts by username across 400 social networks | news.ycombinator.com | 2024-12-25

    the only data needed are the urls from https://github.com/sherlock-project/sherlock/blob/master/she...

    [1] https://www.reddit.com/r/github/comments/1at9br4/i_am_new_to...

  2. CodeRabbit

    CodeRabbit: AI Code Reviews for Developers. Revolutionize your code reviews with AI. CodeRabbit offers PR summaries, code walkthroughs, 1-click suggestions, and AST-based analysis. Boost productivity and code quality across all major languages with each PR.

    CodeRabbit logo
  3. SQLMap

    Automatic SQL injection and database takeover tool

    Project mention: The Impact of Open-Source Tools in Cyber Warfare: A Deep Dive | dev.to | 2025-03-06

    Open-source tools have led to a significant transformation in cyber warfare for two primary reasons: cost-effectiveness and community-driven innovation. Tools such as SQLmap and Aircrack-ng exemplify how attackers exploit vulnerabilities, making it easier for individuals with limited resources to engage in cyber exploits. Conversely, defensive tools like Snort and OSSEC empower security professionals to monitor networks and system logs, helping organizations detect and mitigate breaches in real time. The evolution does not stop at merely having access to these tools but extends to how continuously they are updated and improved. The community-driven nature of open-source software encourages ongoing enhancements and shared knowledge. This, however, is paired with increased risk. With any tool that is available to all, the challenge of distinguishing ethical use from malicious intent becomes prominent, placing a heavier burden on security professionals to adapt and be vigilant.

  4. Ciphey

    ⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡

  5. spiderfoot

    SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

    Project mention: SpiderFoot automates OSINT for threat intelligence | news.ycombinator.com | 2024-07-03

    Some would disagree with that statement: <https://github.com/smicallef/spiderfoot/issues>

      The little development on the project is probably due to it's age.

  6. dirsearch

    Web path scanner

  7. owasp-mastg

    The Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the controls listed in the OWASP Mobile Application Security Verification Standard (MASVS).

    Project mention: The Case for Standards in Mobile App Security | dev.to | 2024-07-31

    The OWASP Mobile Application Security (MAS) flagship project provides a robust security standard for mobile apps, known as the OWASP MASVS, along with a comprehensive testing guide (OWASP MASTG). These resources cover the processes, techniques, and tools used during a mobile app security test, ensuring consistent and complete results.

  8. pupy

    Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C

  9. SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
  10. bbot

    The recursive internet scanner for hackers. 🧡

    Project mention: Blacklanternsecurity / Bbot | news.ycombinator.com | 2024-12-13
  11. DefaultCreds-cheat-sheet

    One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

  12. androguard

    Reverse engineering and pentesting for Android applications

  13. faraday

    Open Source Vulnerability Management Platform (by infobyte)

  14. commix

    Automated All-in-One OS Command Injection Exploitation Tool.

  15. PhoneSploit-Pro

    An all-in-one hacking tool to remotely exploit Android devices using ADB and Metasploit-Framework to get a Meterpreter session.

  16. drozer

    The Leading Security Assessment Framework for Android.

  17. Villain

    Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).

  18. Nettacker

    Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

    Project mention: Nettacker: Open-Source Automated Penetration Testing and Vulnerability Scanner | news.ycombinator.com | 2024-09-03
  19. pocsuite3

    pocsuite3 is an open-sourced remote vulnerability testing framework developed by the Knownsec 404 Team.

  20. NetExec

    The Network Execution Tool

    Project mention: Hack The Box Writeup: Heist | dev.to | 2024-07-05

    NOTE: The last time I rooted this machine, it was July 2023. At time of editing, (July 2024), CrackMapExec has been deprecated, and it's generally recommended to use NetExec (NXC). The syntax should be very similar, and it should get you through this portion of the writeup.

  21. blackbird

    An OSINT tool to search for accounts by username and email in social networks. (by p1ngul1n0)

  22. Raccoon

    A high performance offensive security tool for reconnaissance and vulnerability scanning

  23. malicious-pdf

    💀 Generate a bunch of malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh

  24. slowloris

    Low bandwidth DoS tool. Slowloris rewrite in Python.

  25. CloudFail

    Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network

  26. SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

Python Pentesting discussion

Log in or Post with

Python Pentesting related posts

  • The Case for Standards in Mobile App Security

    1 project | dev.to | 31 Jul 2024
  • Hack The Box Writeup: Heist

    4 projects | dev.to | 5 Jul 2024
  • SSH-Snake: Automated SSH-Based Network Traversal

    5 projects | news.ycombinator.com | 5 Jan 2024
  • Google Play rolls out an "Independent security review" badge for apps

    2 projects | news.ycombinator.com | 3 Nov 2023
  • Code from the book “Black Hat Python” refactored and ported to Python 3

    1 project | news.ycombinator.com | 15 Jun 2023
  • Where do you look for help when doing ctf

    1 project | /r/Hacking_Tutorials | 8 Jun 2023
  • Securing PDF Generators Against SSRF Vulnerabilities

    1 project | /r/netsec | 30 May 2023
  • A note from our sponsor - CodeRabbit
    coderabbit.ai | 19 Mar 2025
    Revolutionize your code reviews with AI. CodeRabbit offers PR summaries, code walkthroughs, 1-click suggestions, and AST-based analysis. Boost productivity and code quality across all major languages with each PR. Learn more →

Index

What are some of the best open-source Pentesting projects in Python? This list will help you:

# Project Stars
1 sherlock 62,984
2 SQLMap 33,559
3 Ciphey 18,814
4 spiderfoot 13,911
5 dirsearch 12,660
6 owasp-mastg 12,041
7 pupy 8,616
8 bbot 8,157
9 DefaultCreds-cheat-sheet 5,985
10 androguard 5,473
11 faraday 5,265
12 commix 5,181
13 PhoneSploit-Pro 4,992
14 drozer 4,094
15 Villain 3,945
16 Nettacker 3,881
17 pocsuite3 3,694
18 NetExec 3,663
19 blackbird 3,277
20 Raccoon 3,156
21 malicious-pdf 2,953
22 slowloris 2,518
23 CloudFail 2,306

Sponsored
CodeRabbit: AI Code Reviews for Developers
Revolutionize your code reviews with AI. CodeRabbit offers PR summaries, code walkthroughs, 1-click suggestions, and AST-based analysis. Boost productivity and code quality across all major languages with each PR.
coderabbit.ai

Did you know that Python is
the 2nd most popular programming language
based on number of references?