Ruby Pentesting

Open-source Ruby projects categorized as Pentesting

Top 8 Ruby Pentesting Projects

  1. WhatWeb

    Next generation web scanner

  2. SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
  3. evil-winrm

    The ultimate WinRM shell for hacking/pentesting

    Project mention: HTB – AD Enumeration & Attacks – Skills Assessment Part I - Walkthrough - without Metasploit | dev.to | 2026-05-02

    ─[eu-academy-1]─[10.10.14.30]─[htb-ac-2510340@htb-hnkzcchgmi]─[~] └──╼ [★]$ proxychains evil-winrm -i 172.16.6.3 -u Administrator -H 27dedb1dab4d8545c6e1c66fba077da0 [proxychains] config file found: /etc/proxychains.conf [proxychains] preloading /usr/lib/x86_64-linux-gnu/libproxychains.so.4 [proxychains] DLL init: proxychains-ng 4.16 Evil-WinRM shell v3.5 Warning: Remote path completions is disabled due to ruby limitation: quoting_detection_proc() function is unimplemented on this machine Data: For more information, check Evil-WinRM GitHub: https://github.com/Hackplayers/evil-winrm#Remote-path-completion Info: Establishing connection to remote endpoint [proxychains] Strict chain ... 127.0.0.1:1080 ... 172.16.6.3:5985 ... OK PS C:\Users\Administrator\Desktop> whoami [proxychains] Strict chain ... 127.0.0.1:1080 ... 172.16.6.3:5985 ... OK [proxychains] Strict chain ... 127.0.0.1:1080 ... 172.16.6.3:5985 ... OK inlanefreight\administrator

  4. capsulecorp-pentest

    Vagrant VirtualBox environment for conducting an internal network penetration test

  5. haiti

    :key: Hash type identifier (CLI & lib)

  6. dradis-ce

    Dradis Framework: Collaboration and reporting for IT Security teams

  7. ronin-vulns

    Tests URLs for Local File Inclusion (LFI), Remote File Inclusion (RFI), SQL injection (SQLi), and Cross Site Scripting (XSS), Server Side Template Injection (SSTI), and Open Redirects.

  8. vulnerable-code-snippets

    Vulnerable code snippets repository showcasing different vulnerabilities to practice code analysis skills. (by Acceis)

  9. hedra

    Hedra — Command-line tool to analyze HTTP security headers and detect missing protections like CSP, HSTS, and X-Frame-Options. (by bl4ckstack)

    Project mention: Hedra | news.ycombinator.com | 2025-12-04

    Check out my new security tool:Command-line tool to analyze HTTP security headers and detect missing protections like CSP, HSTS, and X-Frame-Options.https://github.com/bl4ckstack/hedra

NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

Ruby Pentesting discussion

Log in or Post with

Ruby Pentesting related posts

  • what Do YOU Recommend?

    2 projects | /r/hacking | 20 Apr 2023
  • Lazypariah - A tool for generating reverse shell payloads on the fly

    1 project | /r/hacking | 21 Jul 2022
  • LAZYPARIAH: A tool for generating reverse shell payloads on the fly.

    1 project | /r/coolgithubprojects | 25 Mar 2021

Index

What are some of the best open-source Pentesting projects in Ruby? This list will help you:

# Project Stars
1 WhatWeb 6,634
2 evil-winrm 5,395
3 capsulecorp-pentest 985
4 haiti 984
5 dradis-ce 817
6 ronin-vulns 78
7 vulnerable-code-snippets 23
8 hedra 9

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com

Did you know that Ruby is
the 13th most popular programming language
based on number of references?