Kargo automates promotion across dev, staging, and prod with approval gates and verification. Open source, built by the team behind Argo CD. Download now. Learn more →
Top 23 Penetration Testing Open-Source Projects
-
Awesome-Hacking
A collection of various awesome lists for hackers, pentesters and security researchers
-
AppSignal
AppSignal knows why the f*#k it crashed. Stop vibe-debugging. Every exception, every backtrace, grouped so you see patterns, not noise.
-
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
-
would love it to see it h2h against https://github.com/usestrix/strix (45k stars)
-
shannon
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.
-
Anthropic-Cybersecurity-Skills
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Project mention: Anthropic-Cybersecurity-Skills:817 structured cybersecurity skills for AI agents | news.ycombinator.com | 2026-06-23 -
h4cker
This repository is maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), AI security, vulnerability research, exploit development, reverse engineering, and more. 🔥 Also check: https://hackertraining.org
-
Project mention: Current Frontline in AI Agent Development: Robust Agent Design and Security Measures | dev.to | 2026-03-23
-
Kargo
Stop Scripting Promotions. Start Shipping with Kargo. Kargo automates promotion across dev, staging, and prod with approval gates and verification. Open source, built by the team behind Argo CD. Download now.
-
Awesome-Hacking-Resources
A collection of hacking / penetration testing resources to make you better!
-
-
setoolkit
The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.
-
-
Osintgram
Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname
-
-
-
-
Sn1per
Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.
-
-
wstg
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
Project mention: Multi-Tenant Audit Logging: The Architecture Mistakes We Made | dev.to | 2026-04-26We added these integration tests after the incident. They should have been there from the start. Per OWASP's testing guide, multi-tenant isolation testing should be part of your standard security test suite.
-
-
Scanners-Box
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
-
rengine
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.
-
reconftw
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
-
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
Penetration Testing discussion
Penetration Testing related posts
-
Show HN: Ansede – Free SAST with 100% CVE recall (Semgrep CE got 23%)
-
I Built a 100% Offline SAST Scanner That Finds What Semgrep and CodeQL Miss
-
I Built an Offline SAST Scanner — Try It on Your Code and Tell Me Where It Fails
-
Ansede – an offline SAST scanner I built to catch IDOR and auth bypass
-
Show HN: AI-native red-team for penetration testing and vulnerability research
-
Show HN: Z3r0 – Multi-agent red team collaboration platform
-
Multi-Tenant Audit Logging: The Architecture Mistakes We Made
-
A note from our sponsor - Kargo
akuity.io | 12 Sep 2026
Index
What are some of the best open-source Penetration Testing projects? This list will help you:
| # | Project | Stars |
|---|---|---|
| 1 | Awesome-Hacking | 120,069 |
| 2 | PayloadsAllTheThings | 80,760 |
| 3 | strix | 61,796 |
| 4 | shannon | 47,781 |
| 5 | Anthropic-Cybersecurity-Skills | 32,637 |
| 6 | h4cker | 29,366 |
| 7 | pentagi | 22,647 |
| 8 | Awesome-Hacking-Resources | 17,384 |
| 9 | PentestGPT | 15,404 |
| 10 | setoolkit | 15,284 |
| 11 | dirsearch | 14,709 |
| 12 | Osintgram | 14,089 |
| 13 | awesome-web-security | 13,781 |
| 14 | fsociety | 12,306 |
| 15 | thc-hydra | 12,260 |
| 16 | Sn1per | 11,227 |
| 17 | nishang | 10,003 |
| 18 | wstg | 9,803 |
| 19 | RedTeam-Tools | 9,699 |
| 20 | Scanners-Box | 9,040 |
| 21 | rengine | 8,813 |
| 22 | reconftw | 8,096 |
| 23 | cve | 8,048 |