PyRank
  • Insights
  • PyPI
  • GitHub
  • Search
  • Compare
  • Advisories
  • Ecosystem
  • About

Penetration Testing Python Packages

Python packages with the GitHub topic penetration-testing. Sorted by relevance, with stars and monthly downloads.
Paradoxis
flask-unsign

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

62K 644 47
maurosoria
dirsearch

Web path scanner

24K 14K 2K
Usta0x001
phantom-agent

Autonomous Offensive Security Intelligence - AI-powered penetration testing

17K 13 4
ncouture
mockssh

Mock an SSH server and define all commands it supports (Python, Twisted)

16K 130 25
Paradoxis
flask-unsign-wordlist

The following package is the standalone wordlist-only component to flask-unsign.

14K 44 13
dalisecurity
fray

Open-source WAF Security Testing Platform — 7,200+ attack payloads, 98 WAF/CDN fingerprints, AI-powered bypass engine, recon pipeline, beautiful CLI output

11K 50 4
ThePorgs
exegol

Fully featured and community-driven hacking environment

7K 3K 276
0xSteph
ptai

Offensive-security MCP server with 205 wrapped tools, 17 specialist agents, and 60 SPA-aware probes for OWASP Top 10. CLI + MCP, BYO LLM. No API key needed on MCP path.

7K 255 52
AlaBouali
bane

This Python library offers a comprehensive set of tools for various cybersecurity and networking tasks. Its functionalities encompass diverse capabilities such as bruteforce attacks, cryptographic methods, DDoS attacks, information gathering, botnet creation and management, CMS vulnerability scanning, network discovery, vulnerability scanning, useful modules for common tasks, web page analyzers, and proxy utilities making it a powerful toolkit for cybersecurity professionals and network administrators.

7K 358 70
nikitastupin
clairvoyance

Obtain GraphQL API schema even if the introspection is disabled

6K 1K 132
ADscanPro
adscan

Free Active Directory pentesting tool and Linux CLI for AD enumeration, BloodHound, Kerberoasting, ADCS, DCSync, and attack paths.

5K 299 36
cytopia
netcat

pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully scriptable with Python (PSE)

4K 2K 216
Grunny
zapcli

A simple tool for interacting with OWASP ZAP from the commandline.

4K 258 70
ExploitCraft
reconninja

38-phase automated reconnaissance framework for security researchers

4K 39 7
infobyte
faradaysec

Open Source Vulnerability Management Platform

4K 6K 1K
Unclecheng-li
vulnclaw

基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。

4K 46 8
gkbrk
slowloris

Low bandwidth DoS tool. Slowloris rewrite in Python.

3K 3K 736
Paradoxis
stegcracker

Steganography brute-force utility to uncover hidden data inside files

3K 594 106
mattybellx
ansede-static

Ansede Static: Next-Gen SAST Engine — Fast, Offline, Security for Modern Codebases Detect critical security vulnerabilities and code quality issues in Python, JavaScript, and TypeScript projects with a single command. No dependencies, no cloud, no setup—just download, unzip, and scan any folder instantly.

3K 4 0
appthreat
wasm-tools

A WebAssembly parser and disassembler in python.

3K 0 0
fsociety-team
fsociety

A Modular Penetration Testing Framework

2K 2K 205
taoq-ai
ziran

自然 ZIRAN is an open-source security testing framework for AI agents. It discovers dangerous tool chain compositions via knowledge graph analysis, detects execution-level side effects (not just text output), and runs multi-phase trust exploitation campaigns that model real attacker behaviour.

2K 6 1
guelfoweb
knock-subdomains

Knock Subdomain Scan

2K 4K 882
GamehunterKaan
autopwn-suite

AutoPWN Suite is a project for scanning vulnerabilities and exploiting systems automatically.

2K 1K 131
    • Data from PyPI, GitHub, ClickHouse, and BigQuery