A curated list of tools, frameworks, and resources for vulnerability scanning, exploitation, and management. Perfect for red teams, blue teams, and security researchers.
Credit: xkcd, modified via explainxkcd
- Vulnerability Scanners
- Exploitation Frameworks
- Vulnerability Management
- Cloud & Container Security
- API Security
- Exploit Databases
- Labs & Practice
- Resources & Learning
- Contributing
- Nessus - Industry-standard vulnerability scanner with extensive plugin support.
- OpenVAS - Open-source vulnerability assessment system.
- Nuclei - Fast, YAML-based vulnerability scanner using community-driven templates.
- Burp Suite - Powerful web vulnerability scanner and proxy.
- OWASP ZAP - Open-source web app security scanner.
- Acunetix - Automated web vulnerability scanner (commercial).
- Nmap - Network discovery and vulnerability detection via NSE scripts.
- Rapid7 Nexpose - Unified asset and vulnerability management.
- Trivy - Vulnerability scanner for containers, Kubernetes, and IaC.
- Metasploit - Penetration testing framework with exploit modules.
- ExploitDB - Archive of exploits and vulnerable software.
- Sn1per - Automated pentest framework for reconnaissance and exploitation.
- AutoSploit - Automated mass exploitation tool (use ethically!).
- DefectDojo - Open-source vulnerability management platform.
- VulnWhisperer - Prioritize vulnerabilities using SIEM data.
- Faraday - Collaborative pentest environment with vulnerability tracking.
- Prowler - AWS security assessment and hardening tool.
- kube-hunter - Kubernetes penetration testing tool.
- ScoutSuite - Multi-cloud security auditing tool.
- Postman + Burp Suite - Manual API testing.
- Kiterunner - API endpoints brute-forcing and scanning.
- APIFuzzer - Automated API fuzzing for OWASP Top 10 vulnerabilities.
- Exploit-DB - The ultimate exploit repository.
- Packet Storm - Latest exploits and advisories.
- 0day.today - Zero-day exploit marketplace (use with caution).
- DVWA - Damn Vulnerable Web Application for testing.
- OWASP Juice Shop - Modern vulnerable web app.
- Hack The Box - Vulnerable machines for hands-on practice.
- Blogs:
- Courses:
- Books:
- The Web Application Hacker’s Handbook
- Black Hat Python
Your contributions are welcome!
📥 How to contribute:
- Fork the repo.
- Add/update tools/resources in the appropriate section.
- Submit a pull request with a brief description.
- Only include open-source or freemium tools.
- Avoid deprecated/unmaintained projects.
- Keep descriptions concise and factual.
This project is licensed under MIT License.
