Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

3 Commits
 
 
 
 

Repository files navigation

Awesome Vulnerability Vault 🔍💥

Awesome GitHub Stars License

A curated list of tools, frameworks, and resources for vulnerability scanning, exploitation, and management. Perfect for red teams, blue teams, and security researchers.

Vulnerability Stack Meme
Credit: xkcd, modified via explainxkcd


Table of Contents


Vulnerability Scanners

General Purpose

  • Nessus - Industry-standard vulnerability scanner with extensive plugin support.
  • OpenVAS - Open-source vulnerability assessment system.
  • Nuclei - Fast, YAML-based vulnerability scanner using community-driven templates.

Web Application

  • Burp Suite - Powerful web vulnerability scanner and proxy.
  • OWASP ZAP - Open-source web app security scanner.
  • Acunetix - Automated web vulnerability scanner (commercial).

Network & Infrastructure

  • Nmap - Network discovery and vulnerability detection via NSE scripts.
  • Rapid7 Nexpose - Unified asset and vulnerability management.
  • Trivy - Vulnerability scanner for containers, Kubernetes, and IaC.

Exploitation Frameworks

  • Metasploit - Penetration testing framework with exploit modules.
  • ExploitDB - Archive of exploits and vulnerable software.
  • Sn1per - Automated pentest framework for reconnaissance and exploitation.
  • AutoSploit - Automated mass exploitation tool (use ethically!).

Vulnerability Management

  • DefectDojo - Open-source vulnerability management platform.
  • VulnWhisperer - Prioritize vulnerabilities using SIEM data.
  • Faraday - Collaborative pentest environment with vulnerability tracking.

Cloud & Container Security

  • Prowler - AWS security assessment and hardening tool.
  • kube-hunter - Kubernetes penetration testing tool.
  • ScoutSuite - Multi-cloud security auditing tool.

API Security


Exploit Databases


Labs & Practice


Resources & Learning


Contributing

Your contributions are welcome!
📥 How to contribute:

  1. Fork the repo.
  2. Add/update tools/resources in the appropriate section.
  3. Submit a pull request with a brief description.

⚠️ Guidelines:

  • Only include open-source or freemium tools.
  • Avoid deprecated/unmaintained projects.
  • Keep descriptions concise and factual.

License

This project is licensed under MIT License.

About

A curated list of tools, frameworks, and resources for everything related vulnerability management realm.

Resources

Stars

3 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors