m14r41/PentestingEverything

TypeScriptpentesting.m14r41.in

Complete Solution for VAPT/AppSec and Pentesting Guide: Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting | SAST | DAST etc...

appsecapi-pentestingvaptactive-directorycybersecuritydevsecopsmobile-penetration-testingnetworkingosint-resourcespentestingsastsourcecode-analysis
Crescimento de estrelas
Estrelas
2.1k
Forks
463
Crescimento semanal
+18
Issues
0
5001k1.5k2k
nov. de 2023out. de 2024set. de 2025set. de 2026
Artefatosnpm
README

PentestingEverything

Practical penetration testing knowledge base covering 23 security domains, with 108 documentation pages, 104 reference PDFs, and 212+ tools. Use the website to quickly explore methodologies, discover the right tools for each testing area, and access documentation and references all organized in one fast, structured, and easy-to-navigate place.

Upcoming New Resources
Your ideas, suggestions, and contributions are always welcome!
  • New Module: Agentic Testing — Leveraging AI agents in penetration testing with Claude, GPT, Ollama, and other AI models.
Recently Updated Content : 2026
  • iOS Pentesting Module
  • Android Pentesting
  • API Pentesting Module
  • SAST / Source Code Review
  • DevSecOps & SCA
  • Thick Client Pentesting
  • OWASP Top 10:2025 Web Application
  • Threat Modeling, Design Review, Idea Review, Architecture Review
  • New Module : LLMs OWASP Top 10
  • New Module : MCP Pentesting
  • New Module : Firewall (In progress)
Improvements and Advanced Techniques
  • I will keep updating this section with new improvements, advanced techniques, and practical additions.
Agent Skill

Install a portable Agent Skill to use this knowledge base from Cursor, Claude and other agents for Agentic testing, Secure Coding and knowledgebase.

Who it's for: bug hunters, security testers, and penetration testers running real engagements through an agent, not just browsing static docs. Ground rules keep autonomous use safe: authorization is confirmed before active testing, high-impact actions are gated, findings pass a false-positive check before being drafted, and automated requests are paced to respect program rate limits.

Install (project-local):

npx skills add m14r41/PentestingEverything --skill pentesting-everything

Install globally (available across projects):

npx skills add m14r41/PentestingEverything --skill pentesting-everything --global

Target a specific client (examples):

npx skills add m14r41/PentestingEverything --skill pentesting-everything --agent cursor
npx skills add m14r41/PentestingEverything --skill pentesting-everything --agent claude-code

List without installing:

npx skills add m14r41/PentestingEverything --list

Skill source: .agents/skills/pentesting-everything/.


0.1. Table of Contents

No. Types of Pentesting No. Types of Pentesting
1 Web Application Pentesting 13 MCP Security Assessment
2 API Pentesting 14 LLM Security Assessment
3 Mobile Pentesting 15 Threat Modeling
4 Thick Client Pentesting 16 Configuration Review
5 Secure Code Review 17 Container & Kubernetes Assessment
6 Cloud Pentesting 18 CI/CD Pentesting
7 DevSecOps 19 IoT Pentesting
8 Network Pentesting 20 BlockChain Pentesting
9 Wi-Fi Pentesting 21 Phishing Assessment
10 Firewall Penetration 22 OSINT
11 Active Directory Pentesting 23 Forensic
12 Infrastructure Security

Repository Activity

Repository Activity — Latest 20 updates

Activity log is automatically updated every 15 days.


Date & Time (IST) Activity Commit
16 Aug 2026 · 11:36 IST Metasploitable Report Update 3478b98
16 Aug 2026 · 11:23 IST Update Metasploitable Pentest Report formatting 4f307d1
16 Aug 2026 · 01:23 IST docs: update repository activity (#246) fe6b0b2
16 Aug 2026 · 01:19 IST Update README with activity log information e3dba5b
16 Aug 2026 · 01:15 IST Update cron schedule for repository activity workflow 168865f
15 Aug 2026 · 23:35 IST Update Xamring-DotNet SSL Bypass.md 0fa47be
15 Aug 2026 · 23:31 IST Add Xamarin SSL Bypass Setup c3a2ffb
15 Aug 2026 · 21:24 IST docs: add Dessalines39394 as a contributor for code (#240) b37ec50
15 Aug 2026 · 21:20 IST Fix broken Star History chart link in README (#239) d48b431
08 Aug 2026 · 16:10 IST Merge pull request #238 from m14r41/m14r41-patch-1 91a97a0
08 Aug 2026 · 15:19 IST Add MobSF Docker setup instructions cddc785
08 Aug 2026 · 14:38 IST Merge pull request #237 from m14r41/m14r41-patch-1 26415b1
08 Aug 2026 · 14:38 IST Add SonarQube Docker setup and usage guide 8b56dcc
25 Jul 2026 · 01:33 IST Merge pull request #236 from m14r41/m14r41-patch-1 f0a342d
25 Jul 2026 · 01:32 IST Agent Skill 32a4965
25 Jul 2026 · 01:26 IST Fix broken CONTRIBUTING.md link: repo default branch is main, not master 7ca8399
25 Jul 2026 · 01:16 IST docs: add Spottie97 as a contributor 94f517f
25 Jul 2026 · 01:12 IST Add v2.1.0 changelog entry for the Agent Skill c6b9e79
22 Jul 2026 · 22:13 IST Update README.md with XSS examples and resources 4e0392f
21 Jul 2026 · 17:34 IST Add portable Agent Skill for authorized assessments eca5a36

Pentesting & Tools

40 Plus Type of Security Assessment Tools


1. Penetration Testing and Tools

Category Tools
Web Application Pentesting Acunetix, Burp Suite Professional, Dirb, FFUF, Nmap, Nikto, Nuclei, OWASP ZAP, SQLMap, WhatWeb, WPScan, Invicti (Netsparker), Fortify WebInspect
Android Security adb, APKTool, Apkscan, AndroBugs, Android Studio / Genymotion, AppMon, Dexter/Objection (Objection), Drozer, Frida, Magisk, MITMProxy, MobSF, Quark Engine, JADX
iOS Security checkra1n, Class-dump, Frida, iMazing, iOS-decrypt, iOS-Hook, MobSF, Needle, Objection, Palera1n, Passionfruit, SSL Kill Switch 2, Cycript
API Pentesting Burp Suite Professional, GraphQL Raider, GraphQL Voyager, Insomnia, Kite Runner, Postman, Swagger UI
Secure Code Review Bandit, Checkmarx, CodeQL, FindSecBugs, Gitleaks, Semgrep, SonarQube, Snyk, Veracode, Fortify Static (Workbench/Audit)
Thick-Client Security Burp Suite Professional, dnSpy, de4dot, Fiddler, Ghidra, IDA Pro, OllyDbg, Process Explorer, x64dbg, CFF Explorer, Sysinternals Suite, Wireshark
Network Pentesting Bettercap, CrackMapExec, Metasploit, Netcat, Nessus, Nmap, OpenVAS, Responder, Wireshark

2. Extended version

Category Tools
Active Directory Pentesting BloodHound, Mimikatz, CrackMapExec, Impacket, Kerbrute, Rubeus, LDAPDomainDump, SharpHound, PowerView, ADRecon
Cloud Security Prowler, ScoutSuite, CloudSploit, Pacu, Steampipe, CloudMapper, NCC Scout, kube-bench, Terrascan, KICS
IoT Security Firmwalker, Binwalk, Firmware-Mod-Kit, Shodan, RIOT, JTAGulator, Qiling, Ghidra, Avatar2, Firmadyne
Firewall Pentesting hping3, NPing, Scapy, Zmap, firewalk, FTester, Nmap (Firewall Bypass), Packet Sender, T50, Ettercap, TCPReplay
Firmware Analysis Binwalk, Firmware Analysis Toolkit (FAT), QEMU, Ghidra, IDA Pro, Firmware-Mod-Kit, Radare2, Firmadyne
Container Security Trivy, Aqua Microscanner, Clair, Anchore, Docker Bench, kube-hunter, Falco, Sysdig, Snyk, Grype
WiFi Pentesting Aircrack-ng, Kismet, Bettercap, Reaver, Fluxion, Wireshark, hcxtools, Fern WiFi Cracker, Wifiphisher, Hashcat
DevSecOps GitHub Advanced Security, Trivy, Snyk, Anchore, OWASP Dependency-Check, Jenkins, Checkmarx, Veracode, Dagda, Sysdig Secure, Cloud Custodian, Bridgecrew, Kubescape
OSINT theHarvester, Maltego, SpiderFoot, Recon-ng, Shodan, FOCA, Google Dorks, OSINT Framework, GHunt, Sherlock, PhoneInfoga
Configuration Review Lynis, OpenSCAP, Auditd, Tripwire, cis-cat Pro, Chef InSpec, Prowler, Kubescape
Phishing Simulation GoPhish, SET, Evilginx2, Phishery, King Phisher, Modlishka, Phishing Frenzy
Forensics Autopsy, Volatility, Sleuth Kit, FTK Imager, Redline, Magnet AXIOM, X-Ways, Bulk Extractor, ExifTool
Blockchain Security Mythril, Slither, Manticore, Remix IDE, Oyente, SmartCheck, Echidna, Tenderly
Threat Modeling Microsoft TMT, OWASP Threat Dragon, IriusRisk, SeaSponge, Draw.io, Pytm
Red Team Tools Cobalt Strike, Sliver, Mythic, Empire, Metasploit, Brute Ratel, Koadic, FudgeC2, Nishang, PowerShell Empire
Blue Team Tools Velociraptor, Wazuh, OSQuery, GRR, Sysmon, CrowdStrike Falcon, Elastic Security, Sigma Rules
SIEM & Log Analysis Splunk, ELK Stack, Graylog, Wazuh, AlienVault OSSIM, SIEMonster, Logstash, Fluentd, Loki, Falco, Humio, Kibana, Loggly, Logz.io
Password Cracking Hashcat, John the Ripper, Hydra, CrackStation, Cain & Abel, Medusa, THC-Hydra
Reverse Engineering Ghidra, IDA Pro, x64dbg, OllyDbg, Binary Ninja, Radare2, Cutter
Hardware Hacking ChipWhisperer, Saleae Logic, OpenOCD, JTAGulator, Bus Pirate, Flashrom, Arduino, Raspberry Pi, RTL-SDR
Social Engineering SET, BeEF, King Phisher, Evilginx / Evilginx2, Modlishka, EyeWitness, PhishToolkit, PhishX, Psychological Frameworks (Pretexting, Elicitation)
SCADA/ICS Security Snort, Wireshark, ModScan, ModbusPal, Scadafence, OpenPLC, GasPot, Conpot, PLCScan
Supply Chain Security Snyk, OWASP Dependency-Check, Trivy, Syft, Grype, CycloneDX, Whitesource, Anchore Engine
Email Security Testing GoPhish, Modlishka, SMTPTester, MailSniper, Evilginx2, Phish5, Email Header Analyzer
Mobile Malware Analysis APKTool, MobSF, Jadx, Frida, VirusTotal Mobile, Droidbox, Bytecode Viewer, Drozer, Quark-Engine
AI/ML Security Adversarial Robustness Toolbox (ART), TextAttack, Foolbox, IBM AI Explainability 360, CleverHans, Alibi Detect, SecML, DeepExploit
Security Automation / SOAR StackStorm, Cortex XSOAR, Shuffle, DFIR-IR-Playbook, Phantom Cyber, Tines
Bug Bounty Toolkit Amass, Sublist3r, Nuclei, HTTPX, Naabu, FFUF, GF, Dalfox, Kiterunner, Hakrawler, JSParser, ParamSpider
Credential Dumping & Cracking LaZagne, Mimikatz, Hashcat, John the Ripper, Windows Credential Editor, CrackMapExec, GetNPUsers.py
Payload Generation MSFVenom, Unicorn, Shellter, Veil, Nishang, Empire, Obfuscation.io, Metasploit, Donut
Honeypots / Deception Cowrie, Dionaea, Kippo, Honeyd, T-Pot, Conpot, Canarytokens, Artillery
MacOS Security KnockKnock, BlockBlock, OSXCollector, Objective-See Suite, MacMonitor, Little Snitch, Dylib Hijack Scanner
Windows Post-Exploitation PowerView, Seatbelt, SharpUp, WinPEAS, Sherlock, Empire, FireEye Red Team Tools, SharpHound
Linux Post-Exploitation LinPEAS, Linux Exploit Suggester, pspy, Chkrootkit, rkhunter, bashark, GTFOBins, Sudomy
Browser Security Testing BeEF, XSStrike, XSSer, Burp Collaborator, NoScript, uBlock Origin, Chrome Developer Tools


2.1. Contributors

I appreciate your interest in contributing! please read Contribution Guidelines.

A heartfelt thanks to the amazing individuals for their contributions to this project. You can view emoji key to see the various ways you can contribute!

Marko Živanović
Marko Živanović

🔧
m14r41
m14r41

💻
0xanon
0xanon

💻
InfoBugs
InfoBugs

💻
Ratnesh kumar
Ratnesh kumar

💻
Chandrabhushan Kumar
Chandrabhushan Kumar

💻
Satya Prakash
Satya Prakash

💻 👀
Wei Lin
Wei Lin

🌍
Reinhardt Erasmus
Reinhardt Erasmus

💻
Dessalines39394
Dessalines39394

💻

2.2. Star History

Star History Chart


Content and Attribution

This project is open source (MIT) and includes third-party material such as PDFs and documents that belong to their original owners. It is shared in good faith for education only. If any of it is yours and you want it credited differently or removed, just ask and it will be handled promptly. See CONTENT_REMOVAL.md.


Support:

m14r41

Repositórios relacionados
KeygraphHQ/shannon

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

TypeScriptnpmGNU Affero General Public License v3.0penetration-testingpentesting
keygraph.io
47.9k5.5k
sqlmapproject/sqlmap

Automatic SQL injection and database takeover tool

PythonPyPIOthersql-injectiondetection
sqlmap.org
38.4k6.4k
OWASP/CheatSheetSeries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

PythonPyPItutorialCreative Commons Attribution Share Alike 4.0 Internationalowaspcode
cheatsheetseries.owasp.org
33.1k4.6k
chaitin/SafeLine

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

GoGo ModulesGNU General Public License v3.0firewallhttp-flood
ly.safepoint.cloud/fUxS0GW
22.5k1.5k
zaproxy/zaproxy

The ZAP by Checkmarx Core project

JavaMavenappApache License 2.0zapzap-development
zaproxy.org
15.7k2.6k
maurosoria/dirsearch

Web path scanner

PythonPyPIfuzzerfuzzing
14.7k2.4k
juice-shop/juice-shop

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

TypeScriptnpmMIT Licenseowaspjavascript
owasp-juice.shop
13.8k19.5k
OWASP/wstg

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

PythonPyPItutorialCreative Commons Attribution Share Alike 4.0 Internationalbest-practicesguide
owasp.org/www-project-web-security-testing-guide/
9.8k1.7k
infoslack/awesome-web-hacking

A list of web application security

awesomeMIT Licensepenetration-testingweb-hacking
7.3k1.4k
microsoft/Security-101

8 Lessons, Kick-start Your Cybersecurity Learning.

HTMLtutorialCreative Commons Zero v1.0 Universalappseccia-triad
microsoft.github.io/Security-101/
6.9k930
urbanadventurer/WhatWeb

Next generation web scanner

RubyRubyGemsGNU General Public License v2.0securityweb
morningstarsecurity.com/research/whatweb
6.8k1k
infobyte/faraday

Open Source Vulnerability Management Platform

PythonPyPIGNU General Public License v3.0devopspenetration-testing
faradaysec.com
6.7k1.1k