PyPI Stats
  • Insights
  • PyPI
  • GitHub
  • Search
  • Compare
  • Advisories
  • Ecosystem
  • About
Home

Penetration Testing Python Packages

Python packages with the GitHub topic penetration-testing. Sorted by relevance, with stars and monthly downloads.
Paradoxis
flask-unsign

Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.

71K 640 47
Usta0x001
phantom-agent

Autonomous Offensive Security Intelligence AI-powered multi-agent penetration testing

31K 14 4
dalisecurity
fray

Open-source WAF Security Testing Platform — 7,200+ attack payloads, 98 WAF/CDN fingerprints, AI-powered bypass engine, recon pipeline, beautiful CLI output

30K 50 4
ncouture
mockssh

Mock an SSH server and define all commands it supports (Python, Twisted)

27K 130 25
maurosoria
dirsearch

Web path scanner

24K 14K 2K
Paradoxis
flask-unsign-wordlist

The following package is the standalone wordlist-only component to flask-unsign.

13K 43 13
AlaBouali
bane

The "bane" Python library stands out as a robust toolkit catering to a wide spectrum of cybersecurity and networking tasks. Its versatile range of functionalities covers various aspects, including bruteforce attacks, cryptographic methods, DDoS attacks, information gathering, botnet creation and management, and CMS vulnerability scanning and more..

7K 359 70
ThePorgs
exegol

Fully featured and community-driven hacking environment

7K 3K 275
ADscanPro
adscan

Free Active Directory pentesting tool and Linux CLI for AD enumeration, BloodHound, Kerberoasting, ADCS, DCSync, and attack paths.

6K 267 34
nikitastupin
clairvoyance

Obtain GraphQL API schema even if the introspection is disabled

6K 1K 130
0xSteph
ptai

The most autonomous pentesting AI on the market. MCP server + Python agents with 150+ security tools, exploit chaining, and PoC validation.

5K 159 39
Unclecheng-li
vulnclaw

基于 AI Agent + MCP 工具链 + 渗透 Skill 编排, 配合大语言模型, 自然语言输入 → 自动完成「信息收集 → 漏洞发现 → 漏洞利用 → 报告生成」全流程。

5K 30 9
Grunny
zapcli

A simple tool for interacting with OWASP ZAP from the commandline.

4K 258 70
cytopia
netcat

pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully scriptable with Python (PSE)

4K 2K 216
gkbrk
slowloris

Low bandwidth DoS tool. Slowloris rewrite in Python.

4K 3K 732
taoq-ai
ziran

自然 ZIRAN is an open-source security testing framework for AI agents. It discovers dangerous tool chain compositions via knowledge graph analysis, detects execution-level side effects (not just text output), and runs multi-phase trust exploitation campaigns that model real attacker behaviour.

3K 6 1
Paradoxis
stegcracker

Steganography brute-force utility to uncover hidden data inside files

3K 594 108
infobyte
faradaysec

Open Source Collaborative Penetration Test and Vulnerability Management Platform https://www.faradaysec.com

3K 6K 1K
ExploitCraft
reconninja

⚡ ReconNinja v8.2.1 — 38-phase recon framework for pentesters & bug bounty hunters. Subdomain enum → port scan → web recon → WAF/CORS/JS/cloud bucket detection → GitHub OSINT → CVE lookup → AI threat analysis → HTML report. Domains, IPs, CIDRs, target lists. Plugin system. 598 tests.

3K 39 6
appthreat
wasm-tools

A WebAssembly parser and disassembler in python.

3K 0 0
FrancescoStabile
numasec

AI agent for penetration testing. Like Claude Code, but for security. Open source, MCP-native, works with any LLM.

2K 119 17
fsociety-team
fsociety

A Modular Penetration Testing Framework

2K 2K 205
cytopia
pwncat

pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully scriptable with Python (PSE)

2K 2K 216
fportantier
habu

Hacking Toolkit

2K 980 164
    • Data from PyPI, GitHub, ClickHouse, and BigQuery