MP

m14r41/pentestingeverything

Developer tools
2 тыс. stars Качество 40 Тренд 40

Read it online at : fully searchable, with 108 documentation pages, 104 reference PDFs, and 212+ topics across 23 domains.

Обзор

Read it online at : fully searchable, with 108 documentation pages, 104 reference PDFs, and 212+ topics across 23 domains.

README

Read it online at pentesting.m14r41.in: fully searchable, with 108 documentation pages, 104 reference PDFs, and 212+ topics across 23 domains. The website turns this repository into a fast, structured, and readable knowledge base.

New in v2.0.0: the project is now a full website with instant full-text search, a filterable reference PDF library, learning paths for common engagements, and a companion checklist at checklist.m14r41.in. Full notes in the changelog.

PentestingEverything is an open-source, comprehensive penetration-testing knowledge base. It brings together methodology, checklists, payloads, commands, and field-tested references across 23 domains: web, API, mobile, network, cloud, Active Directory, OSINT, and more. The goal is simple: give you the concise, practical knowledge to assess any target, from scoping an engagement to hunting a specific vulnerability class to writing the report.

Practical companion: PentestingChecklist. This project is the knowledge base. The checklist is the hands-on, tick-as-you-go companion. A structured checklist across 23 platforms (web, API, mobile, cloud, AD and more) with progress tracking, notes, and export. Use them side by side.

Agent Skill

Install a portable Agent Skill to use this knowledge base from Cursor and other coding agents. It grounds answers in PentestingEverything Markdown, builds scoped checklists, and drafts evidence-based notes for authorized assessments only.

Who it’s for: bug hunters, security testers, and penetration testers running real engagements through an agent, not just browsing static docs. Ground rules keep autonomous use safe: authorization is confirmed before active testing, high-impact actions are gated, findings pass a false-positive check before being drafted, and automated requests are paced to respect program rate limits.

Install (project-local):

npx skills add m14r41/PentestingEverything --skill pentesting-everything

Install globally (available across projects):

npx skills add m14r41/PentestingEverything --skill pentesting-everything --global

Target a specific client (examples):

npx skills add m14r41/PentestingEverything --skill pentesting-everything --agent cursor
npx skills add m14r41/PentestingEverything --skill pentesting-everything --agent claude-code

List without installing:

npx skills add m14r41/PentestingEverything --list

Skill source: .agents/skills/pentesting-everything/.

0.1. Table of Contents



1. Penetration Testing and Tools

Category Tools
Web Application Pentesting Acunetix, Burp Suite Professional, Dirb, FFUF, Nmap, Nikto, Nuclei, OWASP ZAP, SQLMap, WhatWeb, WPScan, Invicti (Netsparker), Fortify WebInspect
Android Security adb, APKTool, Apkscan, AndroBugs, Android Studio / Genymotion, AppMon, Dexter/Objection (Objection), Drozer, Frida, Magisk, MITMProxy, MobSF, Quark Engine, JADX
iOS Security checkra1n, Class-dump, Frida, iMazing, iOS-decrypt, iOS-Hook, MobSF, Needle, Objection, Palera1n, Passionfruit, SSL Kill Switch 2, Cycript
API Pentesting Burp Suite Professional, GraphQL Raider, GraphQL Voyager, Insomnia, Kite Runner, Postman, Swagger UI
Secure Code Review Bandit, Checkmarx, CodeQL, FindSecBugs, Gitleaks, Semgrep, SonarQube, Snyk, Veracode, Fortify Static (Workbench/Audit)
Thick-Client Security Burp Suite Professional, dnSpy, de4dot, Fiddler, Ghidra, IDA Pro, OllyDbg, Process Explorer, x64dbg, CFF Explorer, Sysinternals Suite, Wireshark
Network Pentesting Bettercap, CrackMapExec, Metasploit, Netcat, Nessus, Nmap, OpenVAS, Responder, Wireshark

2. Extended version

Category Tools
Active Directory Pentesting BloodHound, Mimikatz, CrackMapExec, Impacket, Kerbrute, Rubeus, LDAPDomainDump, SharpHound, PowerView, ADRecon
Cloud Security Prowler, ScoutSuite, CloudSploit, Pacu, Steampipe, CloudMapper, NCC Scout, kube-bench, Terrascan, KICS
IoT Security Firmwalker, Binwalk, Firmware-Mod-Kit, Shodan, RIOT, JTAGulator, Qiling, Ghidra, Avatar2, Firmadyne
Firewall Pentesting hping3, NPing, Scapy, Zmap, firewalk, FTester, Nmap (Firewall Bypass), Packet Sender, T50, Ettercap, TCPReplay
Firmware Analysis Binwalk, Firmware Analysis Toolkit (FAT), QEMU, Ghidra, IDA Pro, Firmware-Mod-Kit, Radare2, Firmadyne
Container Security Trivy, Aqua Microscanner, Clair, Anchore, Docker Bench, kube-hunter, Falco, Sysdig, Snyk, Grype
WiFi Pentesting Aircrack-ng, Kismet, Bettercap, Reaver, Fluxion, Wireshark, hcxtools, Fern WiFi Cracker, Wifiphisher, Hashcat
DevSecOps GitHub Advanced Security, Trivy, Snyk, Anchore, OWASP Dependency-Check, Jenkins, Checkmarx, Veracode, Dagda, Sysdig Secure, Cloud Custodian, Bridgecrew, Kubescape
OSINT theHarvester, Maltego, SpiderFoot, Recon-ng, Shodan, FOCA, Google Dorks, OSINT Framework, GHunt, Sherlock, PhoneInfoga
Configuration Review Lynis, OpenSCAP, Auditd, Tripwire, cis-cat Pro, Chef InSpec, Prowler, Kubescape
Phishing Simulation GoPhish, SET, Evilginx2, Phishery, King Phisher, Modlishka, Phishing Frenzy
Forensics Autopsy, Volatility, Sleuth Kit, FTK Imager, Redline, Magnet AXIOM, X-Ways, Bulk Extractor, ExifTool
Blockchain Security Mythril, Slither, Manticore, Remix IDE, Oyente, SmartCheck, Echidna, Tenderly
Threat Modeling Microsoft TMT, OWASP Threat Dragon, IriusRisk, SeaSponge, Draw.io, Pytm
Red Team Tools Cobalt Strike, Sliver, Mythic, Empire, Metasploit, Brute Ratel, Koadic, FudgeC2, Nishang, PowerShell Empire
Blue Team Tools Velociraptor, Wazuh, OSQuery, GRR, Sysmon, CrowdStrike Falcon, Elastic Security, Sigma Rules
SIEM & Log Analysis Splunk, ELK Stack, Graylog, Wazuh, AlienVault OSSIM, SIEMonster, Logstash, Fluentd, Loki, Falco, Humio, Kibana, Loggly, Logz.io
Password Cracking Hashcat, John the Ripper, Hydra, CrackStation, Cain & Abel, Medusa, THC-Hydra
Reverse Engineering Ghidra, IDA Pro, x64dbg, OllyDbg, Binary Ninja, Radare2, Cutter
Hardware Hacking ChipWhisperer, Saleae Logic, OpenOCD, JTAGulator, Bus Pirate, Flashrom, Arduino, Raspberry Pi, RTL-SDR
Social Engineering SET, BeEF, King Phisher, Evilginx / Evilginx2, Modlishka, EyeWitness, PhishToolkit, PhishX, Psychological Frameworks (Pretexting, Elicitation)
SCADA/ICS Security Snort, Wireshark, ModScan, ModbusPal, Scadafence, OpenPLC, GasPot, Conpot, PLCScan
Supply Chain Security Snyk, OWASP Dependency-Check, Trivy, Syft, Grype, CycloneDX, Whitesource, Anchore Engine
Email Security Testing GoPhish, Modlishka, SMTPTester, MailSniper, Evilginx2, Phish5, Email Header Analyzer
Mobile Malware Analysis APKTool, MobSF, Jadx, Frida, VirusTotal Mobile, Droidbox, Bytecode Viewer, Drozer, Quark-Engine
AI/ML Security Adversarial Robustness Toolbox (ART), TextAttack, Foolbox, IBM AI Explainability 360, CleverHans, Alibi Detect, SecML, DeepExploit
Security Automation / SOAR StackStorm, Cortex XSOAR, Shuffle, DFIR-IR-Playbook, Phantom Cyber, Tines
Bug Bounty Toolkit Amass, Sublist3r, Nuclei, HTTPX, Naabu, FFUF, GF, Dalfox, Kiterunner, Hakrawler, JSParser, ParamSpider
Credential Dumping & Cracking LaZagne, Mimikatz, Hashcat, John the Ripper, Windows Credential Editor, CrackMapExec, GetNPUsers.py
Payload Generation MSFVenom, Unicorn, Shellter, Veil, Nishang, Empire, Obfuscation.io, Metasploit, Donut
Honeypots / Deception Cowrie, Dionaea, Kippo, Honeyd, T-Pot, Conpot, Canarytokens, Artillery
MacOS Security KnockKnock, BlockBlock, OSXCollector, Objective-See Suite, MacMonitor, Little Snitch, Dylib Hijack Scanner
Windows Post-Exploitation PowerView, Seatbelt, SharpUp, WinPEAS, Sherlock, Empire, FireEye Red Team Tools, SharpHound
Linux Post-Exploitation LinPEAS, Linux Exploit Suggester, pspy, Chkrootkit, rkhunter, bashark, GTFOBins, Sudomy
Browser Security Testing BeEF, XSStrike, XSSer, Burp Collaborator, NoScript, uBlock Origin, Chrome Developer Tools

2.1. Contributors

I appreciate your interest in contributing! please read Contribution Guidelines.

A heartfelt thanks to the amazing individuals for their contributions to this project. You can view emoji key to see the various ways you can contribute!


2.2. Star History


Content and Attribution

This project is open source (MIT) and includes third-party material such as PDFs and documents that belong to their original owners. It is shared in good faith for education only. If any of it is yours and you want it credited differently or removed, just ask and it will be handled promptly. See CONTENT_REMOVAL.md.


Support:

View this README on GitHub

Рекомендуемые инструменты

Попробуйте другой запрос или уберите фильтр.

Установка

npx skillfish add m14r41/pentestingeverything