PentestingEverything

August 15, 2026 · View on GitHub

Practical penetration testing knowledge base covering 23 security domains, with 108 documentation pages, 104 reference PDFs, and 212+ tools. Use the website to quickly explore methodologies, discover the right tools for each testing area, and access documentation and references all organized in one fast, structured, and easy-to-navigate place.

Live website:

Live Website · PentestingChecklist · Contribute · Report an Issue

Upcoming New Resources
Your ideas, suggestions, and contributions are always welcome!
  • New Module: Agentic Testing — Leveraging AI agents in penetration testing with Claude, GPT, Ollama, and other AI models.
Recently Updated Content : 2026
  • iOS Pentesting Module
  • Android Pentesting
  • API Pentesting Module
  • SAST / Source Code Review
  • DevSecOps & SCA
  • Thick Client Pentesting
  • OWASP Top 10:2025 Web Application
  • Threat Modeling, Design Review, Idea Review, Architecture Review
  • New Module : LLMs OWASP Top 10
  • New Module : MCP Pentesting
  • New Module : Firewall (In progress)
Improvements and Advanced Techniques
  • I will keep updating this section with new improvements, advanced techniques, and practical additions.
Agent Skill

Install a portable Agent Skill to use this knowledge base from Cursor, Claude and other agents for Agentic testing, Secure Coding and knowledgebase.

Who it's for: bug hunters, security testers, and penetration testers running real engagements through an agent, not just browsing static docs. Ground rules keep autonomous use safe: authorization is confirmed before active testing, high-impact actions are gated, findings pass a false-positive check before being drafted, and automated requests are paced to respect program rate limits.

Install (project-local):

npx skills add m14r41/PentestingEverything --skill pentesting-everything

Install globally (available across projects):

npx skills add m14r41/PentestingEverything --skill pentesting-everything --global

Target a specific client (examples):

npx skills add m14r41/PentestingEverything --skill pentesting-everything --agent cursor
npx skills add m14r41/PentestingEverything --skill pentesting-everything --agent claude-code

List without installing:

npx skills add m14r41/PentestingEverything --list

Skill source: .agents/skills/pentesting-everything/.

Language

0.1. Table of Contents

No.Types of PentestingNo.Types of Pentesting
1Web Application Pentesting13MCP Security Assessment
2API Pentesting14LLM Security Assessment
3Mobile Pentesting15Threat Modeling
4Thick Client Pentesting16Configuration Review
5Secure Code Review17Container & Kubernetes Assessment
6Cloud Pentesting18CI/CD Pentesting
7DevSecOps19IoT Pentesting
8Network Pentesting20BlockChain Pentesting
9Wi-Fi Pentesting21Phishing Assessment
10Firewall Penetration22OSINT
11Active Directory Pentesting23Forensic
12Infrastructure Security

Repository Activity

Repository Activity — Latest 20 updates

Activity log is automatically updated every 15 days.


Date & Time (IST)ActivityCommit
16 Aug 2026 · 01:19 ISTUpdate README with activity log informatione3dba5b
16 Aug 2026 · 01:15 ISTUpdate cron schedule for repository activity workflow168865f
16 Aug 2026 · 01:11 ISTRefactor repository activity workflow13b0aa9
16 Aug 2026 · 01:08 ISTEnable canceling in-progress deployments535dbd9
16 Aug 2026 · 00:56 ISTEnhance repository activity workflow904c875
15 Aug 2026 · 23:35 ISTUpdate Xamring-DotNet SSL Bypass.md0fa47be
15 Aug 2026 · 23:31 ISTAdd Xamarin SSL Bypass Setupc3a2ffb
15 Aug 2026 · 21:24 ISTdocs: add Dessalines39394 as a contributor for code (#240)b37ec50
15 Aug 2026 · 21:20 ISTFix broken Star History chart link in README (#239)d48b431
08 Aug 2026 · 16:10 ISTMerge pull request #238 from m14r41/m14r41-patch-191a97a0
08 Aug 2026 · 15:19 ISTAdd MobSF Docker setup instructionscddc785
08 Aug 2026 · 14:38 ISTMerge pull request #237 from m14r41/m14r41-patch-126415b1
08 Aug 2026 · 14:38 ISTAdd SonarQube Docker setup and usage guide8b56dcc
25 Jul 2026 · 01:33 ISTMerge pull request #236 from m14r41/m14r41-patch-1f0a342d
25 Jul 2026 · 01:32 ISTAgent Skill32a4965
25 Jul 2026 · 01:26 ISTFix broken CONTRIBUTING.md link: repo default branch is main, not master7ca8399
25 Jul 2026 · 01:16 ISTdocs: add Spottie97 as a contributor94f517f
25 Jul 2026 · 01:12 ISTAdd v2.1.0 changelog entry for the Agent Skillc6b9e79
22 Jul 2026 · 22:13 ISTUpdate README.md with XSS examples and resources4e0392f
21 Jul 2026 · 17:34 ISTAdd portable Agent Skill for authorized assessmentseca5a36

Pentesting & Tools

40 Plus Type of Security Assessment Tools


1. Penetration Testing and Tools

CategoryTools
Web Application PentestingAcunetix, Burp Suite Professional, Dirb, FFUF, Nmap, Nikto, Nuclei, OWASP ZAP, SQLMap, WhatWeb, WPScan, Invicti (Netsparker), Fortify WebInspect
Android Securityadb, APKTool, Apkscan, AndroBugs, Android Studio / Genymotion, AppMon, Dexter/Objection (Objection), Drozer, Frida, Magisk, MITMProxy, MobSF, Quark Engine, JADX
iOS Securitycheckra1n, Class-dump, Frida, iMazing, iOS-decrypt, iOS-Hook, MobSF, Needle, Objection, Palera1n, Passionfruit, SSL Kill Switch 2, Cycript
API PentestingBurp Suite Professional, GraphQL Raider, GraphQL Voyager, Insomnia, Kite Runner, Postman, Swagger UI
Secure Code ReviewBandit, Checkmarx, CodeQL, FindSecBugs, Gitleaks, Semgrep, SonarQube, Snyk, Veracode, Fortify Static (Workbench/Audit)
Thick-Client SecurityBurp Suite Professional, dnSpy, de4dot, Fiddler, Ghidra, IDA Pro, OllyDbg, Process Explorer, x64dbg, CFF Explorer, Sysinternals Suite, Wireshark
Network PentestingBettercap, CrackMapExec, Metasploit, Netcat, Nessus, Nmap, OpenVAS, Responder, Wireshark

2. Extended version

CategoryTools
Active Directory PentestingBloodHound, Mimikatz, CrackMapExec, Impacket, Kerbrute, Rubeus, LDAPDomainDump, SharpHound, PowerView, ADRecon
Cloud SecurityProwler, ScoutSuite, CloudSploit, Pacu, Steampipe, CloudMapper, NCC Scout, kube-bench, Terrascan, KICS
IoT SecurityFirmwalker, Binwalk, Firmware-Mod-Kit, Shodan, RIOT, JTAGulator, Qiling, Ghidra, Avatar2, Firmadyne
Firewall Pentestinghping3, NPing, Scapy, Zmap, firewalk, FTester, Nmap (Firewall Bypass), Packet Sender, T50, Ettercap, TCPReplay
Firmware AnalysisBinwalk, Firmware Analysis Toolkit (FAT), QEMU, Ghidra, IDA Pro, Firmware-Mod-Kit, Radare2, Firmadyne
Container SecurityTrivy, Aqua Microscanner, Clair, Anchore, Docker Bench, kube-hunter, Falco, Sysdig, Snyk, Grype
WiFi PentestingAircrack-ng, Kismet, Bettercap, Reaver, Fluxion, Wireshark, hcxtools, Fern WiFi Cracker, Wifiphisher, Hashcat
DevSecOpsGitHub Advanced Security, Trivy, Snyk, Anchore, OWASP Dependency-Check, Jenkins, Checkmarx, Veracode, Dagda, Sysdig Secure, Cloud Custodian, Bridgecrew, Kubescape
OSINTtheHarvester, Maltego, SpiderFoot, Recon-ng, Shodan, FOCA, Google Dorks, OSINT Framework, GHunt, Sherlock, PhoneInfoga
Configuration ReviewLynis, OpenSCAP, Auditd, Tripwire, cis-cat Pro, Chef InSpec, Prowler, Kubescape
Phishing SimulationGoPhish, SET, Evilginx2, Phishery, King Phisher, Modlishka, Phishing Frenzy
ForensicsAutopsy, Volatility, Sleuth Kit, FTK Imager, Redline, Magnet AXIOM, X-Ways, Bulk Extractor, ExifTool
Blockchain SecurityMythril, Slither, Manticore, Remix IDE, Oyente, SmartCheck, Echidna, Tenderly
Threat ModelingMicrosoft TMT, OWASP Threat Dragon, IriusRisk, SeaSponge, Draw.io, Pytm
Red Team ToolsCobalt Strike, Sliver, Mythic, Empire, Metasploit, Brute Ratel, Koadic, FudgeC2, Nishang, PowerShell Empire
Blue Team ToolsVelociraptor, Wazuh, OSQuery, GRR, Sysmon, CrowdStrike Falcon, Elastic Security, Sigma Rules
SIEM & Log AnalysisSplunk, ELK Stack, Graylog, Wazuh, AlienVault OSSIM, SIEMonster, Logstash, Fluentd, Loki, Falco, Humio, Kibana, Loggly, Logz.io
Password CrackingHashcat, John the Ripper, Hydra, CrackStation, Cain & Abel, Medusa, THC-Hydra
Reverse EngineeringGhidra, IDA Pro, x64dbg, OllyDbg, Binary Ninja, Radare2, Cutter
Hardware HackingChipWhisperer, Saleae Logic, OpenOCD, JTAGulator, Bus Pirate, Flashrom, Arduino, Raspberry Pi, RTL-SDR
Social EngineeringSET, BeEF, King Phisher, Evilginx / Evilginx2, Modlishka, EyeWitness, PhishToolkit, PhishX, Psychological Frameworks (Pretexting, Elicitation)
SCADA/ICS SecuritySnort, Wireshark, ModScan, ModbusPal, Scadafence, OpenPLC, GasPot, Conpot, PLCScan
Supply Chain SecuritySnyk, OWASP Dependency-Check, Trivy, Syft, Grype, CycloneDX, Whitesource, Anchore Engine
Email Security TestingGoPhish, Modlishka, SMTPTester, MailSniper, Evilginx2, Phish5, Email Header Analyzer
Mobile Malware AnalysisAPKTool, MobSF, Jadx, Frida, VirusTotal Mobile, Droidbox, Bytecode Viewer, Drozer, Quark-Engine
AI/ML SecurityAdversarial Robustness Toolbox (ART), TextAttack, Foolbox, IBM AI Explainability 360, CleverHans, Alibi Detect, SecML, DeepExploit
Security Automation / SOARStackStorm, Cortex XSOAR, Shuffle, DFIR-IR-Playbook, Phantom Cyber, Tines
Bug Bounty ToolkitAmass, Sublist3r, Nuclei, HTTPX, Naabu, FFUF, GF, Dalfox, Kiterunner, Hakrawler, JSParser, ParamSpider
Credential Dumping & CrackingLaZagne, Mimikatz, Hashcat, John the Ripper, Windows Credential Editor, CrackMapExec, GetNPUsers.py
Payload GenerationMSFVenom, Unicorn, Shellter, Veil, Nishang, Empire, Obfuscation.io, Metasploit, Donut
Honeypots / DeceptionCowrie, Dionaea, Kippo, Honeyd, T-Pot, Conpot, Canarytokens, Artillery
MacOS SecurityKnockKnock, BlockBlock, OSXCollector, Objective-See Suite, MacMonitor, Little Snitch, Dylib Hijack Scanner
Windows Post-ExploitationPowerView, Seatbelt, SharpUp, WinPEAS, Sherlock, Empire, FireEye Red Team Tools, SharpHound
Linux Post-ExploitationLinPEAS, Linux Exploit Suggester, pspy, Chkrootkit, rkhunter, bashark, GTFOBins, Sudomy
Browser Security TestingBeEF, XSStrike, XSSer, Burp Collaborator, NoScript, uBlock Origin, Chrome Developer Tools


2.1. Contributors

I appreciate your interest in contributing! please read Contribution Guidelines.

A heartfelt thanks to the amazing individuals for their contributions to this project. You can view emoji key to see the various ways you can contribute!

Marko Živanović
Marko Živanović

🔧
m14r41
m14r41

💻
0xanon
0xanon

💻
InfoBugs
InfoBugs

💻
Ratnesh kumar
Ratnesh kumar

💻
Chandrabhushan Kumar
Chandrabhushan Kumar

💻
Satya Prakash
Satya Prakash

💻 👀
Wei Lin
Wei Lin

🌍
Reinhardt Erasmus
Reinhardt Erasmus

💻
Dessalines39394
Dessalines39394

💻

2.2. Star History

Star History Chart


Content and Attribution

This project is open source (MIT) and includes third-party material such as PDFs and documents that belong to their original owners. It is shared in good faith for education only. If any of it is yours and you want it credited differently or removed, just ask and it will be handled promptly. See CONTENT_REMOVAL.md.


Support:

m14r41