Practical penetration testing knowledge base covering 23 security domains, with 108 documentation pages, 104 reference PDFs, and 212+ tools. Use the website to quickly explore methodologies, discover the right tools for each testing area, and access documentation and references all organized in one fast, structured, and easy-to-navigate place.
Upcoming New Resources
Your ideas, suggestions, and contributions are always welcome!- New Module: Agentic Testing — Leveraging AI agents in penetration testing with Claude, GPT, Ollama, and other AI models.
Recently Updated Content : 2026
- iOS Pentesting Module
- Android Pentesting
- API Pentesting Module
- SAST / Source Code Review
- DevSecOps & SCA
- Thick Client Pentesting
- OWASP Top 10:2025 Web Application
- Threat Modeling, Design Review, Idea Review, Architecture Review
- New Module : LLMs OWASP Top 10
- New Module : MCP Pentesting
- New Module : Firewall (In progress)
Improvements and Advanced Techniques
- I will keep updating this section with new improvements, advanced techniques, and practical additions.
Agent Skill
Install a portable Agent Skill to use this knowledge base from Cursor, Claude and other agents for Agentic testing, Secure Coding and knowledgebase.
Who it's for: bug hunters, security testers, and penetration testers running real engagements through an agent, not just browsing static docs. Ground rules keep autonomous use safe: authorization is confirmed before active testing, high-impact actions are gated, findings pass a false-positive check before being drafted, and automated requests are paced to respect program rate limits.
Install (project-local):
npx skills add m14r41/PentestingEverything --skill pentesting-everythingInstall globally (available across projects):
npx skills add m14r41/PentestingEverything --skill pentesting-everything --globalTarget a specific client (examples):
npx skills add m14r41/PentestingEverything --skill pentesting-everything --agent cursor
npx skills add m14r41/PentestingEverything --skill pentesting-everything --agent claude-codeList without installing:
npx skills add m14r41/PentestingEverything --listSkill source: .agents/skills/pentesting-everything/.
| No. | Types of Pentesting | No. | Types of Pentesting |
|---|---|---|---|
| 1 | Web Application Pentesting | 13 | MCP Security Assessment |
| 2 | API Pentesting | 14 | LLM Security Assessment |
| 3 | Mobile Pentesting | 15 | Threat Modeling |
| 4 | Thick Client Pentesting | 16 | Configuration Review |
| 5 | Secure Code Review | 17 | Container & Kubernetes Assessment |
| 6 | Cloud Pentesting | 18 | CI/CD Pentesting |
| 7 | DevSecOps | 19 | IoT Pentesting |
| 8 | Network Pentesting | 20 | BlockChain Pentesting |
| 9 | Wi-Fi Pentesting | 21 | Phishing Assessment |
| 10 | Firewall Penetration | 22 | OSINT |
| 11 | Active Directory Pentesting | 23 | Forensic |
| 12 | Infrastructure Security |
Repository Activity — Latest 20 updates
Activity log is automatically updated every 15 days.
| Date & Time (IST) | Activity | Commit |
|---|---|---|
| 16 Aug 2026 · 01:19 IST | Update README with activity log information | e3dba5b |
| 16 Aug 2026 · 01:15 IST | Update cron schedule for repository activity workflow | 168865f |
| 16 Aug 2026 · 01:11 IST | Refactor repository activity workflow | 13b0aa9 |
| 16 Aug 2026 · 01:08 IST | Enable canceling in-progress deployments | 535dbd9 |
| 16 Aug 2026 · 00:56 IST | Enhance repository activity workflow | 904c875 |
| 15 Aug 2026 · 23:35 IST | Update Xamring-DotNet SSL Bypass.md | 0fa47be |
| 15 Aug 2026 · 23:31 IST | Add Xamarin SSL Bypass Setup | c3a2ffb |
| 15 Aug 2026 · 21:24 IST | docs: add Dessalines39394 as a contributor for code (#240) | b37ec50 |
| 15 Aug 2026 · 21:20 IST | Fix broken Star History chart link in README (#239) | d48b431 |
| 08 Aug 2026 · 16:10 IST | Merge pull request #238 from m14r41/m14r41-patch-1 | 91a97a0 |
| 08 Aug 2026 · 15:19 IST | Add MobSF Docker setup instructions | cddc785 |
| 08 Aug 2026 · 14:38 IST | Merge pull request #237 from m14r41/m14r41-patch-1 | 26415b1 |
| 08 Aug 2026 · 14:38 IST | Add SonarQube Docker setup and usage guide | 8b56dcc |
| 25 Jul 2026 · 01:33 IST | Merge pull request #236 from m14r41/m14r41-patch-1 | f0a342d |
| 25 Jul 2026 · 01:32 IST | Agent Skill | 32a4965 |
| 25 Jul 2026 · 01:26 IST | Fix broken CONTRIBUTING.md link: repo default branch is main, not master | 7ca8399 |
| 25 Jul 2026 · 01:16 IST | docs: add Spottie97 as a contributor | 94f517f |
| 25 Jul 2026 · 01:12 IST | Add v2.1.0 changelog entry for the Agent Skill | c6b9e79 |
| 22 Jul 2026 · 22:13 IST | Update README.md with XSS examples and resources | 4e0392f |
| 21 Jul 2026 · 17:34 IST | Add portable Agent Skill for authorized assessments | eca5a36 |
| Category | Tools |
|---|---|
| Web Application Pentesting | Acunetix, Burp Suite Professional, Dirb, FFUF, Nmap, Nikto, Nuclei, OWASP ZAP, SQLMap, WhatWeb, WPScan, Invicti (Netsparker), Fortify WebInspect |
| Android Security | adb, APKTool, Apkscan, AndroBugs, Android Studio / Genymotion, AppMon, Dexter/Objection (Objection), Drozer, Frida, Magisk, MITMProxy, MobSF, Quark Engine, JADX |
| iOS Security | checkra1n, Class-dump, Frida, iMazing, iOS-decrypt, iOS-Hook, MobSF, Needle, Objection, Palera1n, Passionfruit, SSL Kill Switch 2, Cycript |
| API Pentesting | Burp Suite Professional, GraphQL Raider, GraphQL Voyager, Insomnia, Kite Runner, Postman, Swagger UI |
| Secure Code Review | Bandit, Checkmarx, CodeQL, FindSecBugs, Gitleaks, Semgrep, SonarQube, Snyk, Veracode, Fortify Static (Workbench/Audit) |
| Thick-Client Security | Burp Suite Professional, dnSpy, de4dot, Fiddler, Ghidra, IDA Pro, OllyDbg, Process Explorer, x64dbg, CFF Explorer, Sysinternals Suite, Wireshark |
| Network Pentesting | Bettercap, CrackMapExec, Metasploit, Netcat, Nessus, Nmap, OpenVAS, Responder, Wireshark |
| Category | Tools |
|---|---|
| Active Directory Pentesting | BloodHound, Mimikatz, CrackMapExec, Impacket, Kerbrute, Rubeus, LDAPDomainDump, SharpHound, PowerView, ADRecon |
| Cloud Security | Prowler, ScoutSuite, CloudSploit, Pacu, Steampipe, CloudMapper, NCC Scout, kube-bench, Terrascan, KICS |
| IoT Security | Firmwalker, Binwalk, Firmware-Mod-Kit, Shodan, RIOT, JTAGulator, Qiling, Ghidra, Avatar2, Firmadyne |
| Firewall Pentesting | hping3, NPing, Scapy, Zmap, firewalk, FTester, Nmap (Firewall Bypass), Packet Sender, T50, Ettercap, TCPReplay |
| Firmware Analysis | Binwalk, Firmware Analysis Toolkit (FAT), QEMU, Ghidra, IDA Pro, Firmware-Mod-Kit, Radare2, Firmadyne |
| Container Security | Trivy, Aqua Microscanner, Clair, Anchore, Docker Bench, kube-hunter, Falco, Sysdig, Snyk, Grype |
| WiFi Pentesting | Aircrack-ng, Kismet, Bettercap, Reaver, Fluxion, Wireshark, hcxtools, Fern WiFi Cracker, Wifiphisher, Hashcat |
| DevSecOps | GitHub Advanced Security, Trivy, Snyk, Anchore, OWASP Dependency-Check, Jenkins, Checkmarx, Veracode, Dagda, Sysdig Secure, Cloud Custodian, Bridgecrew, Kubescape |
| OSINT | theHarvester, Maltego, SpiderFoot, Recon-ng, Shodan, FOCA, Google Dorks, OSINT Framework, GHunt, Sherlock, PhoneInfoga |
| Configuration Review | Lynis, OpenSCAP, Auditd, Tripwire, cis-cat Pro, Chef InSpec, Prowler, Kubescape |
| Phishing Simulation | GoPhish, SET, Evilginx2, Phishery, King Phisher, Modlishka, Phishing Frenzy |
| Forensics | Autopsy, Volatility, Sleuth Kit, FTK Imager, Redline, Magnet AXIOM, X-Ways, Bulk Extractor, ExifTool |
| Blockchain Security | Mythril, Slither, Manticore, Remix IDE, Oyente, SmartCheck, Echidna, Tenderly |
| Threat Modeling | Microsoft TMT, OWASP Threat Dragon, IriusRisk, SeaSponge, Draw.io, Pytm |
| Red Team Tools | Cobalt Strike, Sliver, Mythic, Empire, Metasploit, Brute Ratel, Koadic, FudgeC2, Nishang, PowerShell Empire |
| Blue Team Tools | Velociraptor, Wazuh, OSQuery, GRR, Sysmon, CrowdStrike Falcon, Elastic Security, Sigma Rules |
| SIEM & Log Analysis | Splunk, ELK Stack, Graylog, Wazuh, AlienVault OSSIM, SIEMonster, Logstash, Fluentd, Loki, Falco, Humio, Kibana, Loggly, Logz.io |
| Password Cracking | Hashcat, John the Ripper, Hydra, CrackStation, Cain & Abel, Medusa, THC-Hydra |
| Reverse Engineering | Ghidra, IDA Pro, x64dbg, OllyDbg, Binary Ninja, Radare2, Cutter |
| Hardware Hacking | ChipWhisperer, Saleae Logic, OpenOCD, JTAGulator, Bus Pirate, Flashrom, Arduino, Raspberry Pi, RTL-SDR |
| Social Engineering | SET, BeEF, King Phisher, Evilginx / Evilginx2, Modlishka, EyeWitness, PhishToolkit, PhishX, Psychological Frameworks (Pretexting, Elicitation) |
| SCADA/ICS Security | Snort, Wireshark, ModScan, ModbusPal, Scadafence, OpenPLC, GasPot, Conpot, PLCScan |
| Supply Chain Security | Snyk, OWASP Dependency-Check, Trivy, Syft, Grype, CycloneDX, Whitesource, Anchore Engine |
| Email Security Testing | GoPhish, Modlishka, SMTPTester, MailSniper, Evilginx2, Phish5, Email Header Analyzer |
| Mobile Malware Analysis | APKTool, MobSF, Jadx, Frida, VirusTotal Mobile, Droidbox, Bytecode Viewer, Drozer, Quark-Engine |
| AI/ML Security | Adversarial Robustness Toolbox (ART), TextAttack, Foolbox, IBM AI Explainability 360, CleverHans, Alibi Detect, SecML, DeepExploit |
| Security Automation / SOAR | StackStorm, Cortex XSOAR, Shuffle, DFIR-IR-Playbook, Phantom Cyber, Tines |
| Bug Bounty Toolkit | Amass, Sublist3r, Nuclei, HTTPX, Naabu, FFUF, GF, Dalfox, Kiterunner, Hakrawler, JSParser, ParamSpider |
| Credential Dumping & Cracking | LaZagne, Mimikatz, Hashcat, John the Ripper, Windows Credential Editor, CrackMapExec, GetNPUsers.py |
| Payload Generation | MSFVenom, Unicorn, Shellter, Veil, Nishang, Empire, Obfuscation.io, Metasploit, Donut |
| Honeypots / Deception | Cowrie, Dionaea, Kippo, Honeyd, T-Pot, Conpot, Canarytokens, Artillery |
| MacOS Security | KnockKnock, BlockBlock, OSXCollector, Objective-See Suite, MacMonitor, Little Snitch, Dylib Hijack Scanner |
| Windows Post-Exploitation | PowerView, Seatbelt, SharpUp, WinPEAS, Sherlock, Empire, FireEye Red Team Tools, SharpHound |
| Linux Post-Exploitation | LinPEAS, Linux Exploit Suggester, pspy, Chkrootkit, rkhunter, bashark, GTFOBins, Sudomy |
| Browser Security Testing | BeEF, XSStrike, XSSer, Burp Collaborator, NoScript, uBlock Origin, Chrome Developer Tools |
I appreciate your interest in contributing! please read Contribution Guidelines.
A heartfelt thanks to the amazing individuals for their contributions to this project. You can view emoji key to see the various ways you can contribute!
Marko Živanović 🔧 |
m14r41 💻 |
0xanon 💻 |
InfoBugs 💻 |
Ratnesh kumar 💻 |
Chandrabhushan Kumar 💻 |
Satya Prakash 💻 👀 |
Wei Lin 🌍 |
Reinhardt Erasmus 💻 |
Dessalines39394 💻 |
This project is open source (MIT) and includes third-party material such as PDFs and documents that belong to their original owners. It is shared in good faith for education only. If any of it is yours and you want it credited differently or removed, just ask and it will be handled promptly. See CONTENT_REMOVAL.md.
