Open source pentest projects

Every project in the registry tagged pentest, ranked by real GitHub adoption.

projects 3 combined stars ★ 8.4K refresh nightly
01 black-hat-rust ★ 4.4K

Applied offensive security with Rust - https://kerkour.com/black-hat-rust

last push12 months ago languageRust licenseMIT
02 pwndoc ★ 2.9K

Pentest Report Generator

last push7 days ago languageJavaScript licenseMIT
03 xalgorix ★ 1.1K

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

last push2 days ago languageGo licenseApache-2.0

← all tags

Frequently asked questions

How many open source pentest projects are there?

This registry tracks 3 projects tagged pentest, with 8,401 GitHub stars between them. The most-adopted is black-hat-rust at 4,403 stars.

Are these pentest projects free to use?

Yes — 3 of the 3 carry an explicit open-source licence across 2 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which pentest project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these pentest projects still maintained?

2 of the 3 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.