Stream helps developers build engaging apps that scale to millions with performant and flexible Chat, Feeds, Moderation, and Video APIs and SDKs powered by a global edge network and enterprise-grade infrastructure. Learn more →
Top 23 Python Hacking Projects
-
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
if you've never worked on SQL injection that's fine there is a PWNSOME REPOSITORY(get it? pwn + awesome) called[ Payload All The Things (https://github.com/swisskyrepo/PayloadsAllTheThings) it has different payloads for different web vulnerabilities.
-
Stream
Stream - Scalable APIs for Chat, Feeds, Moderation, & Video. Stream helps developers build engaging apps that scale to millions with performant and flexible Chat, Feeds, Moderation, and Video APIs and SDKs powered by a global edge network and enterprise-grade infrastructure.
-
-
Ciphey
⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡
-
-
-
mastg
The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
-
Plug in the SDR into your Laptop and install Universal Radio Hacker (URH) software. Get your ceiling fan light remote control ready and record the RF signal with URH. Usually, the RF frequency is 433.92M.
-
InfluxDB
InfluxDB – Built for High-Performance Time Series Workloads. InfluxDB 3 OSS is now GA. Transform, enrich, and act on time series data directly in the database. Automate critical tasks and eliminate the need to move data externally. Download now.
-
Osintgram
Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname
-
bbot is a recursive internet scanner that supports Python-based modules.
-
-
pyWhat
🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it is! 🧙♀️
-
-
PhoneSploit-Pro
An all-in-one hacking tool to remotely exploit Android devices using ADB and Metasploit-Framework to get a Meterpreter session.
-
-
h8mail
Email OSINT & Password breach hunting tool, locally or using premium services. Supports chasing down related email
-
Villain
Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).
-
pentest-wiki
PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others.
-
-
hoaxshell
A Windows reverse shell payload generator and handler that abuses the http(s) protocol to establish a beacon-like reverse shell.
-
-
Ghost
Ghost Framework is an Android post-exploitation framework that exploits the Android Debug Bridge to remotely access an Android device. (by EntySec)
-
-
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
Python Hacking discussion
Python Hacking related posts
-
Reverse Engineering a 27MHz RC Toy Communication Using RTL SDR
-
Irish-Name-Repo 2 - picoCTF '19 (web)
-
HTB - Bastion (Windows)
-
List of Useful Payloads and Bypass for Web Application Security and Pentest/CTF
-
Blacklanternsecurity / Bbot
-
Show HN: Outcheckr- Webpage outbound link enumerator with threading
-
Outcheckr- A webpage outbound link enumerator with threading support
-
A note from our sponsor - Stream
getstream.io | 16 Nov 2025
Index
What are some of the best open-source Hacking projects in Python? This list will help you:
| # | Project | Stars |
|---|---|---|
| 1 | PayloadsAllTheThings | 71,639 |
| 2 | hackingtool | 54,018 |
| 3 | Ciphey | 20,165 |
| 4 | spiderfoot | 15,846 |
| 5 | dirsearch | 13,651 |
| 6 | mastg | 12,550 |
| 7 | urh | 11,941 |
| 8 | Osintgram | 11,760 |
| 9 | bbot | 9,135 |
| 10 | trape | 8,458 |
| 11 | pyWhat | 7,077 |
| 12 | caldera | 6,529 |
| 13 | PhoneSploit-Pro | 5,382 |
| 14 | NetExec | 4,916 |
| 15 | h8mail | 4,715 |
| 16 | Villain | 4,264 |
| 17 | pentest-wiki | 3,633 |
| 18 | TorBot | 3,596 |
| 19 | hoaxshell | 3,365 |
| 20 | Raccoon | 3,259 |
| 21 | Ghost | 3,144 |
| 22 | github-dorks | 3,075 |
| 23 | trackerjacker | 2,689 |