SaaSHub helps you find the best software and product alternatives Learn more →
Top 23 Python Redteam Projects
-
Wow, it's actually real.
https://old.reddit.com/r/github/comments/1at9br4/i_am_new_to...
https://github.com/sherlock-project/sherlock/issues/2011
-
SaaSHub
SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives
-
PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
if you've never worked on SQL injection that's fine there is a PWNSOME REPOSITORY(get it? pwn + awesome) called[ Payload All The Things (https://github.com/swisskyrepo/PayloadsAllTheThings) it has different payloads for different web vulnerabilities.
-
Project mention: Should you leave red herrings about yourself online? | news.ycombinator.com | 2026-05-11
This article reminded me of seeing this in GH trending repositories last month: https://github.com/soxoj/maigret
"For educational and lawful purposes only"
-
Project mention: Introducing Installerpedia - Install Anything With Zero Hassle | dev.to | 2026-01-11
"installation_methods": [ { "instructions": [ { "command": "curl -LsSf https://astral.sh/uv/install.sh | sh" }, { "command": "git clone https://github.com/laramies/theHarvester" }, { "command": "cd theHarvester" }, { "command": "uv sync" }, { "command": "uv run theHarvester" } ], "title": "Binary Installation" } ]
-
-
Villain
Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).
-
malicious-pdf
💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh
-
Project mention: Snoop Project Update (search for usernames on 5k websites) | news.ycombinator.com | 2026-01-01
-
-
Lockdoor-Framework
🔐 Lockdoor Framework : A Penetration Testing framework with Cyber Security Resources
-
-
-
sam-the-admin
Exploiting CVE-2021-42278 and CVE-2021-42287 to impersonate DA from standard domain user
-
SlackPirate
Slack Enumeration and Extraction Tool - extract sensitive information from a Slack Workspace
-
-
-
Spoofy
Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.
-
GTFONow
Automatic privilege escalation for misconfigured capabilities, sudo and suid binaries using GTFOBins.
-
-
TheBigBrother
The Big Brother V5.0 is a weaponized OSINT platform featuring username enumeration (473+ platforms), quad-vector visual intelligence, Sky Radar tracking, crypto wallet analysis, SSL intelligence, digital footprint reconstruction, EXIF extraction, advanced dorking, and network reconnaissance.
Project mention: The Big Brother v3.0 is a weaponized OSINT platform | news.ycombinator.com | 2026-02-22 -
Dome
Dome - Subdomain Enumeration Tool. Fast and reliable python script that makes active and/or passive scan to obtain subdomains and search for open ports. (by v4d1)
-
-
GoodHound
Uses Sharphound, Bloodhound and Neo4j to produce an actionable list of attack paths for targeted remediation.
Python Redteam discussion
Python Redteam related posts
-
Introducing Installerpedia - Install Anything With Zero Hassle
-
Search for sensitive data using theHarvester and h8mail tools
-
Docx, doc macro rev shell generator?
-
hey guys which would be easier to make, a malicious docx or pdf?
-
What are some fun cybersecurity-related coding projects?
-
HavocNotion: A simple ExternalC2 POC for Havoc C2. Communicates over Notion using a custom python agent, handler and extc2 channel.
-
University final year project
-
A note from our sponsor - SaaSHub
www.saashub.com | 21 Jun 2026
Index
What are some of the best open-source Redteam projects in Python? This list will help you:
| # | Project | Stars |
|---|---|---|
| 1 | sherlock | 85,206 |
| 2 | PayloadsAllTheThings | 78,479 |
| 3 | maigret | 33,196 |
| 4 | theHarvester | 16,512 |
| 5 | dirsearch | 14,406 |
| 6 | Villain | 4,382 |
| 7 | malicious-pdf | 4,079 |
| 8 | snoop | 3,946 |
| 9 | 100-redteam-projects | 2,880 |
| 10 | Lockdoor-Framework | 1,535 |
| 11 | PlumHound | 1,292 |
| 12 | VcenterKit | 1,254 |
| 13 | sam-the-admin | 1,049 |
| 14 | SlackPirate | 780 |
| 15 | emploleaks | 774 |
| 16 | Octopus | 765 |
| 17 | Spoofy | 763 |
| 18 | GTFONow | 638 |
| 19 | overlord | 633 |
| 20 | TheBigBrother | 620 |
| 21 | Dome | 540 |
| 22 | fileless-elf-exec | 503 |
| 23 | GoodHound | 485 |