#1General purpose tools for collecting various types of information about targets.
Kitploit recommended

A collection oneliner scripts for bug bounty
Artifact collection tool for *nix systems

A better version of my xssfinder tool - scans for different types of xss on a list of urls.

Network assessment tool for various UDP Services covering both IPv4 and IPv6 protocols

Maps attack surface of GWT applications by extracting obfuscated RPC endpoints and generating serialized request payloads for security testing.

A handy DNS service written in Go to aid in the detection of several types of blind vulnerabilities. It monitors a pentester's server for out-of-band…

TIH is an intelligence tool that helps you in searching for IOCs across multiple openly available security feeds and some well known APIs. The idea…

Network-based passive DNS logger capturing and logging DNS queries from live traffic or pcap files, outputting JSON for integration with SIEM and…

Python exploit for Jenkins CVE-2024-23897: arbitrary file read via CLI args4j parsing, enabling RCE. Scans hosts and extracts sensitive files from…

This tool allows you mass play any YouTube video, terminate apps and rename Chromecast device(s) obtained from Shodan.io

the ps utility, with an eBPF twist and container context

Modular information gathering framework for penetration testers, featuring website analysis, email/phone lookup, credit card BIN checking, IP…

I Know Where Your Page Lives: Derandomizing the latest Windows 10 Kernel - ZeroNights 2016

Twitter Intelligence OSINT project performs tracking and analysis of the Twitter

This is a simple python tool to automatically deface webdav vulnerable websites.

Python library and CLI for the Bug Bounty Recon API

macOS dig wrapper that appends spoofed local TXT records to DNS query output, designed to deceive LLM agents into performing automated penetration…

A BloodHound collector for Microsoft Configuration Manager