#1General purpose tools for collecting various types of information about targets.
Kitploit recommended

C-based Android static analysis framework for decompilation, secret detection, endpoint discovery, permission analysis, and native library scanning…

OSINT tool that finds domains, subdomains, directories, endpoints and files for a given seed URL.

Simple framework to extract "actionable" data from Android malware (C&Cs, phone numbers etc.)

A script that checks for vulnerable Log4j (CVE-2021-44228) systems using injection of the payload in common HTTP headers.

This tool is based on regex with effective standards for detecting phishing sites in real time using certstream and can also detect punycode (IDNA)…

Automated CORS misconfiguration discovery tool using typosquatting domains and browser service workers to probe internal networks of bug bounty…

Enumerate AD through LDAP with a collection of helpfull scripts being bundled

Proof of Concept for CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207

ProfileHound - BloodHound OpenGraph collector for user profiles stored on domain machines. Make informed decisions about looting secrets by…

Scans public GitHub repositories for accidentally uploaded sensitive data like credentials, secret keys, and tokens using a personal access token.

Golang tool which helps dropping the irrelevant entries from your ffuf result file.

Python-based web security scanner that analyzes HTTP headers, SSL/TLS, DNS records, and common misconfigurations to generate a scored security report…

PowerShell toolkit for Active Directory penetration testing, featuring domain/user/group enumeration, trust relationship analysis, RDP configuration,…

AI-powered web scraping and data extraction library that extracts structured information from any webpage using natural language instructions, with…

🦁 Python project to identify and scan for vulnerabilities related to the Joomla CMS project. It scans for common misconfigurations and public…

A collector and derivation engine. It maps your environment, evaluates effective permissions and trust, and writes a complete attack graph as a…

Modular web application reconnaissance framework for automated subdomain enumeration, directory brute-forcing, and extraction of endpoints, JS URLs,…

Tool designed to help identify open Elasticsearch servers that are exposing sensitive information