Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Scanners-Box — A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑 | Kitploit
Tools/GitHubGitHub/we5ter/scanners-box
Vulnerability ScannersIoT SecurityWeb SecurityPenetration TestingMobile SecurityBinary AnalysisLearning & EducationCurated ResourcesAI Security
GitHubwe5ter/scanners-box

Scanners-Box

A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑

9.0k2.4k1529 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

English | 简体中文 | Español

version license scanners ScanCodex MCP Server Share on X

Introduction

Scanners Box is a curated arsenal of 9,000+ ⭐ open-source cybersecurity treasures — with a special focus on AI-driven automated security agents and Red Team / Blue Team tooling. All tools feature source code available, covering 10+ categories from subdomain enumeration to IoT auditing, mobile analysis, smart contract scanning, and cloud security.

Project A³C

A³C — Autonomous AI Certification

Status: Active Type: Open Source

A³C Scanner-Box Authenticated

Projects displaying the A³C badge are officially certified by Scanners Box as trusted, active AI-powered autonomous projects.

The A³C badge is Scanners Box's official certification for open-source AI-powered autonomous projects — verified, active, and trusted tools powered by artificial intelligence.

Visit Project A³C

Contents

[!IMPORTANT] ❋⚛🐋 For AI

  • AI Autonomous Cybersecurity Agents
  • LLM-Powered Vulnerability Scanners
  • Security Auditing for AI Apps
  • AI Agent Runtime Controls
  • Security Auditing for Agent Skills
  • Autonomous Vulnerability Discovery and Remediation Skills
  • Scanners for Smart Contracts
  • Red Team vs Blue Team
  • Mobile App Packages Analysis
  • Binary Executables Analysis
  • Privacy Compliance
  • Subdomain Enumeration or Takeover
  • Database SQL Injection Vulnerability or Brute Force
  • Weak Usernames or Passwords Enumeration For Web
  • IoT Hardware Automated Audit
  • Mutiple types of Cross-site scripting Detection
  • Enterprise sensitive information Leak Scan
  • Malware Detection
  • Vulnerability Assessment for Middleware
  • Special Vulnerability Categories Scannners for Web
  • Dynamic or Static Code Analysis
  • Modular Design Scanners or Vulnerability Detecting Framework
  • Advanced Persistent Threat Detect

AI Autonomous Cybersecurity Agents

  • https://github.com/oritera/Cairn - A general-purpose state-space search engine validated on autonomous penetration testing — no predefined roles or workflows, purely goal-driven pathfinding

A³C Certified GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/KeygraphHQ/shannon - Autonomous white-box AI pentester for web apps & APIs — analyzes source code, identifies attack vectors, and executes real exploits pre-production

A³C Certified GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/SickHackPark/SickHackShark - Multi-agent AI platform for CTF automation — covers recon, scanning, exploitation, and flag capture end-to-end

A³C Certified GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/SanMuzZzZz/LuaN1aoAgent - LuaN1ao (鸾鸟) - A next-generation Autonomous Penetration Testing Agent powered by LLMs, integrating P-E-R Agent Collaboration with Causal Graph Reasoning to simulate security expert thinking patterns

A³C Certified GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Ed1s0nZ/CyberStrikeAI - An AI-native security testing platform in Go, integrating 100+ tools, intelligent orchestration, role-based testing, skills system, full lifecycle management, and a built-in lightweight C2 framework for authorized engagements

A³C Certified GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/ASCIT31/Dark-Moon - Autonomous AI pentesting engine performing continuous offensive security across web, cloud, AD and Kubernetes. Uses agentic reasoning, real exploit execution and attack path analysis to deliver proof-based vulnerabilities.

GitHub language count GitHub last commit GitHub stars GitHub

LLM-Powered Vulnerability Scanners

  • https://github.com/weareaisle/nano-analyzer - A minimal LLM-powered zero-day vulnerability scanner by AISLE

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/vercel-labs/deepsec - An agent-powered vulnerability scanner for on-demand review of all code in existing large-scale repos, surfacing hard-to-find issues that have been lurking in applications for a long time

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/vigolium/vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

GitHub language count GitHub last commit GitHub stars GitHub

Security Auditing for AI Apps

  • https://github.com/leondz/garak - LLM vulnerability scanner for hallucination, data leakage, promp injection, misinformation, toxicity generation, jailbreaks, and many other weaknesses

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/protectai/rebuff - Designed to protect AI applications from prompt injection (PI) attacks

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/mnns/LLMFuzzer - Fuzzing Framework for Large Language Models

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Tencent/AI-Infra-Guard - A.I.G (AI-Infra-Guard) integrates capabilities such as AI infrastructure vulnerability scanning, MCP Server risk detection, and LLM security assessments

GitHub language count GitHub last commit GitHub stars GitHub

AI Agent Runtime Controls

  • https://github.com/agentkitai/agentgate - Approval workflow engine for AI agents — define policies to auto-approve safe actions, auto-deny dangerous ones, and route the rest to a human via dashboard, Slack, Discord, or email

GitHub language count GitHub last commit GitHub stars GitHub

Security Auditing for Agent Skills

  • https://github.com/NVIDIA/SkillSpector - Security scanner for AI agent skills — detect vulnerabilities, malicious patterns, and security risks before installing agent skills (Claude Code, Codex CLI, Gemini CLI, etc.)

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/cisco-ai-defense/skill-scanner - A best-effort security scanner for AI Agent Skills — detects prompt injection, data exfiltration, and malicious code patterns via pattern-based detection (YAML+YARA), LLM-as-a-judge, and behavioral dataflow analysis. Supports OpenAI Codex Skills, Cursor Agent Skills, and Claude Code commands.

GitHub language count GitHub last commit GitHub stars GitHub

Autonomous Vulnerability Discovery and Remediation Skills

  • https://github.com/anthropics/defending-code-reference-harness - Skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can customize for end-to-end vulnerability management

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/cloudflare/security-audit-skill - A coding-agent skill for multi-phase security audits — recon, hunting, adversarial validation, reporting, structured output, and independent verification — with machine-readable findings

GitHub language count GitHub last commit GitHub stars GitHub

Scanners for Smart Contracts

  • https://github.com/ConsenSys/mythril - Security analysis tool for EVM bytecode. Supports smart contracts built for Ethereum, Hedera etc.

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/enzymefinance/oyente - An Analysis Tool for Smart Contracts

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/eth-sri/securify2 - Official security scanner for Ethereum smart contracts supported by the Ethereum Foundation

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/smartdec/smartcheck - Static analysis tool that detects vulnerabilities and bugs in Solidity programs

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/ivicanikolicsg/MAIAN - Automatic tool for finding trace vulnerabilities in Ethereum smart contracts

GitHub language count GitHub last commit GitHub stars GitHub

Red Team vs Blue Team

Supply Chain Analysis(SCA)

  • https://github.com/murphysecurity/murphysec - Open source tool for software supply chain security

GitHub language count GitHub last commit GitHub stars GitHub

Container and Cluster

  • https://github.com/cdk-team/CDK - A tool to gather information inside container/cluster and exploit them

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/cr0hn/dockerscan - Docker security analysis & hacking tools

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/armosec/kubescape - The first tool for testing if Kubernetes is deployed securely as defined in Kubernetes Hardening Guidance by to NSA and CISA

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/chaitin/veinmind-tools - Container security scanner for backdoor, malicious, weak pass and sensitive and the like.

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/deepfence/ThreatMapper - Scan for in-production vulnerabilities and exposed secrets, and identify attack paths to reach them remotely

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/deepfence/SecretScanner - Scan containers and host filesystems for unprotected keys, API tokens and passwords

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/cyberark/KubiScan - A tool to scan Kubernetes cluster for risky permissions

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/kvesta/vesta - A static analysis of vulnerabilities, Docker and Kubernetes cluster configuration detect toolkit

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/anchore/grype - A vulnerability scanner for container images and filesystems

GitHub language count GitHub last commit GitHub stars GitHub

Services fingerprint detection

  • https://github.com/EdgeSecurityTeam/EHole - Core system fingerprint detection tool for Red team

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/opabravo/mass-bruter - Mass bruteforce network protocols and default credentials for ports

GitHub language count GitHub last commit GitHub stars GitHub

Man-In-The-Middle

  • https://github.com/niloofarkheirkhah/nili - Tool for Network Scan, Man in the Middle, Protocol Reverse Engineering and Fuzzing

GitHub language count GitHub last commit GitHub stars GitHub

The framework

  • https://github.com/m4n3dw0lf/PytheM - Multi-purpose network pentest framework

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/FunnyWolf/Viper - Graphical, Modularization and weaponization intranet penetration tool

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/P1-Team/AlliN - Mostly used for asset collection before penetration and lateral movement of intranet

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/k8gege/LadonGo - Pentest framework for Windows/Linux/Mac intranet networks

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/shmilylty/netspy - Quickly scan the reachable network segmentation of the intranet

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/byt3bl33d3r/CrackMapExec - Swiss army knife for pentesting Windows/Active Directory environments

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/u21h2/nacs - Event-driven intranet pentest scanner

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/h4wkst3r/SCMKit - Source Code Management Attack Toolkit,such as GitHub Enterprise, GitLab Enterprise and Bitbucket Server

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/lijiejie/MisConfig_HTTP_Proxy_Scanner - Helps to scan misconfigured reverse proxy servers and misconfigured forward proxy servers

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/chainreactors/gogo - A highly controllable and scalable automation engine for red teams

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/freelabz/secator - secator - the pentester's swiss knife

GitHub language count GitHub last commit GitHub stars GitHub

Wireless Pentest

  • https://github.com/savio-code/fern-wifi-cracker - Testing and discovering flaws in ones own network

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/P0cL4bs/WiFi-Pumpkin - Framework for Rogue Wi-Fi Access Point Attack

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/MisterBianco/BoopSuite - A Suite of Tools written in Python for wireless auditing and security testing

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/besimaltnok/PiFinger - Searches for wifi-pineapple traces and calculate wireless network security score

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/derv82/wifite2 - A complete re-write of Wifite,Automated Wireless Attack Tool

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/D3Ext/WEF - Wi-Fi Exploitation Framework for 2.4 and 5 Ghz both attacks

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/pinecone-wifi/pinecone - A WLAN red team framework

GitHub language count GitHub last commit GitHub stars GitHub

Mobile Apps Packages Analysis

  • https://github.com/dwisiswant0/apkleaks - Scanning APK file for URIs, endpoints & secrets

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/kelvinBen/AppInfoScanner - Collecting information from APK file, support self-defined rules

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/maaaaz/androwarn - Yet another static code analyzer for malicious Android applications

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/quark-engine/quark-engine - Android Malware (Analysis | Scoring) System

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/droidefense/engine - Advance Android malware analysis framework

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/abhi-r3v0/Adhrit - Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks

GitHub language count GitHub last commit GitHub stars GitHub BlacHatUSA-arsenal-2022

  • https://github.com/pascal-lab/Tai-e - An easy-to-learn/use static analysis framework for Java, especially for Android

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Cyber-Buddy/APKHunt - A comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/cryptax/droidlysis - A pre-analysis tool for Android apps: it performs repetitive and boring tasks we'd typically do at the beginning of any reverse engineering

GitHub language count GitHub last commit GitHub stars GitHub

Binary Executables Analysis

  • https://github.com/m4rco-/dorothy2 - A malware/botnet analysis framework written in Ruby

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Tencent/HaboMalHunter - Used for automated malware analysis and security assessment on the Linux system

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/KeenSecurityLab/BinAbsInspector - Static analyzer for automated reverse engineering and scanning vulnerabilities in binaries

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/fkie-cad/cwe_checker - Static analyzer for detecting common bug classes such as buffer overflows in binaries

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/airbus-seclab/bincat - Binary code static analyser, with IDA integration. Performs value and taint analysis

GitHub language count GitHub last commit GitHub stars GitHub

Privacy Compliance

  • https://github.com/riskscanner/riskscanner - Multi-cloud privacy compliance scanning platform, through Cloud Custodian's YAML DSL to define scanning rules

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/momosecurity/bombus - Enterprise security and privacy compliance platform

GitHub language count GitHub last commit GitHub stars GitHub

Subdomain Enumeration or Takeover

  • https://github.com/lijiejie/subDomainsBrute - A classical subdomain enumeration Tool by lijiejie

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/ring04h/wydomain - A Speed and Precision subdomain enumeration Tool by ringzero

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/le4f/dnsmaper - Subdomain enumeration tool with map record

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/TheRook/subbrute - A DNS meta-query spider that enumerates DNS records, and subdomains,supported API

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/We5ter/GSDF - Subdomain enumeration via Google certificate transparency

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/mandatoryprogrammer/cloudflare_enum - Subdomain enumeration via CloudFlare

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/guelfoweb/knock - Knock subdomain scan

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/exp-db/PythonPool/tree/master/Tools/DomainSeeker - An intergratd Python subdomain enumeration tool

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/code-scan/BroDomain - Find brother domain

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/chuhades/dnsbrute - A fast domain brute tool

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/yanxiu0614/subdomain3 - A simple and fast tool for bruting subdomains

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/michenriksen/aquatone - A powerful subdomain tool and domain takeovers finding tools

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/evilsocket/dnssearch - A subdomain enumeration tool

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/reconned/domained - Subdomain enumeration tools for bug hunting

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/bit4woo/Teemo - A domain name & Email address collection tool

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/laramies/theHarvester - E-mail, subdomain and people names harvester

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/nmalcolm/Inventus - A spider designed to find subdomains of a specific domain by crawling it

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/aboul3la/Sublist3r - Fast subdomains enumeration tool for penetration testers

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/jonluca/Anubis - Subdomain enumeration and information gathering tool

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/n4xh4ck5/N4xD0rk - Listing subdomains about a main domain

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/infosec-au/altdns - Subdomain discovery through alterations and permutations

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/FeeiCN/ESD - Enumeration sub domains tool,based on AsyncIO and non-repeating dict

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/UnaPibaGeek/ctfr - Abusing certificate transparency logs for getting HTTPS websites subdomains

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/giovanifss/Dumb - Dumain Bruteforcer, a fast and flexible domain bruteforcer

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/OWASP/Amass - In-depth Attack Surface Mapping and Asset Discovery

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Ice3man543/subfinder - A subdomain discovery tool which has a simple modular architecture and has been aimed as a successor to sublist3r project

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Ice3man543/SubOver - A powerful subdomain takeover tool

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/janniskirschner/horn3t - Powerful Visual Subdomain Enumeration

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/yunxu1/dnsub - A high concurrency and cross platform subdomain scanner based on Golang

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/shmilylty/OneForAll - An ultimate subdomains scanner integrated multiple subdomain scanning tools

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/knownsec/ksubdomain - A stateless and cross-platform subdomain enumeration tool, speed up to 30w/s on Mac and Windows, and 160w/s on Linux

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/gwen001/github-subdomains - Find subdomains on GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/bit4woo/domain_hunter_pro - Domain finder and Targets management, automated information collection, integrated with burpsuite

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/m4ll0k/takeover - Sub-Domain TakeOver Vulnerability Scanner

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/v4d1/Dome - Active and/or passive scan to obtain subdomains and search for open port

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/cramppet/regulator - Automated subdomain enumeration tool by learning of regexes for DNS discovery

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/hadriansecurity/subwiz - A lightweight GPT model, trained to discover subdomains.

GitHub language count GitHub last commit GitHub stars GitHub

Database SQL Injection Vulnerability or Brute Force

  • https://github.com/0xbug/SQLiScanner - A SQLi vulnerability scanner via SQLMAP and Charles

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/stamparm/DSSS - A SQLi vulnerability scanner with 99 lines of code

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/youngyangyang04/NoSQLAttack - A SQLi vulnerability scanner for mongoDB

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Neohapsis/bbqsql - A blind SQLi vulnerability scanner

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/NetSPI/PowerUpSQL - A SQLi vulnerability scanner with Powershell script

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/WhitewidowScanner/whitewidow - Another SQL vulnerability scanner

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/stampery/mongoaudit - A powerful MongoDB auditing and pentesting tool

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/torque59/Nosql-Exploitation-Framework - A Python framework For NoSQL scanning and exploitation

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/missDronio/blindy - Simple script to automate brutforcing blind sql injection vulnerabilities

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/fengxuangit/Fox-scan - A initiative and passive SQL injection vulnerable test tools

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/JohnTroony/Blisqy - Exploit time-based blind-SQL injection in HTTP-Headers

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/ron190/jsql-injection - A lightweight application used to find database information from a distant server

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Hadesy2k/sqliv - Massive SQL injection vulnerability scanner

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/s0md3v/sqlmate - A friend of SQLmap which will do what you always expected from SQLmap

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/m8r0wn/enumdb - MySQL and MSSQL brute force and post exploitation tool

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/tariqhawis/injectbot - A web-based, easy-to-use, SQL injection scanner and exploiter tool

GitHub language count GitHub last commit GitHub stars GitHub

Weak Usernames or Passwords Enumeration For Web

  • https://github.com/lijiejie/htpwdScan - A python HTTP weak pass scanner

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/netxfly/crack_ssh - SSH, Redis, mongoDB weak password bruteforcer

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/shengqi158/weak_password_detect - A python HTTP weak password scanner

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/s0md3v/Blazy - a modern login bruteforcer which also tests for CSRF, Clickjacking, Cloudflare and WAF

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/MooseDojo/myBFF - Web application brute force framework,supports Citrix Gateway,CiscoVPN and so on

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/TideSec/web_pwd_common_crack - A common web weak_password cracking script,can detect batches of management backgrounds without verification codes

GitHub language count GitHub last commit GitHub stars GitHub

IoT Hardware Automated Audit

  • https://github.com/rapid7/IoTSeeker - Weak-password IoT devices scanner

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/shodan-labs/iotdb - IoT Devices scanner via nmap

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/googleinurl/RouterHunterBR - Testing vulnerabilities in devices and routers connected to the Internet

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/scu-igroup/telnet-scanner - Weak telnet password scanner based on password enumeration

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/viraintel/OWASP-Nettacker - Network information gathering vulnerability scanner,most useful to scan IoT

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/threat9/routersploit - Exploitation Framework for embedded Devices,such as router

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/w3h/icsmaster/tree/master/nse - Digital bond's ICS enumeration tools

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/firmianay/firmeye - An IDA plug-in, based on sensitive function parameter backtracking to assist in vulnerability mining

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/bahaabdelwahed/st - An advanced security tool engineered specifically to scrutinize and detect threats within the intricate protocols utilized by IoT (Internet of Things) devices

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/0x4D31/salt-scanner - Linux vulnerability scanner based on Salt Open and vulners audit API, with Slack notifications and JIRA integration

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/vulmon/Vulmap - Local vulnerability scanning programs for Windows and Linux operating systems

GitHub language count GitHub last commit GitHub stars GitHub

Mutiple types of Cross-site scripting Detection

  • https://github.com/0x584A/fuzzXssPHP - A very simple reflected XSS scanner supports GET/POST

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/chuhades/xss_scan - Reflected XSS scanner

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/BlackHole1/autoFindXssAndCsrf - A plugin for browser that checks automatically whether a page haves XSS and CSRF vulnerabilities

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/shogunlab/shuriken - XSS command line tool for testing lists of XSS payloads on web apps

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/s0md3v/XSStrike - Fuzz and bruteforce parameters for XSS, WAFs detect and bypass

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/stamparm/DSXS - A fully functional cross-site scripting vulnerability scanner,supporting GET and POST parameters,and written in under 100 lines of code

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/fcavallarin/domdig - DOM XSS scanner for Single Page Applications

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/lwzSoviet/NoXss - Faster reflected-xss and dom-xss scanner based on Phantomjs

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/pwn0sec/PwnXSS - A powerful XSS scanner made in python 3.7

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/hahwul/dalfox - Parameter Analysis and XSS Scanning tool based on golang

GitHub language count GitHub last commit GitHub stars GitHub

Enterprise sensitive information Leak Scan

  • https://github.com/x0day/Multisearch-v2 - Enterprise assets collector based on search engine

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Ekultek/Zeus-Scanner - An advanced dork searching tool that is capable of finding IP address /URL blocked by search engine,and can run sqlmap and nmap scans on the URL's

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/metac0rtex/GitHarvester - Used for harvesting information from GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/repoog/GitPrey - Searching sensitive files and contents in GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/0xbug/Hawkeye - Github leak scan for enterprise

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/UnkL4b/GitMiner - Advanced search tool and automation in Github

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/dxa4481/truffleHog - Searches high entropy strings through git repositories

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/1N3/Goohak - Automatically launch Google hacking queries against a target domain

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/UKHomeOffice/repo-security-scanner - CLI tool that finds secrets accidentally committed to a git repo, eg passwords, private keys

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/FeeiCN/GSIL - Github sensitive information leakage scan

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/MiSecurity/x-patrol - Github leaked patrol

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/anshumanbh/git-all-secrets - A tool to capture all the git secrets by leveraging multiple open source git searching tools

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/VKSRC/Github-Monitor - Github sensitive information leakage monitor by vipkid SRC

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/eth0izzle/shhgit - A docker and web based monitor for finding secrets and sensitive files across GitHub

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/SAP/credential-digger - A GitHub scanning tool that identifies hardcoded credentials, filtering the false positive data through machine learning models

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/sdushantha/dora - Find exposed API keys based on RegEx and get exploitation methods for some of keys that are found

GitHub language count GitHub last commit GitHub stars GitHub

Malware Detection

  • https://github.com/he1m4n6a/findWebshell - Simple webshell detector

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/nbs-system/php-malware-finder - An awesome tool to detect potentially malicious PHP files

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/emposha/PHP-Shell-Detector - Helps you find and identify PHP/Perl/Asp/Aspx shells

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/erevus-cn/scan_webshell - Simple webshell detector

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/emposha/Shell-Detector - A application that helps you find and identify PHP/Perl/Asp/Aspx shells

GitHub language count GitHub last commit GitHub stars GitHub

Vulnerability Assessment for Middleware

  • https://github.com/ring04h/wyportmap - Target port scanning + system service fingerprint recognition

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/ring04h/weakfilescan - Dynamic multi - thread sensitive information leak detection tool

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/EnableSecurity/wafw00f - Identify and fingerprint Web Application Firewall

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/rbsec/sslscan - Tests SSL/TLS enabled services to discover supported cipher suites

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/TideSec/TideFinger - Web fingerprint identification tool, more fingerprint database, more detection methods

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/TideSec/FuzzScanner - Comprehensive web information collection platform, easy to deploy, versatile and practical

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/urbanadventurer/whatweb - Website fingerprinter

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/tanjiti/FingerPrint - Another website fingerprinter

GitHub language count GitHub last commit GitHub stars GitHub


Read more

Download Tool