
faraday
Open Source Vulnerability Management Platform

Open Source Vulnerability Management Platform

A next-generation crawling and spidering framework.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

CLI client for bulk DIARIO API consumption: upload PDF/Office documents, query file hashes, and automate malware analysis workflows via command-line…

Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

The simple PoC of CVE-2023-27587

List of API's for gathering information about phone numbers, addresses, domains etc

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

A fast, simple, recursive content discovery tool written in Rust.

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24…

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…


Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

A Burp Suite Extension for Application Penetration Testing to map flows and vulnerabilities