


Open-source and AI-powered cybersecurity tools for offensive security, vulnerability management, and autonomous pentesting. Built by hackers in Latin…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Automated API security testing tool that scans REST and SOAP APIs for vulnerabilities using OpenAPI/Swagger specs and WSDL files. Deploys a full …

Automatic SQL injection and database takeover tool


A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24…

ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

An organizational asset and vulnerability management tool, with Jira integration, designed for generating application security reports.

Parse OpenAPI documents into Burp Suite for automating OpenAPI-based APIs security assessments (approved by PortSwigger for inclusion in their…

A python3 script searching for secret on swaggerhub

Cross-cloud S3-compatible object storage CLI to list, export, and download buckets across AWS, Aliyun, Tencent, Huawei and more, with anonymous…

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

🔗 Lightweight security orchestrator mobile application for URI vetting, providing a unified, multi-engine interface to aggregate and validate link…