
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Web vulnerability scanner written in Python3

AI-powered bug bounty hunting toolkit that works with or without subscription.

AI-powered bug bounty hunting toolkit that works with or without subscription.

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

AI-powered bug bounty hunting toolkit that works with or without subscription.

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.

Modular DevSecOps toolset for REST API security testing, designed for developers, sysadmins, and penetration testers to automate security checks…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more

AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

Automatic SQL injection and database takeover tool