
wpprobe
A fast WordPress plugin enumeration tool

A fast WordPress plugin enumeration tool

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

A PoC exploit for CVE-2021-4191 - GitLab User Enumeration.

Keyless active-probe security auditor for Directus CMS. Proves public-role data exposure, user enumeration, unauthenticated version/schema leaks,…

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

Enterprise WAF evaluation tool that sends 90 real attack payloads across 6 suites (OWASP, API, bypass, rate limiting) and generates compliance-ready…

High-performance web fuzzer for content discovery, virtual host enumeration, and parameter fuzzing. Supports recursive scanning, multi-wordlist…

A fast, simple, recursive content discovery tool written in Rust.

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

RESTful API wrapping Nmap for automated network scanning, port detection, service enumeration, and vulnerability analysis with optional AI-powered…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Advanced web path brute-forcer for discovering hidden directories and files. Supports recursive scanning, custom wordlists, filters, proxies, and…

API-first subdomain discovery service using Certificate Transparency logs for fast, passive enumeration of subdomains via a REST API with JSON or…

Automated GraphQL security testing toolkit that discovers endpoints, introspects schemas, detects mutations and sensitive queries, and scores…