


Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Collaborative application security testing between humans and agents via CLI and MCP

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through WebDriver BiDi

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Automatic SQL injection and database takeover tool

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

A next-generation crawling and spidering framework.

Evidence-oriented DAST scanner in Go that crawls web apps and APIs, then runs adaptive SQLi, XSS, RCE, SSRF, and auth checks with replayable proof.

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Web vulnerability scanner written in Python3

AI-powered bug bounty hunting toolkit that works with or without subscription.

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision