
aura-inspector
Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Cloud Container Attack Tool (CCAT) is a tool for testing security of container environments.

A list of awesome penetration testing tools and resources.

Practical labs, notes, and reports for CEH v13 modules — covering web hacking, network pentesting, malware analysis, social engineering, and security…

Fast subdomain takeover scanner with 50+ signatures, supporting cloud provider integrations (AWS, Azure, Cloudflare) and CI/CD pipeline mode for…

All-in-one penetration testing toolkit aggregating 185+ tools across 20 categories including information gathering, web & wireless attacks, phishing,…

Directory/File, DNS and VHost busting tool written in Go

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and…

Security Tool to Look For Interesting Files in S3 Buckets

A penetration testing tool to enumerate and analyse Amazon S3 Buckets owned by a domain.

Automated Kubernetes cluster penetration testing tool that exploits misconfigurations in API, Kubelet, etcd, and Dashboard to achieve node takeover…

Gorsair gives root access on remote docker containers that expose their APIs

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

ProjectDiscovery's Open Source Tool Manager

CyberArk Security Audit

Create On Demand Disposable OpenVPN Endpoints on AWS.

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.