
Egyscan
Egyscan The Best web vulnerability scanner; it's a multifaceted security powerhouse designed to fortify your web applications against malicious…

Egyscan The Best web vulnerability scanner; it's a multifaceted security powerhouse designed to fortify your web applications against malicious…

Next generation web scanner

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Crawls web applications to detect second-order subdomain takeover vulnerabilities by collecting URLs and matching configurable rules for non-200…

Turn any web app into an API. Chrome extension captures browser traffic, auto-generates schemas, lets AI replay APIs directly. No official API needed.

Simple random DNS, HTTP/S internet traffic noise generator

Automated OSINT reconnaissance tool that queries Google and social platforms to gather intelligence on usernames and queries, with proxy rotation and…

Privacy-respecting metasearch engine that aggregates results from multiple search services without tracking or profiling users. Self-hostable with…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Fetch all the URLs that the Wayback Machine knows about for a domain

OnionSearch is a script that scrapes urls on different .onion search engines.

Automated white-hat vulnerability scanner that monitors HackerOne and Bugcrowd assets, performs subdomain enumeration, crawling, fingerprinting, and…

Python Pastebin Webcrawler that returns list of public pastebins containing keywords

Rock-On is a all in one Recon tool that will just get a single entry of the Domain name and do all of the work alone.

Automated Google dork scanner that fetches exploit-db dork lists and scans targets or the entire internet for vulnerable applications, secret files,…

OSINT tool that finds domains, subdomains, directories, endpoints and files for a given seed URL.

Async HTTP(S) scanner that greps response bodies and headers for strings or regex across hosts, ports, CIDR/ranges and TLS-cert vhosts.

CLI website vulnerability scanner that detects outdated server software, insecure HTTP headers, and extracts Cloudflare IP/port data with performance…