




A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

Try to reproduce this issue with Docker

An asynchronous enumeration & vulnerability scanner. Run all the tools on all the hosts.

Community curated list of templates for the nuclei engine to find security vulnerabilities.

A high performance go implementation of Wappalyzer Technology Detection Library

Modular framework for discovering and analyzing open directories on the web. Crawls URLs, extracts content, applies YARA/ClamAV scanning, and outputs…


High speed/Low cost CommonCrawl RegExp in Node.js

Port of Wappalyzer (uncovers technologies used on websites) to automate mass scanning.

Burp Suite's extension to scan and crawl Single Page Applications

Undetected version of the Playwright testing and automation library.

Rock-On is a all in one Recon tool that will just get a single entry of the Domain name and do all of the work alone.

GUI based offensive penetration testing tool (Open Source)

A short scraper looking for a POC of CVE-2024-49112

declutters url lists for crawling/pentesting