
Scrapling
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!

🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Burp Suite's extension to scan and crawl Single Page Applications

A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file.

Google search crawler that collects URLs vulnerable to Apache Struts2 S2-045 (CVE-2017-5638) using configurable keywords and proxy support.

A script to search, scrape and scan for Apache Log4j CVE-2021-44228 affected files using Google dorks

Community curated list of templates for the nuclei engine to find security vulnerabilities.

HTTrack Website Copier, copy websites to your computer (Official repository)

AIL framework - Analysis Information Leak framework. Project moved to https://github.com/ail-project

🤖 Top-rated tools to scrape all major public sections from Facebook, Instagram, and Twitter (X) including posts (likes/comments), photos/videos,…

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets

Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and…

Port of Wappalyzer (uncovers technologies used on websites) to automate mass scanning.

Automated OSINT reconnaissance tool that queries Google and social platforms to gather intelligence on usernames and queries, with proxy rotation and…

Tool to find JavaScript files on Websites

htcap is a web application scanner able to crawl single page application (SPA) recursively by intercepting ajax calls and DOM changes.

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.