
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

Go-based CLI scanner for web cache poisoning and deception. Supports 10 poisoning techniques, multiple deception methods, built-in crawler, JSON…

Crawls web applications to detect second-order subdomain takeover vulnerabilities by collecting URLs and matching configurable rules for non-200…

WEBFANG, is my first CLI, a modular OSINT & Reconnaissance toolkit curated for Ethical Hackers and Red-Teamers. Sink fangs into web targets using a…

Async HTTP(S) scanner that greps response bodies and headers for strings or regex across hosts, ports, CIDR/ranges and TLS-cert vhosts.

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Port of Wappalyzer (uncovers technologies used on websites) to automate mass scanning.

Find web directories without bruteforce

Extracting URLs of a specific target based on the results of "commoncrawl.org"

Fetches JavaScript files quickly and comprehensively.


Exploiting misconfigured firebase databases

API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites

The recursive internet scanner for hackers. 🧡

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines,…

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more