
SecLists
Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Python-based interactive packet manipulation library for forging, decoding, sending, capturing, and analyzing network packets across a wide range of…

Fast passive subdomain enumeration tool.

The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain…

dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.

Portable DNS resolver in Rust — .numa local domains, ad blocking, developer overrides

ioc2rpz is a place where threat intelligence meets DNS.

Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)

The modern, high-speed successor to nsec3walker. A specialized NSEC3 forensics engine built in Go for rapid zone harvesting and automated hash…

In-depth attack surface mapping and asset discovery

Subdomain enumeration tool, asynchronous dns packets, use pcap to scan 1600,000 subdomains in 1 second

Proof-of-concept exploit for CVE-2023-52235 demonstrating DNS rebinding attack against SpaceX Starlink user terminals to bypass network security…

High-speed DNS resolver and subdomain bruteforcer with accurate wildcard filtering and DNS poisoning validation for precise reconnaissance.

MassDNS wrapper written in go to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard filtering and easy…