
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Automatic SSTI detection tool with interactive interface

Web vulnerability scanner written in Python3

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Automatic SQL injection and database takeover tool

A next-generation crawling and spidering framework.

A collection of my Frida instrumentation scripts to reverse engineer mobile apps and more.

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

A fast, simple, recursive content discovery tool written in Rust.

A powerful decompiler that lets you reverse-engineer React Native mobile apps by converting their compiled Hermes bytecode (.hbc) files back into…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

An strace-like program for the Windows 'native' API
