
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Web vulnerability scanner written in Python3


Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Automatic SQL injection and database takeover tool

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.

Sample extensions, scripts, and API uses for WinDbg.

A security scanner for your LLM agentic workflows

Elite is the client-side component of the Covenant project. Covenant is a .NET command and control framework that aims to highlight the attack…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

A wrapper around grep, to help you grep for things

Scans code diffs with context to build an impact graph and uses LLMs to find vulnerabilities, supporting multi-repo scans and CI gating with SARIF…

A fast, simple, recursive content discovery tool written in Rust.

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

A collection of useful resources for hacking WordPress and it's plugins and themes

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

GUI Burp Plugin to ease discovering of security holes in web applications