
dalfox
Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fil-C: completely compatible memory safety for C and C++


A next-generation crawling and spidering framework.

Automatic SQL injection and database takeover tool

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

GNU IFUNC is the real culprit behind CVE-2024-3094

Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)

Web vulnerability scanner written in Python3

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

match functions in binaries by what they do, not what their bytes look like. behavioral function fingerprinting via microexecution.

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

XSStrike based XSS scanner with custom features. Detects XSS vulnerabilities in web applications.

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings