
wapiti
Web vulnerability scanner written in Python3

Web vulnerability scanner written in Python3

Inject code into running Python processes

Automatic SSTI detection tool with interactive interface

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

LLM powered fuzzing via OSS-Fuzz.

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive…

Sample extensions, scripts, and API uses for WinDbg.

A security scanner for your LLM agentic workflows

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

Documentation and reverse engineering of reCAPTCHA

TInjA is a CLI tool for testing web pages for template injection vulnerabilities and supports 44 of the most relevant template engines for eight…

GUI Burp Plugin to ease discovering of security holes in web applications

Windows NT ioctl bruteforcer and modular fuzzer

Exploit for Jenkins serialization vulnerability - CVE-2016-0792

A collection of useful resources for hacking WordPress and it's plugins and themes

ComfyEngine is a memory exploration toolkit built for people who need to monitor, patch, and script a running process.

A Magisk module that simplifies running the Frida server on Android, with easy management commands to download specific versions, enable or disable…