
wafw00f
Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

The Swiss Army knife for automated Web Application Testing

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

A Framework for Integrating Application Security into Software Engineering (FIASSE) using the Securable Software Engineering Model (SSEM)

ADT is a toolset designed to help model application behavior, research and test security vulnerabilities, and facilitate reversing hostile code.

Enterprise Security API library providing security controls for Java web applications, including authentication, access control, input validation,…

A Android malware analysis tool that creates comprehensive runtime profiles by hooking into application behavior across cryptography, file systems,…

Library and CLI for mutating structured data (JSON, XML, X.509) to support grammar-based fuzzing, with multiple mutation strategies and integration…

Open-source mobile security testing suite for iOS and Android. Previously Passionfruit

Fermion, an electron wrapper for Frida & Monaco.

Detect, analyze and uniquely identify crashes in Windows applications

A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…



Fast XSS scanner with parameter analysis, WAF fingerprinting, and DOM/AST verification. Supports reflected, stored, and DOM-based XSS detection via…

Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)