
py3webfuzz
A Python3 module to assist in fuzzing web applications

A Python3 module to assist in fuzzing web applications

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

Smart ssrf scanner using different methods like parameter brute forcing in post and get...


A wordlist framework to fullfill your kinks with your wordlists. For security researchers, bug bounty and hackers.

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

针对JWT渗透开发的漏洞验证/密钥爆破工具,针对CVE-2015-9235/空白密钥/未验证签名攻击/CVE-2016-10555/CVE-2018-0114/CVE-2020-28042的结果生成用于FUZZ,也可使用字典/字符枚举(包括JJWT)的方式进行爆破(JWT Crack)

Brute-force tool for discovering hidden GET and POST parameters in web applications, supporting custom wordlists and concurrent requests.

Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

Super Simple Python Word List Generator for Fuzzing and Brute Forcing in Python