

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

Automatic SSTI detection tool with interactive interface

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Web vulnerability scanner written in Python3

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

Automated prompt injection testing framework for LLM-integrated applications with dual-LLM architecture.

Collections of my POCs for android vendor CVEs

Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing,…

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

Grammar-guided evolutionary fuzzer for dynamic analysis of AT command interfaces on Android smartphones via Bluetooth and USB, uncovering DoS,…

An open, local-first security testing platform for pentesters, AI agents, CI/CD pipelines, and teams.

Chrome extension for fast web fuzzing to discover hidden files and directories during penetration testing and vulnerability analysis.

PenBox - A Penetration Testing Framework - The Tool With All The Tools , The Hacker's Repo

BootStomp: a bootloader vulnerability finder


☸The first ever dependency-aware GraphQL API testing tool!