
lighthouse
A Coverage Explorer for Reverse Engineers

A Coverage Explorer for Reverse Engineers

Evidence-oriented DAST scanner in Go that crawls web apps and APIs, then runs adaptive SQLi, XSS, RCE, SSRF, and auth checks with replayable proof.


REx@Skill - Agentic Reverse Engineering eXecution Skill for binary vulnerability discovery

End-to-end agentic smart contract fuzzing and threat hunting

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

Curated collection of custom wordlists for fuzzing, DNS enumeration, parameter discovery, and default credentials, plus a Go generator for nuclei…

A Burp Suite extension that exposes the full Montoya API as a local REST API, with Swagger UI

Full-stack AI security OS for your browser, terminal, and agents. Find, verify, and fix vulnerabilities. Prioritized by business impact instead of…

The one shot API attacker tool - finds the API url from the given root simulate the automated attacks

Modern WiFi auditing library for ESP32 using advanced 802.11 techniques. Captures WPA/WPA2/WPA3 handshakes via PMKID extraction and CSA injection…

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

ESP32DIV is a multi-purpose wireless offensive and defensive toolkit powered by an ESP32

Automatic SSTI detection tool with interactive interface

AI-assisted research pipeline that extracts HTTP desync techniques, generates malformed request test-cases, validates them via Burp, and confirms…

Web vulnerability scanner written in Python3

RCE detection and confirmation toolkit that tests URLs or captured HTTP requests for command injection, SSTI, blind and OOB paths, returning tiered…