
SecLists
Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

A reverse engineering framework written in Python.

Directory/File, DNS and VHost busting tool written in Go

Vajra is a highly customizable target and scope based automated web hacking framework to automate boring recon tasks and same scans for multiple…

Automated differential fuzzing tool for cryptographic software that detects implementation errors, compliance failures, and side-channel leaks…

Scope-based reconnaissance automation framework that orchestrates multiple open-source tools for subdomain enumeration, vulnerability scanning, and…

MeowEye is a real-time scanner for identifying multiple web vulnerabilities in live applications.

Proof-of-concept exploit for CVE-2026-42945, a critical heap overflow in NGINX rewrite module enabling unauthenticated remote code execution via…

Scalable assembly analysis platform for indexing, clone search, and executable classification using static, dynamic, and machine-learning techniques…

XSS Fuzzer is a tool which generates XSS payloads based on user-defined vectors and fuzzing lists.

Tool to discover paths in web applications

A pure-python fully automated and unattended fuzzing framework.

Portable debugger-based crash triage tool for fuzzing outputs. Supports parallel triage, crash deduplication, sanitizer report parsing, and multiple…

Library and CLI for mutating structured data (JSON, XML, X.509) to support grammar-based fuzzing, with multiple mutation strategies and integration…

CAN Bus vehicle simulator for practicing offensive automotive security attacks. Emulates multiple ECUs to enable sniffing, injection, and…

Continuous fuzzing solution integrated into CI workflows to find vulnerabilities in code changes and batch runs, supporting multiple languages and CI…

Automated scanner for CVE-2021-44228 (Log4Shell) that tests single or multiple web targets for the vulnerability using remote callback servers.