
fastfuz-chrome-ext
Chrome extension for fast web fuzzing to discover hidden files and directories during penetration testing and vulnerability analysis.

Chrome extension for fast web fuzzing to discover hidden files and directories during penetration testing and vulnerability analysis.


Multi-threaded web fuzzer for URL path, HTTP header, and POST data brute-forcing with proxy support, status code filtering, and reflexive content…

Application for capturing, modifying and sending custom WebSocket data from client to server and vice versa.

Tools for auditing WAFS

A structure-aware JSON fuzzer

Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:


Proof-of-concept exploit for CVE-2017-9096 demonstrating XML External Entity (XXE) injection in iText PDF library via malicious XMP metadata and form…

Security analysis toolkit for proprietary car protocols

Smart ssrf scanner using different methods like parameter brute forcing in post and get...

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

A fork and successor of the Sulley Fuzzing Framework

A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.

Remote proof-of-concept for CVE-2022-0778 that injects a crafted certificate into a TLS handshake to trigger the OpenSSL BN_mod_sqrt()…

A multi-platform fuzzer for poking at userland binaries, network clients and servers

Find zero-days while you sleep. DeepZero is an automated vulnerability research framework that parses, decompiles, and analyzes thousands of Windows…