
SSTImap
Automatic SSTI detection tool with interactive interface

Automatic SSTI detection tool with interactive interface

FGscanner is an advanced, opensource URL scanner.

BurpSuite plugin for encrypting payloads with AES, RSA, DES, or custom JS code, enabling automated decryption of front-end encrypted traffic during…

Zip file format fuzzer and multi-tool.

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

SIP Security Assessment Framework for VoIP Pentesters. Presented at DEFCON, BlackHat & Offzone.

Binary visualiser and triage tool — entropy, byte-class and Hilbert surfaces, dot plots and control-flow graphs over one shared address-space model.

An LLVM-based instrumentation tool for universal taint tracking, dataflow analysis, and tracing.


Some bugs found via binary instrumentation and fuzzing

IEEE 802.11 Wi-Fi testing tool for protocol weakness exploitation, including beacon flooding, deauthentication, packet fuzzing, and IDS evasion.…


PenBox - A Penetration Testing Framework - The Tool With All The Tools , The Hacker's Repo

C library implementing the SSH protocol for secure remote access, authentication, and encrypted communication. Includes fuzzing support via OSS-Fuzz…

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

dtls-fuzzer is a protocol-state-fuzzer for DTLS server implementations.