
godirb
Fast and easy-to-use directory brute-forcer written in Go.

Fast and easy-to-use directory brute-forcer written in Go.

Technology-aware web content discovery scanner: detects Wappalyzer fingerprints, adapts wordlists/extensions, and performs fast directory bruteforce…

A Ruby library and CLI for generating and working with wordlists.

1337 Wordlists for Bug Bounty Hunting


Modular wordlist generation, editing, analysis, and discovery toolkit for password cracking, fuzzing, and ethical security testing. Supports…

An extremely fast and flexible web fuzzer

Modular web fuzzer for automated security testing. Injects payloads into any HTTP request field to discover vulnerabilities, brute-force parameters,…

Brute-force tool for discovering hidden GET and POST parameters in web applications, supporting custom wordlists and concurrent requests.


Super Simple Python Word List Generator for Fuzzing and Brute Forcing in Python

RMIScout uses wordlist and bruteforce strategies to enumerate Java RMI functions and exploit RMI parameter unmarshalling vulnerabilities

Powerful mutable web directory fuzzer to bruteforce existing and/or hidden files or directories.

Software for fuzzing, used on web application pentestings.

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab: