
WordList
Curated collection of custom wordlists for fuzzing, DNS enumeration, parameter discovery, and default credentials, plus a Go generator for nuclei…

Curated collection of custom wordlists for fuzzing, DNS enumeration, parameter discovery, and default credentials, plus a Go generator for nuclei…

Fast and easy-to-use directory brute-forcer written in Go.


Multi-phase reconnaissance and attack-surface scanner that maps domains, IPs, ASNs, cloud assets, and CVEs into a knowledge graph with CVSS scoring…

Make URL path combinations using a wordlist


Technology-aware web content discovery scanner: detects Wappalyzer fingerprints, adapts wordlists/extensions, and performs fast directory bruteforce…

Golang tool which helps dropping the irrelevant entries from your ffuf result file.

Automates web content discovery and directory bruteforcing with multithreaded ffuf execution, tech-aware wordlists, endpoint filtering, WAF…

A BASH Script to automate the installation of the most popular bug bounty tools

DotDotPwn - The Directory Traversal Fuzzer

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

Web application security scanner created by lcamtuf for google - Unofficial Mirror

Scanner for the Log4j vulnerability dubbed Log4Shell (CVE-2021-44228)

Automated defect verification tool for 6 dnsmasq CVEs (CVE-2026-2291, 4890, 4891, 4892, 4893, 5172)

Fuzzing the Microsoft Windows DNS client library. Inspired by CVE-2026-41096.

CVE-2026-5172: buffer overflow in extract_addresses() on crafted resource record PoC