
SSTImap
Automatic SSTI detection tool with interactive interface

Automatic SSTI detection tool with interactive interface

Automated API security testing tool that generates tests from OpenAPI specs, fuzzes inputs, and checks for OWASP API Top 10 vulnerabilities including…

Symbolic execution tool

A tool that is used to hunt vulnerabilities in x64 WDM drivers

Tool that reproduces CVE-2025-55315 in ASP.NET Core.

Bash-based fuzzing tool that leverages Google Dorking for stealthy enumeration of directories, files, subdomains, and parameters without direct…

Irregular methods on regular expressions

Black-box regex fuzzing tool that generates payloads to bypass input validations, discover normalizations, and evade WAFs in web applications.

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

Platform security assessment tool for dumping and analyzing UEFI/SMM registers, PCI config space, physical memory, SPI flash, and S3 bootscripts with…

🦚 A web-app pentesting suite written in rust .

Create your Custom Wordlist For Fuzzing

Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:

Software for fuzzing, used on web application pentestings.

General-purpose data compression library implementing the zlib, deflate, and gzip formats, with thread-safe functions and cross-platform build…

Domain-aware URL fuzzer that dynamically generates wordlists to discover exposed backup and sensitive files on web servers.

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

Automated web path fuzzing tool that detects hidden directories, files, and endpoints using intelligent language detection, blacklist/whitelist…