
wordlistctl
Fetch, install and search wordlist archives from websites and torrent peers.

Fetch, install and search wordlist archives from websites and torrent peers.

Modular fuzzing framework with a DSL (HierarFlow) to compose fuzzing loops from reusable primitives. Supports AFL, libFuzzer, VUzzer, and more for…

Golang tool which helps dropping the irrelevant entries from your ffuf result file.

Static binary instrumentation tool that dumps COFF object files from executables, enabling code/data insertion at any location for black-box fuzzing…

一个轻量级浏览器抓包与安全分析扩展,在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。(A lightweight browser extension for traffic capture and security analysis, enabling…

Automated reasoning tool based on the SMACK verifier that detects SGX enclave bugs from trusted boundary violations, including invalid pointer…

GromHacks Labs -- The payload lists they don't want you to have. 1,324 injection probes beamed down from the mothership to detect what's injectable…

A PoC to trigger CVE-2023-5217 from the Browser WebCodecs or MediaRecorder interface.

Experimenting with CVE-2022-20120 (Pixel Bootloader / ABL) using Unicorn, derived from eShard's emulator at…

Python API security testing tool from OpenStack Security Group

A wordlist framework to fullfill your kinks with your wordlists. For security researchers, bug bounty and hackers.


A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

IEEE 802.11 Wi-Fi testing tool for protocol weakness exploitation, including beacon flooding, deauthentication, packet fuzzing, and IDS evasion.…

An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.

Proof of Concept of ESP32/8266 Wi-Fi vulnerabilties (CVE-2019-12586, CVE-2019-12587, CVE-2019-12588)

Fast HTTP enumerator

Template-driven binary format fuzzer that generates and parses valid test inputs at high speed, with AFL++ integration for coverage-guided fuzzing.