
firefly
High-performance black-box fuzzer for web applications with built-in payload engine, request verification, tampering, encoding, and advanced…

High-performance black-box fuzzer for web applications with built-in payload engine, request verification, tampering, encoding, and advanced…

An automatic XSS discovery tool

Advanced Time-based Blind SQL Injection fuzzer for HTTP Headers

User-Agent , X-Forwarded-For and Referer SQLI Fuzzer

Multi-threaded web fuzzer for URL path, HTTP header, and POST data brute-forcing with proxy support, status code filtering, and reflexive content…

Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:

Software for fuzzing, used on web application pentestings.

SSRFuzz is a tool to find Server Side Request Forgery vulnerabilities, with CRLF chaining capabilities

Multi-threaded Go tool to detect nginx alias traversal vulnerabilities using heuristic and brute-force techniques for identifying vulnerable…

Nuclei template to detect Apache servers vulnerable to CVE-2024-38473

CRLFMap is a tool to find HTTP Splitting vulnerabilities

exploit CVE-2024-40725 (Apache httpd) with

Mass exploiter for CVE-2020-5902 targeting F5 Big-IP devices, with multi-threaded scanning and exploitation capabilities for unauthenticated remote…

Gryffin is a large scale web security scanning platform.

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

Evidence-oriented DAST scanner in Go that crawls web apps and APIs, then runs adaptive SQLi, XSS, RCE, SSRF, and auth checks with replayable proof.

A high performance offensive security tool for reconnaissance and vulnerability scanning

Autonomous security research framework integrating static analysis, binary analysis, fuzzing, LLM-powered vulnerability validation, exploit…