
NucleiFuzzer
Automated web vulnerability scanner combining URL discovery tools (ParamSpider, waybackurls, gauplus, hakrawler, katana) with Nuclei fuzzing…

Automated web vulnerability scanner combining URL discovery tools (ParamSpider, waybackurls, gauplus, hakrawler, katana) with Nuclei fuzzing…

SIP Security Assessment Framework for VoIP Pentesters. Presented at DEFCON, BlackHat & Offzone.

Web application security scanner created by lcamtuf for google - Unofficial Mirror

Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist

Secure multithreaded packet sniffer

BurpSuite plugin for HTTP packet analysis and fuzzing dictionary generation. Extracts parameters, paths, and files from requests, counts frequency,…

DotDotPwn - The Directory Traversal Fuzzer

Fetch, install and search wordlist archives from websites and torrent peers.

Ronin is a Free and Open Source Ruby Toolkit for Security Research and Development. Ronin also allows for the rapid development and distribution of…

Domain-aware URL fuzzer that dynamically generates wordlists to discover exposed backup and sensitive files on web servers.

htcap is a web application scanner able to crawl single page application (SPA) recursively by intercepting ajax calls and DOM changes.

Fast HTTP enumerator

Tools for information gathering

Weaponizing WaybackUrls for Recon, BugBounties , OSINT, Sensitive Endpoints and what not

POC-T强化版本 POC-S , 用于红蓝对抗中快速验证Web应用漏洞, 对功能进行强化以及脚本进行分类添加,自带dnslog等, 平台补充来自vulhub靶机及其他开源项目的高可用POC

🔭 Lightweight URL fuzzer and spider: Discover a web server's undisclosed files, directories and VHOSTs

A multithreaded, very fast and smart HTTP(S) directory and file bruteforcer written in C on top of libcurl

Smart context-based SSRF vulnerability scanner.