
ParamPamPam
Brute-force tool for discovering hidden GET and POST parameters in web applications, supporting custom wordlists and concurrent requests.

Brute-force tool for discovering hidden GET and POST parameters in web applications, supporting custom wordlists and concurrent requests.

🦚 A web-app pentesting suite written in rust .

Automated web path fuzzing tool that detects hidden directories, files, and endpoints using intelligent language detection, blacklist/whitelist…

Technology-aware web content discovery scanner: detects Wappalyzer fingerprints, adapts wordlists/extensions, and performs fast directory bruteforce…

Create your Custom Wordlist For Fuzzing

Powerful mutable web directory fuzzer to bruteforce existing and/or hidden files or directories.

A BurpSuite extension to create a custom word-list of endpoint and parameters for enumeration and fuzzing

An extremely fast and flexible web fuzzer

PolarDNS is a specialized authoritative DNS server suitable for penetration testing and vulnerability research.


Golang tool which helps dropping the irrelevant entries from your ffuf result file.

Automates web content discovery and directory bruteforcing with multithreaded ffuf execution, tech-aware wordlists, endpoint filtering, WAF…

Generates target specific word lists for Fuzzing with fuff


windows api bug

Different utility scripts for pentesting and hacking.

A BASH Script to automate the installation of the most popular bug bounty tools
