
ReconHound
ReconHound is a Python-based web reconnaissance tool designed for penetration testers, bug bounty hunters, and ethical hackers. It supports directory…

ReconHound is a Python-based web reconnaissance tool designed for penetration testers, bug bounty hunters, and ethical hackers. It supports directory…

Modular web fuzzer for automated security testing. Injects payloads into any HTTP request field to discover vulnerabilities, brute-force parameters,…

WiFi Penetration Testing & Auditing Tool

Java-based framework for systematic fuzzing and analysis of TLS libraries. Enables arbitrary protocol message crafting, modification, and testing of…

WS-Attacker is a modular framework for web services penetration testing. It is developed by the Chair of Network and Data Security, Ruhr University…

Go Web Application Penetration Test

Modular WAF bypass fuzzer with multi-threading, request manipulation, and payload encoding for red team web application testing.

PolarDNS is a specialized authoritative DNS server suitable for penetration testing and vulnerability research.


Fuzz testing framework for network protocols.

Chrome extension for fast web fuzzing to discover hidden files and directories during penetration testing and vulnerability analysis.

CRLFISCANNER is a lightweight and powerful CLI tool designed for bug bounty hunters and penetration testers to automatically detect CRLF injection…

Testing resources and attacker tool for CVE-2023-44487 (HTTP/2 Rapid Reset) to evaluate server resilience across Go, gRPC, reverse proxy, and nginx…

Go-based exploit tool for CVE-2026-42945 (nginx HTTP/2) with detection, crash probing, command execution, and reverse shell capabilities for…

SCADA Security Testing tool

WAFNinja is a tool which contains two functions to attack Web Application Firewalls.

Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:

Software for fuzzing, used on web application pentestings.