
Raccoon
A high performance offensive security tool for reconnaissance and vulnerability scanning

A high performance offensive security tool for reconnaissance and vulnerability scanning

Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

Brute-force tool for discovering hidden GET and POST parameters in web applications, supporting custom wordlists and concurrent requests.

Multi-threaded web reconnaissance tool for directory/file enumeration, subdomain discovery, virtual host detection, and parameter fuzzing, designed…

Automated CRLF and open redirect injection scanner that fuzzes URL parameters with payloads to detect HTTP header injection and redirect…

Go-based exploit tool for Vite dev server arbitrary file read vulnerabilities (CVE-2025-30208, CVE-2025-31125, CVE-2025-31486) with fofa integration…

Automated web path fuzzing tool that detects hidden directories, files, and endpoints using intelligent language detection, blacklist/whitelist…

SIP Security Assessment Framework for VoIP Pentesters. Presented at DEFCON, BlackHat & Offzone.

Different utility scripts for pentesting and hacking.

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

Create your Custom Wordlist For Fuzzing

Fast directory and file brute-forcing tool written in Rust, using wordlists to discover hidden web resources with customizable HTTP headers, cookies,…

Automated web vulnerability scanner combining URL discovery tools (ParamSpider, waybackurls, gauplus, hakrawler, katana) with Nuclei fuzzing…

Fuzz a list of domains for specific endpoints

File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.

Domain-aware URL fuzzer that dynamically generates wordlists to discover exposed backup and sensitive files on web servers.

Golang tool which helps dropping the irrelevant entries from your ffuf result file.

Tool to discover paths in web applications