


A next-generation crawling and spidering framework.

AI-powered bug bounty hunting toolkit that works with or without subscription.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Web vulnerability scanner written in Python3

Simple JMX RMI scanning tool

The exploit server for out-of-band findings. Point a target at a domain you own. Every HTTP request and every email it sends back lands in a…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

A fast, keyboard-driven HTTP intercepting proxy and hacking & pentesting toolkit for the terminal.

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Native HTTP/HTTPS interception proxy for penetration testers and bug bounty hunters with live request tampering, request replay, high-speed fuzzing,…

Demonstrates an Insecure Direct Object Reference (IDOR) vulnerability in Deepfiction AI's chat API, allowing attackers to consume other users'…

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

SDK for querying the Intelligence X search engine and data archive, supporting selectors like email, domain, IP, and phone. Includes API wrappers in…

A fast, simple, recursive content discovery tool written in Rust.

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints