
Nest
Your gateway to OWASP. Discover, engage, and help shape the future!

Your gateway to OWASP. Discover, engage, and help shape the future!

SIP Security Assessment Framework for VoIP Pentesters. Presented at DEFCON, BlackHat & Offzone.

Burp Suite extension for JavaScript static analysis: extracts API endpoints, URLs, secrets, and emails with noise filtering for web security testing.

A DNS reconnaissance tool for locating non-contiguous IP space.

Production-grade MCP server giving Claude 27 security intelligence tools across 21 APIs — CVE lookup, EPSS scoring, CISA KEV, MITRE ATT&CK, Shodan,…

OWASP Web Recon & Directory Discovery Platform

Web application security scanner created by lcamtuf for google - Unofficial Mirror

MassDNS wrapper written in go to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard filtering and easy…

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files…

A Penetration Testing Framework, Information gathering tool & Website Vulnerability Scanner

Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist

Bash-based fuzzing tool that leverages Google Dorking for stealthy enumeration of directories, files, subdomains, and parameters without direct…

Subdomain enumeration tool, asynchronous dns packets, use pcap to scan 1600,000 subdomains in 1 second

BurpSuite plugin for HTTP packet analysis and fuzzing dictionary generation. Extracts parameters, paths, and files from requests, counts frequency,…

Set of tools to audit SIP based VoIP Systems

Curated collection of bug bounty tips, one-liners, and automation workflows for recon, fuzzing, and web exploitation, with private nuclei templates…

PenBox - A Penetration Testing Framework - The Tool With All The Tools , The Hacker's Repo