
Arjun
HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

HTTP parameter discovery tool that finds valid query parameters for URL endpoints using a large dictionary, supporting GET/POST/JSON/XML requests,…

Web vulnerability scanner written in Python3

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

High-speed API and web content discovery tool that bruteforces routes using compiled Swagger datasets, supporting depth scanning, custom wordlists,…

A fast WordPress plugin enumeration tool

CVE-2026-9830 Proof of Concept

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

Academic purposes only. Attack against Salesforce lightning with guest privilege.

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Automated WAF assessment tool that detects firewall vendors, tests 19 attack categories with advanced evasion payloads, and provides color-coded…

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

A comprehensive web application security testing toolkit that combines 10 powerful penetration testing features into one tool.

MAPS cloud scanner and response parser for Microsoft Defender research.

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

find sensitive data leaking from ServiceNow instances.

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…