


Collaborative pentest tool with highly customizable tools

Extract subdomains from SSL certificates in HTTPS sites.

🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.


Tests hundreds of URL bypass techniques against 40X protected pages using raw curl requests, with multi-mode scanning, header spoofing, and JSON/HTML…

Modern alternative to dirbuster/dirb

Active Directory data ingestor for BloodHound Legacy written in Rust. 🦀

Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.

Opensource, cross-platform and portable toolkit for automating routine processes when carrying out various works for testing!

An automated e-mail OSINT tool

Bash script wrapping Active Directory tools for automated enumeration, vulnerability checks, exploitation, and password dumping via LDAP, RPC,…

Jok3r v3 BETA 2 - Network and Web Pentest Automation Framework

🕵️ Python project to crawl for JavaScript files and search for secrets like API keys, authorization tokens, hardcoded credentials, etc.

🦁 Python project to identify and scan for vulnerabilities related to the Joomla CMS project. It scans for common misconfigurations and public…

A fast enumeration tool for publicly exposed Azure Storage blobs.

Jok3r - Network and Web Pentest Framework