
Routeglass
Multi-threaded router fingerprinting tool that identifies web-exposed network devices by analyzing HTTP responses, headers, and favicon hashes for…

Multi-threaded router fingerprinting tool that identifies web-exposed network devices by analyzing HTTP responses, headers, and favicon hashes for…

Async HTTP(S) scanner that greps response bodies and headers for strings or regex across hosts, ports, CIDR/ranges and TLS-cert vhosts.

Extract subdomains from SSL certificates in HTTPS sites.

Agent-based tool that collects OS, hardware, file, and hook data from internet-connected sandboxes via HTTPS exfiltration, aiding Red Team artifact…

Open source pre-operation C2 server based on python and powershell

Take a list of domains and probe for working HTTP and HTTPS servers

Let's find someone's account

Abusing Certificate Transparency logs for getting HTTPS websites subdomains.

19 Customizable honeypots for monitoring network traffic, bots activities and username\password credentials (DNS, HTTP Proxy, HTTP, HTTPS, SSH, POP3,…

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP…

A multithreaded, very fast and smart HTTP(S) directory and file bruteforcer written in C on top of libcurl

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

CVE-2012-1823 exploit for https user password website.

SKYWORTH GN542VF Hardware Version 2.0 and Software Version 2.0.0.16 does not set the Secure flag for the session cookie in an HTTPS session

Lockphish it's the first tool (07/04/2020) for phishing attacks on the lock screen, designed to grab Windows credentials, Android PIN and iPhone…

Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

A Powerful Sensor Tool to discover login panels, and POST Form SQLi Scanning

Searching for virtual hosts among non-resolvable domains