
CRSprober
Remote detection tool for OWASP Core Rule Set version and paranoia level on ModSecurity WAFs, aiding security posture assessment.

Remote detection tool for OWASP Core Rule Set version and paranoia level on ModSecurity WAFs, aiding security posture assessment.

A Security Tool for Enumerating WebSockets

Automated security testing tool for Salesforce Experience Cloud that discovers misconfigured Aura applications, accessible records, and unauthorized…

Automated GraphQL schema enumeration and data extraction tool that iterates introspection documents, reconstructs queries, and saves responses for…

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Comprehensive vulnerability detection tool for n8n workflow automation instances. Detects the critical CVE-2026-21858 vulnerability (CVSS 10.0)…

OWASP D4N155 - Intelligent and dynamic wordlist using OSINT

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

High-performance network scanner for large-scale IP and port scanning with service identification, embedded device detection, and vulnerability…

MAPS cloud scanner and response parser for Microsoft Defender research.

WordPress security scanner with AI-powered analysis, ethical compliance framework, and professional reporting.

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

WEB SERVICE SECURITY ASSESSMENT TOOL

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

A fast WordPress plugin enumeration tool

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice