
requests-ip-rotator
A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Focused web crawler that uses page classifiers and link prioritization to efficiently collect domain-specific or pattern-matching web pages, with…

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

Multi-proxy web interaction simulator for analyzing traffic behavior, access controls, and response patterns under varied network conditions.…

Python-based web crawler and SQL injection vulnerability scanner using dork queries. Supports proxy and automated scanning for security testing.

Comprehensive web application security testing platform featuring advanced scanning engine, intercepting proxy, and automated vulnerability detection…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

DNSChef (NG) - DNS proxy for Penetration Testers and Malware Analysts

API Scraper Agent for Web API's

Selenium powered Python script to automate searching for vulnerable web apps.

Mirror moved — see GitHub and Codeberg

Go-based tool that scans webpages and JavaScript files to discover hidden subdomains and secrets, with optional crawling and real-time proxy analysis…

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

Curated wordlists of API function names, verbs, and nouns for fuzzing web application endpoints with Burp Suite Intruder.

HTTP Proxy Analysis for reverse engineering protocol communication

Full-stack platform for authorized web application security scanning with a detector-based engine, async Celery workers, and a React dashboard for…

Python script to scan SharePoint hosts for CVE-2025-53770 using custom payloads, with optional Burp Suite proxy interception for traffic analysis and…