

DotDotPwn - The Directory Traversal Fuzzer

🔭 Lightweight URL fuzzer and spider: Discover a web server's undisclosed files, directories and VHOSTs

An extremely fast and flexible web fuzzer

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…


Domain-aware URL fuzzer that dynamically generates wordlists to discover exposed backup and sensitive files on web servers.

Fast HTTP enumerator

A Comprehensive Web Fuzzer and Content Discovery Tool

Powerful mutable web directory fuzzer to bruteforce existing and/or hidden files or directories.

CRLF and open redirect fuzzer


A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

Automated reconnaissance framework with 17+ modules for subdomain enumeration, directory brute-forcing, JS/link mining, WAF fingerprinting, and…

Weaponizing WaybackUrls for Recon, BugBounties , OSINT, Sensitive Endpoints and what not

A Holistic OSINT and Threat Hunting Platform

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…