
reconix
Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Next generation web scanner

Open-source AI pentester that proves every finding. Machine oracles re-run each exploit; verified bugs ship a proof capsule you can replay yourself.

Go client to communicate with Chaos DB API.

SDK for querying the Intelligence X search engine and data archive, supporting selectors like email, domain, IP, and phone. Includes API wrappers in…

RESTful API wrapping Nmap for automated network scanning, port detection, service enumeration, and vulnerability analysis with optional AI-powered…

Scans public code repositories and code snippet platforms to extract and validate AI service API keys with real-time dashboard and multi-format…

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

API-first subdomain discovery service using Certificate Transparency logs for fast, passive enumeration of subdomains via a REST API with JSON or…

Burp Suite extension to discover assets from HTTP response.

Burp Suite extension for extracting metadata from files

A tool that transforms Firefox browsers into a penetration testing suite