
SecLists
Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…

Web vulnerability scanner written in Python3

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

A collection of custom security tools for quick needs.

Curated collection of custom wordlists for fuzzing, DNS enumeration, parameter discovery, and default credentials, plus a Go generator for nuclei…

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2,…

Manual black-box penetration test of MagnoHost and MeteorCloud infrastructure, documenting exposed MariaDB, default credentials, CVE-2024-27102, and…

NOT for educational purposes: An MCP server for professional penetration testers including STDIO/HTTP/SSE support, nmap, go/dirbuster, nikto, JtR,…

This program Prompts you for the Local File Inclusion information and will automatically search the /etc/passwd and using the users names found will…

A Ruby library and CLI for generating and working with wordlists.

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

GraphQL penetration testing tool that exploits weak rate limits and cost analysis to brute-force credentials, bypass 2FA, enumerate users, and fuzz…

Alibab-Nacos-Unauthorized-Reset PWD

The Offensive Manual Web Application Penetration Testing Framework.

Burpsuite Plugin For AES Crack

NebulousAD automated credential auditing tool.