
shannon
Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

OWASP D4N155 - Intelligent and dynamic wordlist using OSINT

⚡️ Multiple target ZAP Scanning

Penetration tests guide based on OWASP including test cases, resources and examples.

Automated Security Testing For REST API's

Burp Suite plugin for generating and executing Nuclei vulnerability templates directly from HTTP requests and responses, with YAML auto-complete and…

SSRF plugin for burp Automates SSRF Detection in all of the Request

The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Automated tool to probe for mass assignment vulnerabilities by extracting parameters from one HTTP request and applying them to another, with support…

Zap Extension for collaboration in Faraday

A collection of hacking / penetration testing resources to make you better!

In-depth attack surface mapping and asset discovery

Intentionally vulnerable web application covering OWASP Top 10 vulnerabilities for security training, CTF competitions, and penetration testing…

Comprehensive OWASP guide for mobile app security testing, reverse engineering, and verifying MASVS/MASWE weaknesses through static, dynamic, and…

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.