
zaproxy
Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

Successor of Undetected-Chromedriver. Providing a blazing fast framework for web automation, webscraping, bots and any other creative ideas which are…

Rogue Access Point framework for red team engagements and Wi-Fi security testing. Performs Evil Twin, KARMA, and Known Beacons attacks to achieve…

All-in-One Hacking Tools For Hackers! And more hacking tools! For termux.

Generate malicious PDF test files for penetration testing, bug bounty hunting, and red teaming. Tests SSRF, XSS, XXE, NTLM credential theft, and data…

macro_pack is a tool by @EmericNasi used to automatize obfuscation and generation of Office documents, VB scripts, shortcuts, and other formats for…

evilginx3 + gophish

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

crawls the website and finds broken social media links that can be hijacked

Azure JWT Token Manipulation Toolset

Weaponized Browser-in-the-Middle (BitM) for Penetration Testers

Proof-of-concept to demonstrate dynamic QR swap phishing attacks in practice.

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID

MCP server for Google search and page fetching using headless Chromium

This script can be used to gain access to a victim's Samsung Account if they have a specific version of Samsung Members installed on their Samsung…

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

a CLI for ephemeral penetration testing