
DomainDouche
OSINT tool abusing SecurityTrails domain suggestion API to find potentially related domains by keyword and brute force.

OSINT tool abusing SecurityTrails domain suggestion API to find potentially related domains by keyword and brute force.

This tool can be used to brute discover GET and POST parameters

Knock Subdomain Scan

🕷️ A `.git` folder exploiting tool that is able to restore the entire Git repository, including stash, common branches and common tags.

Modern tactical exploitation toolkit.

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Turns any junk text into a usable wordlist for brute-forcing.

User enumeration and password bruteforce on Azure, ADFS, OWA, O365, Teams and gather emails on Linkedin

POC of SecureWorks' recent Azure Active Directory password brute-forcing vuln

Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

User Enumeration vulnerability in Kaiten (workflow management system)

This tool uses a combination of dictionary-based wordlists (brute-force) and DNS resolution checks to verify the existence of subdomains.

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

wide range mass audit toolkit

Probe and discover HTTP pathname using brute-force methodology and filtered by specific word or 2 words at once

A threaded, recursive, web directory brute-force scanner over HTTP/2.

Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment