
secret-regex-list
List of regex for scraping secret API keys and juicy information.

List of regex for scraping secret API keys and juicy information.

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

Offensive Docker is an image with the more used offensive tools to create an environment easily and quickly to launch assessment to the targets.

Ronin is a Free and Open Source Ruby Toolkit for Security Research and Development. Ronin also allows for the rapid development and distribution of…

Web Application Security Automation Framework which recons the target for various assets to maximize the attack surface for security professionals &…

A tool for logging data/testing devices with a Wiegand Interface. Can be used to create a portable RFID reader or installed directly into an existing…

Local-first AI red team for web, API, and LLM application security. Attacker-style reasoning, evidence-backed findings, and skills for AI coding…

Porch Pirate is the most comprehensive Postman recon / OSINT client and framework that facilitates the automated discovery and exploitation of API…

Turn any web app into an API. Chrome extension captures browser traffic, auto-generates schemas, lets AI replay APIs directly. No official API needed.

Automated web path fuzzing tool that detects hidden directories, files, and endpoints using intelligent language detection, blacklist/whitelist…

Curated collection of wordlists for bug bounty hunting, covering directories, subdomains, parameters, usernames, passwords, and web fuzzing payloads.

POC-T强化版本 POC-S , 用于红蓝对抗中快速验证Web应用漏洞, 对功能进行强化以及脚本进行分类添加,自带dnslog等, 平台补充来自vulhub靶机及其他开源项目的高可用POC

Poor (rich?) man's bug bounty pipeline https://dubell.io

A multithreaded, very fast and smart HTTP(S) directory and file bruteforcer written in C on top of libcurl

Create your Custom Wordlist For Fuzzing

Automated web domain reconnaissance and security assessment tool integrating subdomain enumeration, port scanning, vulnerability scanning, and…

CANToolz - Black-box CAN network analysis framework

🦚 A web-app pentesting suite written in rust .