
goWAPT
Go Web Application Penetration Test

Go Web Application Penetration Test

Serverless AWS solution for distributing recon and vulnerability scanning workloads. Submit tasks via web UI; EC2 workers execute custom Python…

Module-based web vulnerability scanner and bug bounty automation framework with built-in XSS, SSTI, SSRF, and Firebase detection engines. Designed to…

Web vulnerability scanner focused on automated XSS/CSP bypass payload testing and batch SQL injection detection, using SQLMap and reporting only…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Automated vulnerability scanner for CVE-2023-28121 that checks a list of targets concurrently and delivers results via Telegram notifications.

An asynchronous enumeration & vulnerability scanner. Run all the tools on all the hosts.

This script is used to perform a fast check if your server is possibly affected by CVE-2021-44228 (the log4j vulnerability).


This Pwsh script run AppScan Standard scans against a list of web sites (URLs.txt) checking for Log4J (CVE-2021-44228) vulnerability

Self-hosted multi-agent environment for Go with LLM-powered pentesting agents (exploiter, reverser, threathunter, webscanner) that automate…

Scrape/Parse Pastebin using GO and expression grammar (PEG)

Mitigate log4shell (CVE-2021-44228) vulnerability attacks using Nginx LUA script

A lightweight CLI tool for systematically detecting and exploiting race conditions in web applications, APIs, and modern services.

PowerShell script to test if a web app is vulnerable to CVE-2025-29927

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

AI-powered web scraping and data extraction library that extracts structured information from any webpage using natural language instructions, with…

Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesWeHack.