
nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

Ashok is a OSINT Recon Tool , a.k.a 😍 Swiss Army knife .

E-mails, subdomains and names Harvester - OSINT

Fast subdomains enumeration tool for penetration testers

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines,…

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

All in one tool for Information Gathering, Vulnerability Scanning and Crawling. A must have tool for all penetration testers

Concurrent DNS takeover scanner detecting CNAME, NS, AXFR, SPF, MX, SRV, and stale A record vulnerabilities across cloud providers, with multi-level…

The Offensive Manual Web Application Penetration Testing Framework.


Curated list of OSINT tools for offensive security, covering email harvesting, subdomain enumeration, threat intelligence, and social engineering for…

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)

A Powerful Subdomain Takeover Tool

A high-speed tool for passively gathering URLs, optimized for efficient and comprehensive web asset discovery without active scanning.

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).