
AISA-Scanner
AISA-Scanner is an AI-powered autonomous vulnerability scanner that maps CVEs to metasploit exploits, MITRE, CEH, and SANS, delivering intelligent,…

AISA-Scanner is an AI-powered autonomous vulnerability scanner that maps CVEs to metasploit exploits, MITRE, CEH, and SANS, delivering intelligent,…

Curated collection of wordlists for bug bounty hunting, covering directories, subdomains, parameters, usernames, passwords, and web fuzzing payloads.

Modern tactical exploitation toolkit.


OSINT tool that finds domains, subdomains, directories, endpoints and files for a given seed URL.

CF-Hero is a reconnaissance tool that uses multiple data sources to discover the origin IP addresses of Cloudflare-protected web applications

A collection of scripts for assessing Microsoft Azure security

Stuff that doesn't deserves its own repository.

Poor (rich?) man's bug bounty pipeline https://dubell.io

Fast passive subdomain enumeration tool.

Passive DNS server that detects exposed cloud storage buckets (AWS S3, GCP, Azure) by resolving DNS requests, tracing CNAME chains, and flagging…

Curated list of OSINT tools for offensive security, covering email harvesting, subdomain enumeration, threat intelligence, and social engineering for…

Extract subdomains from SSL certificates in HTTPS sites.

A modular distributed penetration testing tool.

Search for information related to domain: Emails - IP addresses - Sub-Domains - Information on WEB technology - Type of Firewall - NS and MX records.

Some tools to automate recon - 003random

HackBox is a powerful and comprehensive tool that combines a variety of techniques for web application and network security assessments, including…

Takeover script extracts CNAME record of all subdomains at once. TakeOver saves researcher time and increase the chance of finding subdomain takeover…