

AI-powered bug bounty hunting toolkit that works with or without subscription.

Real-world infosec wordlists, updated regularly

The most exhaustive list of reliable DNS resolvers.

Fast and customizable subdomain wordlist generator using DSL

dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Fast passive subdomain enumeration tool.

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

🕵️♂️ Collect a dossier on a person by username from 6K websites

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

🕵️♂️ All-in-one OSINT tool for analysing any website

Panthera(P.)uncia - Official CLI utility for Subdomain Center & Exploit Observer.

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

Passive DNS server that detects exposed cloud storage buckets (AWS S3, GCP, Azure) by resolving DNS requests, tracing CNAME chains, and flagging…

Terminal-first attack surface intelligence engine. Built for speed, portability, and raw technical signal.

A Modern Orchestration Engine for Security