
wordlists
Real-world infosec wordlists, updated regularly

Real-world infosec wordlists, updated regularly

AI-powered bug bounty hunting toolkit that works with or without subscription.

Fast and customizable subdomain wordlist generator using DSL

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

🕵️♂️ Collect a dossier on a person by username from 6K websites

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

🕵️♂️ All-in-one OSINT tool for analysing any website

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…


Terminal-first attack surface intelligence engine. Built for speed, portability, and raw technical signal.

A Modern Orchestration Engine for Security

NetLogic is an advanced network analysis and cybersecurity toolkit for traffic inspection, packet analysis, and threat detection

a passive OSINT toolkit in python usernames, emails, domains, ips, phones, hashes. no keys, no logins.

a passive OSINT toolkit in python - usernames, emails, domains, ips, phones, hashes. no keys, no logins.

Domain OSINT and security reconnaissance framework running 26 parallel modules for DNS, ports, subdomains, leaked credentials, exposed endpoints,…

Bash-based passive reconnaissance + attack surface mapping script using only public APIs + stock Linux tools (curl, dig, openssl, nmap, python3).