
nuclei
Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast YAML-based vulnerability scanner with template-driven detection engine for automated security testing across web apps, APIs, networks, DNS, and…

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

GyoiThon is a growing penetration test tool using Machine Learning.

GraphQL automated security testing toolkit

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

Panthera(P.)uncia - Official CLI utility for Subdomain Center & Exploit Observer.

Tests your WAF with +160 payloads

API-first subdomain discovery service using Certificate Transparency logs for fast, passive enumeration of subdomains via a REST API with JSON or…

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines,…

All in one tool for Information Gathering, Vulnerability Scanning and Crawling. A must have tool for all penetration testers

A high-speed tool for passively gathering URLs, optimized for efficient and comprehensive web asset discovery without active scanning.

⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)

Generates domain name permutations for subdomain enumeration and recon, supporting custom wordlists, cloud patterns, and fast mode for security…