
SubGPT
Find subdomains with GPT, for free

Curated framework of free OSINT tools and resources for gathering intelligence from public sources, organized by category with structured metadata…

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Automated reconnaissance and XSS detection framework integrating subfinder, httpx, katana, gospider, waybackurls, and dalfox into a 9-stage pipeline…

CVE-2025-55182 (React2Shell) Scanner

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

:new: The Multi-Tool Web Vulnerability Scanner.

A Modern Orchestration Engine for Security

The recursive internet scanner for hackers. 🧡

Generates domain name permutations for subdomain enumeration and recon, supporting custom wordlists, cloud patterns, and fast mode for security…

HackBox is a powerful and comprehensive tool that combines a variety of techniques for web application and network security assessments, including…

Web Application Security Automation Framework which recons the target for various assets to maximize the attack surface for security professionals &…

A streamlined tool for discovering private TLDs for security research.

TugaRecon is an advanced subdomain reconnaissance and intelligence framework built for security researchers, penetration testers and OSINT…

Multi-language scanner for CVE-2025-55182 RCE in Next.js React Server Components, with single/mass scanning modes and integrated bug bounty…

Detects subdomain takeover vulnerabilities by analyzing DNS records and HTTP responses. Automatically identifies takeover-prone subdomains for…

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines,…

All in one tool for Information Gathering, Vulnerability Scanning and Crawling. A must have tool for all penetration testers