
SubGPT
Find subdomains with GPT, for free

Curated framework of free OSINT tools and resources for gathering intelligence from public sources, organized by category with structured metadata…

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are…

CVE-2025-55182 (React2Shell) Scanner

Red team Arsenal - An intelligent scanner to detect security vulnerabilities in company's layer 7 assets.

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

Automated reconnaissance and XSS detection framework integrating subfinder, httpx, katana, gospider, waybackurls, and dalfox into a 9-stage pipeline…

High-performance network discovery and security auditing tool with advanced port scanning, OS detection, service version detection, and scriptable…

:new: The Multi-Tool Web Vulnerability Scanner.

The recursive internet scanner for hackers. 🧡

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

A Modern Orchestration Engine for Security

A high performance offensive security tool for reconnaissance and vulnerability scanning

CPH:SEC WAES: Web Auto Enum & Scanner - Auto enums website(s) and dumps files as result

Fast, accurate subdomain takeover scanner with zero false positives. Detects vulnerable subdomains, collects metadata (IP, CNAME, title, status…

Secure, modular MCP server wrapping nmap, nuclei, gobuster, subfinder, httpx, nikto, sqlmap for AI-powered pentesting

An asynchronous enumeration & vulnerability scanner. Run all the tools on all the hosts.

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…