
jsubfinder
Go-based tool that scans webpages and JavaScript files to discover hidden subdomains and secrets, with optional crawling and real-time proxy analysis…

Go-based tool that scans webpages and JavaScript files to discover hidden subdomains and secrets, with optional crawling and real-time proxy analysis…

Open-source security research tool for identifying origin IP exposure of websites protected by Cloudflare and similar reverse proxy services.

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全…

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

Fast, multi-probe HTTP toolkit for reconnaissance and information gathering. Probes TLS, CSP, headers, tech stack, and CDN. Supports matchers,…

Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management

Tests your WAF with +160 payloads

A Multi-Processing Tool for collecting and extracting information to an Excel file from a Burp Suite output file.

AI-powered bug bounty hunting toolkit that works with or without subscription.


GraphQL automated security testing toolkit