
afrog
A Security Tool for Bug Bounty, Pentest and Red Teaming.

A Security Tool for Bug Bounty, Pentest and Red Teaming.

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Next generation web scanner

Automatic SSTI detection tool with interactive interface

Web application penetration testing lab — vulnerable Flask app, automated scanner, and professional pentest report. Covers OWASP Top 10, SQLi, XSS,…

Multi-protocol port scanner with fingerprint recognition, service detection, and brute-force authentication testing. Supports 1200+ protocols, 10000+…

Automated SQL injection detection and exploitation tool for extracting database information from web applications, supporting multiple injection…

Automated penetration testing tool that sweeps IPs, scans ports and vulnerabilities, executes exploits, and provides an interactive shell with…

vulnx 🕷️ an intelligent Bot, Shell can achieve automatic injection, and help researchers detect security vulnerabilities CMS system. It can perform…

Automated penetration testing tool using Cyber Attack Techniques Scoring (CATS) to select and execute optimal attack scenarios via Metasploit, Nmap,…

A collection oneliner scripts for bug bounty

Bash script wrapping Active Directory tools for automated enumeration, vulnerability checks, exploitation, and password dumping via LDAP, RPC,…

Modular penetration testing framework integrating multiple tools for automated web application security assessment, aligned with OWASP Testing Guide,…

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

Shell-based CMS detection and exploit kit identifying 330+ content management systems, then launching automated security audits and exploitation…