
checkov
Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

Static analysis tool for infrastructure as code that detects cloud misconfigurations, vulnerabilities, and secrets across Terraform, Kubernetes,…

A powerful open-source tool for managing networks and troubleshooting network problems!

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

Automated All-in-One OS Command Injection Exploitation Tool

A Security Tool for Bug Bounty, Pentest and Red Teaming.

A high performance offensive security tool for reconnaissance and vulnerability scanning

Multi-cloud security auditing tool that leverages cloud provider APIs to gather configuration data, assess security posture, and generate HTML…

All in one tool for Information Gathering, Vulnerability Scanning and Crawling. A must have tool for all penetration testers

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive…

Active Directory security risk assessment tool that evaluates vulnerabilities, misconfigurations, and maturity using a streamlined methodology,…

the fastest and most powerful android decompiler(native tool working without Java VM) for the APK, DEX, ODEX, OAT, JAR, AAR, and CLASS file. which…

网络摄像头漏洞扫描工具 | Webcam vulnerability scanning tool

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

Autonomous AI red team agent for penetration testing with 13+ specialized agents, 120+ OWASP test cases, and MITRE ATT&CK integration. Supports 15+…

Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.

Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure.

Server-Side Template Injection and Code Injection Detection and Exploitation Tool