


Finds internet-exposed resources in an AWS account

Runtime-aware SCA — proves which CVEs are actually reachable, not just installed.

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…

Burp Suite extension that finds exposed admin panels and login pages of web applications and infrastructure. 1,000+ payloads, OWASP WSTG-CONF-05.

Web application penetration testing lab — vulnerable Flask app, automated scanner, and professional pentest report. Covers OWASP Top 10, SQLi, XSS,…

OWASP Domain Protect - prevent subdomain takeover

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

End to End testing of Web, API, Cloud, Events and Security

CLI component of purpleteam

Application scanning component of purpleteam

Server scanning component of purpleteam

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

Next generation web scanner

AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…

Nightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes…

AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)