
wpair-app
WPair is a defensive security research tool that demonstrates the CVE-2025-36911 (eg WhisperPair) vulnerability in Google's Fast Pair protocol. This…

WPair is a defensive security research tool that demonstrates the CVE-2025-36911 (eg WhisperPair) vulnerability in Google's Fast Pair protocol. This…

Offensive security platform that automates attack surface discovery and vulnerability management

Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

Automated white-hat vulnerability scanner that monitors HackerOne and Bugcrowd assets, performs subdomain enumeration, crawling, fingerprinting, and…

Automated scanner that hunts for secrets (API keys, credentials) accidentally uploaded to public S3 buckets, using truffleHog3 for detection and…

Domain-aware URL fuzzer that dynamically generates wordlists to discover exposed backup and sensitive files on web servers.

ReconPi - A lightweight recon tool that performs extensive scanning with the latest tools.

File-system scanner that detects vulnerable Log4J versions (CVE-2021-44228, CVE-2021-45046) by analyzing compiled Java classes, including nested…

HackBox is a powerful and comprehensive tool that combines a variety of techniques for web application and network security assessments, including…

Static and dynamic analysis tool that audits open-source packages for malicious, vulnerable, and risky attributes, with sandboxed installation to…

YAML-driven CLI scanner that detects exposed services, files, and folders on web endpoints. Designed for developers to integrate security checks into…

A tool for bug hunting or pentesting for targeting websites that have open .git repositories available in public

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

YARA-based scanner that detects obfuscated PHP malware and webshells using semantic pattern matching instead of file hashes, with a whitelist system…

BFAC (Backup File Artifacts Checker): An automated tool that checks for backup artifacts that may disclose the web-application's source code.

Grafana scanner with all public CVEs that I collected in one script to make grafana testing easier

SQLiPy is a Python plugin for Burp Suite that integrates SQLMap using the SQLMap API.

AI security agent that runs in your terminal, orchestrating local tools, runbooks, and agents for authorized AppSec, pentest, OSINT, and CTF…