
akto
Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

Open-source API security platform for continuous API discovery, vulnerability testing, and runtime threat detection. Integrates with CI/CD pipelines…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Web technology identification scanner with 1800+ plugins for detecting CMS, servers, JS libraries, and embedded devices. Supports stealthy to…

Perl-based web server scanner that performs comprehensive vulnerability checks, CGI scanning, and server fingerprinting with customizable plugins and…

Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Multi-architecture Docker toolkit for penetration testing with preconfigured tools for web, network, mobile, API, OSINT, and forensics. Features…

Docker container for CVE-2017-10271 (Oracle WebLogic RCE) used with Cved framework to manage and deploy vulnerable environments for security testing…

Docker container for CVE-2015-8103 exploitation targeting JBoss, part of a vulnerable container management framework for security testing.

Docker container providing a pre-configured vulnerable environment for CVE-2017-1000486, designed for security testing and exploit practice within…

Semi-automated network penetration testing framework with integrated NMAP, Hydra, Nikto, and CVE-to-exploit mapping for discovery, reconnaissance,…

CLI tool for automated detection of server-side and client-side template injection vulnerabilities across 44 template engines in 8 programming…

The Swiss Army knife for automated Web Application Testing

Automatic SSTI detection tool with interactive interface

Automated DLL Hijacking Discovery, Validation, and Confirmation. Turning local misconfigurations into weaponized, confirmed attack paths.

Admission control and runtime guardrails for agentic AI. Scans skills, MCP servers, plugins, and code before execution; inspects prompts,…

AWS Organization-wide detection toolkit for CVE-2025-55182 & CVE-2025-66478 (React Server Components / Next.js RCE vulnerabilities)