
HawkScan
Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

Security Tool for Reconnaissance and Information Gathering on a website. (python 3.x)

Advanced security testing tool for CVE-2025-55182 vulnerability assessment in Next.js applications. Features interactive shell, batch scanning, WAF…

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

Discovers origin server IP addresses behind WAF-protected websites by querying Shodan, Censys, and ZoomEye search engines for domain information.

Automated web reconnaissance tool with dork scanning, SQLi/XSS detection, port scanning, admin panel discovery, and WAF/captcha bypass capabilities.

Tests hundreds of URL bypass techniques against 40X protected pages using raw curl requests, with multi-mode scanning, header spoofing, and JSON/HTML…

Blind WAF identification tool that recognizes over 80 web protection systems by analyzing responses to non-destructive offensive payloads, enabling…

Ruby-based tool to bypass Cloudflare protection by discovering the origin server's real IP address through DNS analysis, useful for testing server…

Authorized WAF bypass proxy that rotates TCP/TLS/HTTP2 fingerprints, hunts origin IPs behind firewalls, and scans WAF defenses across 10 layers for…

A Modular Framework for Pentesters and Bug Hunters written in python.

Automated web application security scanner detecting and exploiting RCE, SQL injection, and XSS vulnerabilities with WAF bypass payloads and backend…

From Dork to Download: Automating Google Dorks with Playwright

Plugins for Woodpecker framework: WebLogic T3/IIOP scanning, credential extraction, Spring Boot API scan, Log4j2 bypass payloads, and Java exec…

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

Automated scanner for CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Features async endpoint discovery, subdomain…

Mass exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in Divi Form Builder. Features multi-threaded scanning, WAF bypass…

Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to…

Multi-technique XPath injection scanner with error-based, boolean/time-based blind, union, and auth bypass detection. Supports visible and blind data…