
shellsum
A defense tool - detect web shells in local directories via md5sum

A defense tool - detect web shells in local directories via md5sum


The Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

80k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒

ZCBS/ZBBS/ZPBS v4.14k - Reflected XSS

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

一款长亭自研的完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24…

Penetration tests guide based on OWASP including test cases, resources and examples.

The Swiss Army knife for automated Web Application Testing

Burp Suite plugin for generating and executing Nuclei vulnerability templates directly from HTTP requests and responses, with YAML auto-complete and…

Go-based CLI scanner for web cache poisoning and deception. Supports 10 poisoning techniques, multiple deception methods, built-in crawler, JSON…

Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision

SQL Vulnerability Scanner

Autonomous AI pentesting agents — real-time reconnaissance, vulnerability detection, and exploitation orchestration. Go + TypeScript.

NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…