
mitmproxy2swagger
Automagically reverse-engineer REST APIs via capturing traffic

Automagically reverse-engineer REST APIs via capturing traffic

AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.

A python script that finds endpoints in JavaScript files

A fast, simple, recursive content discovery tool written in Rust.


Automated Web Application Firewall fingerprinting tool that identifies and detects over 200 WAF products by analyzing HTTP responses to normal and…

Community curated list of public bug bounty and responsible disclosure programs.

Real-world infosec wordlists, updated regularly

Automated web screenshot tool for reconnaissance, capturing site visuals, server headers, and identifying default credentials. Supports multiple…

Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32…

HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH.

Chrome extension and Express server that exploits keylogging abilities of CSS.

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files

Curated Google Dork search patterns for web security and bug bounty reconnaissance, covering exposed files, admin panels, CMS instances, logs, and…

🔍 gowitness - a golang, web screenshot utility using Chrome Headless

Tools for Pentesting

An OOB interaction gathering server and client library