
FinalRecon
Automated web reconnaissance tool providing header analysis, DNS enumeration, subdomain discovery, directory scanning, SSL inspection, and port…

Automated web reconnaissance tool providing header analysis, DNS enumeration, subdomain discovery, directory scanning, SSL inspection, and port…

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more

This script is intended to automate your reconnaissance process in an organized fashion

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Fetch all the URLs that the Wayback Machine knows about for a domain

Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

OnionScan is a free and open source tool for investigating the Dark Web.

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing

pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching

Arsenal is just a quick inventory and launcher for hacking programs

Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X!

A tool to dump a git repository from a website

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

🕷️ A `.git` folder exploiting tool that is able to restore the entire Git repository, including stash, common branches and common tags.

An advanced web directory & file scanning tool that will be more powerful than DirBuster, Dirsearch, cansina, and Yu…