
xpfarm
Automated bug bounty & recon framework — wraps Subfinder, Naabu, Httpx, Nuclei, Nmap, CVEMap, Gowitness, Katana & more behind a unified web UI

Automated bug bounty & recon framework — wraps Subfinder, Naabu, Httpx, Nuclei, Nmap, CVEMap, Gowitness, Katana & more behind a unified web UI

Flask-like routing framework for mitmproxy to intercept, modify, and spoof HTTP requests/responses. Enables rapid development of MITM scripts for…

YAML-configurable low-interactive honeypot framework for deploying HTTP/HTTPS-based deception servers with built-in honeytraps and Datadog log…

Application-layer protocol framework for trust-based, end-to-end encrypted communication across heterogeneous networks, enabling uniform service…

JAW: A Graph-based Security Analysis Framework for Client-side JavaScript

A blazing fast and fully configurable Blind SQL Injection optimization and automation framework.

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

An modular asset discovery framework written in python to automate the repeating manual work

Vimana is a modular security framework for auditing Python APIs and Web applications. The plugin-based architecture enables security professionals to…

PhishCollector is a research framework for collecting, analysing, and tracking phishing sites.

Fuzzing Framework for Modules in Apache HTTPD Server

Open-source framework for embedding realistic decoy routes and honey fields into APIs to detect attackers probing business logic, converting…

ReactGuard provides framework- and vulnerability-detection tooling for CVE-2025-55182 (React2Shell)

Automated reconnaissance and XSS detection framework integrating subfinder, httpx, katana, gospider, waybackurls, and dalfox into a 9-stage pipeline…

Minimal proof-of-concept for Spring Framework UrlHandlerFilter open redirect (CVE-2026-47883), demonstrating crafted double-slash requests produce…

Python-based exploitation framework for CVE-2026-75604, enabling authorized pentesters to validate Next.js Windows cache traversal vulnerabilities…

Spring4Shell , Spring Framework RCE (CVE-2022-22965) , Burpsuite Plugin

Automated reconnaissance and exploitation framework for misconfigured Supabase instances. Features schema enumeration, Selenium-based key extraction,…