
x8
Hidden parameters discovery suite

Hidden parameters discovery suite

🦁 Python project to identify and scan for vulnerabilities related to the Joomla CMS project. It scans for common misconfigurations and public…

Automated web screenshot tool for reconnaissance, capturing site visuals, server headers, and identifying default credentials. Supports multiple…

🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.

Cross-platform penetration testing platform with Docker support, web-based interface, and API for automated vulnerability scanning and security…

Brute-force tool for discovering hidden GET and POST parameters in web applications, supporting custom wordlists and concurrent requests.

server security auditor scanning Apache, Nginx, and IIS configurations with AI-powered hardening guides and professional reporting.

High-performance web path discovery and directory brute-forcing tool. Discovers hidden files, directories, and endpoints using customizable…

Sanitized report and loopback-only PoC for CVE-2026-102971, a MediaWiki REST revision response leaking hidden revision author user IDs.

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Directory/File, DNS and VHost busting tool written in Go

My simple Swiss Army knife for http/https troubleshooting and profiling.

A tool for bug hunting or pentesting for targeting websites that have open .git repositories available in public

Modern alternative to dirbuster/dirb

Bash script that enumerates subdomains via Subfinder, resolves IPs, and identifies live web applications hosted on a domain for reconnaissance and…

OpenSSL Heartbleed Bug CVE-2014-0160 Toolkit. Built with ❤ by Christopher Ngo.

network visualization & pentest reporting

Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.