
joomscan
Perl-based Joomla CMS vulnerability scanner automating version enumeration, component detection, exploit matching, firewall identification, and…

Perl-based Joomla CMS vulnerability scanner automating version enumeration, component detection, exploit matching, firewall identification, and…

Security module for php7 and php8 - Killing bugclasses and virtual-patching the rest!

SSRF plugin for burp Automates SSRF Detection in all of the Request

This Burp Suite extension allows you to customize header with put a new header into HTTP REQUEST BurpSuite (Scanner, Intruder, Repeater, Proxy…

Automated deployment of OWASP Juice Shop on Kubernetes using kubeadm and Terraform, with integrated Trivy vulnerability scanning for DevSecOps…

In-depth attack surface mapping and asset discovery

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Open-source adversary emulation for AI agents and MCP servers.

A collection of hacking / penetration testing resources to make you better!

Lightweight service virtualization/ API simulation / API mocking tool for developers and testers

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying…

Maryam: Open-source Intelligence(OSINT) Framework

Extends Selenium's Python bindings to give you the ability to inspect requests made by the browser.

Martian is a library for building custom HTTP/S proxies

The Secure Coding Framework

GraphQL automated security testing toolkit