
wtfis
Passive hostname, domain and IP lookup tool for non-robots

Passive hostname, domain and IP lookup tool for non-robots

Open-source intelligence investigation into Meta's multi-channel lobbying campaign for the App Store Accountability Act, tracing dark money flows,…

MassDNS wrapper written in go to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard filtering and easy…

Audits Active Directory SMB shares to inventory, analyze, and report excessive privileges. Discovers accessible systems, enumerates share ACLs,…

Tools for fingerprinting and exploiting Amazon cloud infrastructures

Proof-of-concept exploit for CVE-2025-14847, a MongoDB zlib decompression vulnerability that leaks uninitialized server memory via crafted BSON…

Orbis is an full spectrum automated external attack surface intelligent toolkit.



⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

Simple, but smart, multi-threaded web crawler for randomly gathering huge lists of unique domain names.

SkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS

A next-generation HTTP stealth proxy which perfectly cloaks requests as the Chrome browser across all layers of the stack.

Tool to find JavaScript files on Websites

HomePwn - Swiss Army Knife for Pentesting of IoT Devices

Autonomous AI penetration testing agent that orchestrates multi-agent recon, exploitation, post-exploitation, and reporting with persistent…

Multi-protocol honeypot simulator supporting 50+ network services with deep interaction, TCP/UDP/ICMP logging, JA3 fingerprinting, and virtual…