
apidetector
Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Bash script to build your own system.prop

Rust-powered HTTP Request Smuggling Scanner.


A Burp Extension designed to identify argument injection vulnerabilities.

Android reverse engineering entirely on-device. Radare2 binary analysis, 8 Java decompilers, Flutter & Unity il2cpp support.

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions


Professional extension of sqlmap project

Burp Extension for collaboration in Faraday

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.


Self-hosted WAF and reverse proxy that filters malicious HTTP traffic, blocks SQL injection, XSS, and bot attacks, with rate limiting and dynamic…

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling…

🥧 HTTPie CLI — modern, user-friendly command-line HTTP client for the API era. JSON support, colors, sessions, downloads, plugins & more.

Go-based Web Application Firewall library compatible with ModSecurity SecLang rules and OWASP Core Rule Set v4, providing real-time HTTP traffic…