Sublist3r
Fast subdomains enumeration tool for penetration testers
A curated list of various bug bounty tools
This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.
A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)
The fastest and cross-platform subdomain enumerator, do not waste your time.
Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting
Go client to communicate with Chaos DNS API.
Multi Tool Subdomain Enumeration
This repository contains all the material from the talk "Esoteric sub-domain enumeration techniques" given at Bugcrowd LevelUp 2017 virtual conference
shuffleDNS is a wrapper around massdns written in go that allows you to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard handling and easy input-output…
Fast domain resolver and subdomain bruteforcing with accurate wildcard filtering with wildcard(*)
Perform subdomain enumeration using the certificate transparency logs from Censys.
Subdomain enumeration tool with analysis features for discovered domains
A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys
Fast subdomains enumeration tool for penetration testers.
Another Subdomain ENumeration Tool
A Web-UI for subdomain enumeration (subfinder)
Passive reconnaissance/enumeration of interesting targets by watching for SSL certificates being issued
enumall.py Setup script for Regon-ng
Generates permutations, alterations and mutations of subdomains and then resolves them
An automation framework for running multiple open sourced subdomain bruteforcing tools (in parallel) using your own wordlists via Docker Compose
his is a parallelised domain name prober to find as many subdomains of a given domain as fast as possible.
dnscan is a python wordlist-based DNS subdomain scanner.
Knockpy is a python tool designed to enumerate subdomains on a target domain through a wordlist.
Small, fast tool for performing reverse DNS lookups en masse.
Dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.
Subfinder is a subdomain discovery tool that discovers valid subdomains for websites.
Find domains and subdomains related to a given domain
Yet another subdomain finder
A virtual host scanner that performs reverse lookups
Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration
A research-grade suite of tools for subdomain enumeration, intelligence gathering and attack surface mapping.
Scrape domain names from SSL certificates of arbitrary hosts
Small tool to Grab subdomains using Shodan api
Golang client for querying SecurityTrails API data
This Go script simplifies the process of efficiently saving and analyzing subdomain output from the crt.sh website.
This Go tool performs searches on GitHub and parses the results to find subdomains of a given domain.
This Go tool performs searches on GitLab and parses the results to find subdomains of a given domain.
Fast and powerfull to enumerate subdomains (50+ passive results ).
Discover new target domains using Content Security Policy
Find related domains of a given domain. this tool search for domains that have been registered by the same peoples/companies.
hakip2host takes a list of IP addresses via stdin, then does a series of checks to return associated domain names.
TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.
Nmap - the Network Mapper. Github mirror of official SVN repository.
Nmap on steroids. Simple CLI with the ability to run pure Nmap engine, 31 modules with 459 scan profiles.
Combines the speed of masscan with the reliability and detailed enumeration of nmap
A command-line tool to quickly analyze all IPs in a file and see which ones have open ports/ vulnerabilities.
Fast Port Scanner 🚀
EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.
Aquatone is a tool for visual inspection of websites across a large amount of hosts and is convenient for quickly gaining an overview of HTTP-based attack surface.
Make website screenshots and mobile emulations from the command line.
Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier.
Convolutional neural network for analyzing pentest screenshots
A tool for collecting RDP, web and VNC screenshots all in one place
Recovers passwords from pixelized screenshots
HTTPScreenshot is a tool for grabbing screenshots and HTML of large numbers of websites.
Playwright wrapper for a stealth-patched Firefox 150 binary, useful for screenshotting and recon against targets with anti-bot detection (reCAPTCHA v3, FingerprintPro, Cloudflare).
Identify technology on websites.
Port of Wappalyzer (uncovers technologies used on websites) to automate mass scanning.
BuiltWith API client
scanner detecting the use of JavaScript libraries with known vulnerabilities
httpx is a fast and multi-purpose HTTP toolkit allows to run multiple probers using retryablehttp library, it is designed to maintain the result reliability with increased threads.
fingerprintx is a standalone utility for service discovery on open ports that works well with other popular bug bounty command line tools.
graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint.
wafw00f allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.
cdncheck is a tool for identifying the technology associated with dns / ip network addresses.
A fast and configurable TLS grabber focused on TLS based data collection and analysis.
This little tool is to calculate a MurmurHash value of a favicon. This favicon hash can be used to look for similar websites on various search engines.
rapid content discovery tool for recursively querying webservers, handy in pentesting and web application assessments
A fast, simple, recursive content discovery tool written in Rust.
A Go implementation of dirsearch.
An extremely fast and flexible web fuzzer
Modern alternative to dirbuster/dirb
dirbuster-ng is C CLI implementation of the Java dirbuster tool
Gospider - Fast web spider written in Go
Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application
Fast API endpoint bruteforcer and content discovery tool for modern web applications.
Vaf is a cross-platform very advanced and fast web fuzzer written in nim .
uncover is a go wrapper using APIs of well known search engines to quickly discover exposed hosts on the internet.
CLI tool for filtering a mixed list of targets (URLs/IPs) according to the bug-bounty program's scope. The scope can be supplied manually, or it can also be detected automatically by just giving hacker-scoper the name of the targeted company. Hacker-Scoper supports IPs, URLs, wildcards, CIDR…
A python script that finds endpoints in JavaScript files
a .js scanner, built in php. designed to scrape urls and other info
Extract (links/possible endpoints) from responses & filter them via decoding/sorting
A fast and minimal JS endpoint extractor
Burp Extension for a passive scanning JS files for endpoint links.
A golang utility to spider through a website searching for additional links.
Fetch all the URLs that the Wayback Machine knows about for a domain
Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.
A tool to fastly get all javascript sources/files
Reveals invisible links within JavaScript files
Find way more from the Wayback Machine!
A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target
A high-speed tool for passively gathering URLs, optimized for efficient web asset discovery without active scanning.
This Go tool performs searches on GitHub and parses the results to find endpoints of a given domain.
jsleak is a tool to find secret , paths or links in JavaScript files or source code.
A tool that scans web pages to find JavaScript file URLs linked in the HTML source code.
This tool extracts URLs, paths, secrets, and other interesting bits from JavaScript files. Values are extracted based not just on how they look, but also based on how they are used.
This tool can be used to brute discover GET and POST parameters
This extension identifies hidden, unlinked parameters. It's particularly useful for finding web alterx poisoning vulnerabilities.
This tool for brute discover GET and POST parameters.
HTTP parameter discovery suite.
Mining parameters from dark corners of Web Archives.
Hidden parameters discovery suite written in Rust.
Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.
Potentially dangerous files
A JavaScript Engine Fuzzer
Fuzzapi is a tool used for REST API pentesting and uses API_Fuzzer gem
qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.
very advanced (web) fuzzer written in Nim.
CORS Misconfiguration Scanner
Corser is a Golang CLI Application for Advanced CORS Misconfiguration Detection.
A simple CORS misconfiguration scanner
A multi-threaded scanner that helps identify CORS flaws/misconfigurations
Cross Origin Resource Sharing MisConfiguration Scanner
A fast tool specially designed to scan CRLF injection
A fast tool to scan CRLF vulnerability written in Go
Command line tool for testing CRLF injection on a list of domains.
CRLF and open redirect fuzzer
The Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.
DotDotPwn - The Directory Traversal Fuzzer
File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.
Burp extension to detect alias traversal via NGINX misconfiguration at scale.
tired of manually add dot-dot-slash to your possible path traversal? this short snippet will increment ../ on the URL.
Local file inclusion exploitation tool
Fuzzing for LFI using Burpsuite
Scripts to execute enumeration via LFI
Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner
Wordlist to bruteforce for LFI
InQL - A Burp Extension for GraphQL Security Testing
GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes.
GraphQL security testing tool
Burp Suite extension to help make Graphql request more readable
Obtain GraphQL API schema despite disabled introspection!
Customisable and automated HTTP header injection.
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.
Deserialization payload generator for a variety of .NET formatters
PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily
Open Redirection Analyzer
CRLF and open redirect fuzzer
Small script to check a list of domains against open redirect vulnerability
A Fuzzer for OpenRedirect issues
A Kernel fuzzer focusing on race bugs
Race Condition framework
Small Python library that makes it easy to exploit race conditions in web apps with Requests.
Turbo Intruder is a Burp Suite extension for sending large numbers of HTTP requests and analyzing the results.
Tests for race conditions in web applications. Includes a RESTful API to integrate into a continuous integration pipeline.
HTTP Request Smuggling Detection Tool
Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3
HTTP Request Smuggling over HTTP/2 Cleartext (h2c)
These scripts I use to create Request Smuggling Desync payloads for CLTE and TECL style attacks.
Automatic SSRF fuzzer and exploitation tool
This tool generates gopher link for exploiting SSRF and gaining RCE in various servers
A collection of scripts that run on my web server. Mainly for debugging SSRF, blind XSS, and XXE vulnerabilities.
An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects
Automatic tool for DNS rebinding-based SSRF attacks
A simple SSRF-testing sheriff written in Go
Toolkit to detect and keep track on Blind XSS, XXE & SSRF
Smart ssrf scanner using different methods like parameter brute forcing in post and get...
Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl and Filter Urls With OpenRedirection or SSRF Parameters.
Server-side request forgery detector
Authenticated SSRF in Grafana
Tool to searching sentry config on page or in javascript files and check blind SSRF
Bruteforcing on Hidden parameters to find SSRF vulnerability using GET and POST Methods
A DNS rebinding attack framework.
A "malicious" DNS server for executing DNS Rebinding attacks on the fly (public instance running on rebind.network:53)
A front-end JavaScript toolkit for creating DNS rebinding attacks.
DNS Rebinding Exploitation Framework
Simple DNS Rebinding Service
DNS rebinding toolkit
Escalate your SSRF vulnerabilities on Modern Cloud Environments. surf allows you to filter a list of hosts, returning a list of viable SSRF candidates.
Automated NoSQL database enumeration and web application exploitation tool.
Automatic SQL injection with Charles and sqlmap api
Python3 Burp History parsing tool to discover potential SQL injection points. To be used in tandem with SQLmap.
mssqlproxy is a toolkit aimed to perform lateral movement in restricted environments through a compromised Microsoft SQL Server via socket reuse
SQLi-Hunter is a simple HTTP / HTTPS proxy server and a SQLMAP API wrapper that makes digging SQLi easy.
Gather urls from wayback machine then test each GET parameter for sql injection.
Evil SQL Client (ESC) is an interactive .NET SQL console client with enhanced SQL Server discovery, access, and data exfiltration features.
SQL injection script for MSSQL that extracts domain users from an Active Directory environment based on RID bruteforcing
Performing SQLInjection test on Burp Suite Bulk Requests using SQLMap
Messy BurpSuite plugin for SQL Truncation vulnerabilities.
Blind SQL Injection Tool with Golang
A python library to automate time-based blind SQL injection
massive SQL injection vulnerability scanner
NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.
An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws
XSS'OR - Hack with JavaScript.
XSS spider - 66/66 wavsep XSS detected
Sleepy Puppy XSS Payload Management Framework
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
The XSS Hunter service - a portable version of XSSHunter.com
DalFox(Finder Of XSS) / Parameter Analysis and XSS Scanning tool based on golang
Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.
Powerful XSS Scanning and Parameter analysis tool&gem
XSS payloads designed to turn alert(1) into P1
A tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.
A collection of scripts that run on my web server. Mainly for debugging SSRF, blind XSS, and XXE vulnerabilities.
This is a burp intruder extender that is designed for automation and validation of XSS vulnerabilities.
An interactive multi-user web JS shell
bXSS is a utility which can be used by bug hunters and organizations to identify Blind Cross-Site Scripting.
Uility to embed XXE and XSS payloads in docx,odt,pptx,etc (OXML_XEE on steroids)
XSS Radar is a tool that detects parameters and fuzzes them for cross-site scripting vulnerabilities.
BruteXSS is a tool written in python simply to find XSS vulnerabilities in web application.
A fast DOM based XSS vulnerability scanner with simplicity.
DOM XSS scanner for Single Page Applications
Automated blind-xss search for Burp Suite
Toolkit to detect and keep track on Blind XSS, XXE & SSRF
DOMXSS Scanner is an online tool to scan source code for DOM based XSS vulnerabilities
Correlated injection proxy tool for XSS Hunter
A better version of my xssfinder tool - scans for different types of xss on a list of urls.
XSSMap 是一款基于 Python3 开发用于检测 XSS 漏洞的工具
XSSCon: Simple XSS Scanner tool
BurpSuite extension to inject custom cross-site scripting payloads on every form/request submitted to detect blind XSS vulnerabilities
Maintaining account persistence via XSS and Oauth
Shadow Workers is a free and open source C2 and proxy designed for penetration testers to help in the exploitation of XSS and malicious Service Workers (SW)
This is a burp plugin that extracts keywords from response using regexes and test for reflected XSS on the target scope.
XSS hunter on cloudflare serverless workers.
burpsuite 插件对GP所有参数(过滤特殊参数)一键自动添加xss sql payload 进行fuzz
Detect, manage and exploit Blind Cross-site scripting (XSS) vulnerabilities.
Chrome extension that finds DOM based XSS vulnerabilities
Develop your own XSS Payload using interactive typing
PNG IDAT chunks XSS payload generator
A simple Swagger-ui scanner that can detect old versions vulnerable to various XSS attacks
A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.
a tool designed to help bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting) vulnerabilities on sites where injections are blocked by CSPs that only allow certain whitelisted domains.
A collection of scripts that run on my web server. Mainly for debugging SSRF, blind XSS, and XXE vulnerabilities.
List DTDs and generate XXE payloads using those local DTDs.
Uility to embed XXE and XSS payloads in docx,odt,pptx,etc (OXML_XEE on steroids)
A mini webserver with FTP support for XXE payloads
Tool to help exploit XXE vulnerabilities
Toolkit to detect and keep track on Blind XSS, XXE & SSRF
Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.
A tool for embedding XXE/XML exploits into different filetypes
A bash script that automates the scanning of a target network for HTTP resources through XXE
Go scanner to find web cache poisoning vulnerabilities in a list of URLs .
Advanced tool for security researchers to bypass 403/40X restrictions .
A simple tool to bypass 403 forbidden end-points behind load balancers (Cloudflare) based on X-Forwarded-For header.
A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the system.
Burp Plugin to Bypass WAFs through the insertion of Junk Data.
Hydra is a parallelized login cracker which supports numerous protocols to attack.
One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password
A default credential scanner.
Automatically brute force all services running on a target.
Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.
Prevents you from committing secrets and credentials into git repositories
Searches through git repositories for high entropy strings and secrets, digging deep into commit history
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services
By hooking into the pre-push hook provided by Git, Talisman validates the outgoing changeset for things that look suspicious - such as authorization tokens and private keys.
Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.
A tool to capture all the git secrets by leveraging multiple open source git searching tools
Tools to perform basic search on GitHub.
Finding potential software vulnerabilities from git commit messages
#OSINT tool for finding Github repositories by extracting commit logs in real time from the Github event API
Scan your code for security misconfiguration, search for passwords and secrets.
Tool for advanced mining for content on Github
Ah shhgit! Find GitHub secrets in real time
An enterprise friendly way of detecting and preventing secrets in code.
A suite of secret scanners built in Rust for performance. Based on TruffleHog
Identify hardcoded secrets and dangerous behaviours
Yar is a tool for plunderin' organizations, users and/or repositories.
Search exposed EBS volumes for secrets
Monitors Github for leaked secrets
EarlyBird is a sensitive data detection tool capable of scanning source code repositories for clear text password violations, PII, outdated cryptography methods, key files and more.
Trufflehog-Chrome-Extension
Nosey Parker is a command-line program that finds secrets and sensitive information in textual data and Git history.
Recon tool leveraging Code Search API. Scans for exposed API keys across all of GitHub, not just known repos and orgs. Support for GitHub dorks.
Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more...
A python script for finding sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files.
Scans remote JavaScript files with Trufflehog + Semgrep to detect leaked secrets.
KeyHacks shows methods to validate different API keys found on a Bug Bounty Program or a pentest.
A repository with 3 tools for pwn'ing websites with .git repositories available
Leak git repositories from misconfigured websites
A tool to dump a git repository from a website
A tool for searching a Git repository for interesting content
Rip web accessible (distributed) version control systems: SVN/GIT/HG...
GitHub Self-Hosted Runner Enumeration and Attack Tool
Scan for open AWS S3 buckets and dump the contents
Security Tool to Look For Interesting Files in S3 Buckets
CloudScraper: Tool to enumerate targets in search of cloud resources. S3 Buckets, Azure Blobs, Digital Ocean Storage Space.
Publicly Open Amazon AWS S3 Bucket Viewer
FestIn - S3 Bucket Weakness Discovery
The format of various s3 buckets is convert in one format. for bugbounty and security testing.
This tests a list of s3 buckets to see if they have dir listings enabled or if they are uploadable
Firefox plugin that lists Amazon S3 Buckets found in requests
Finds Directory Listings or open S3 buckets from a list of URLs
Burp extension that performs a passive scan to identify cloud buckets and then test them for publicly accessible vulnerabilities
S3 bucket finder from html,js and bucket misconfiguration testing tool
Enumerate s3 buckets for a specific target.
Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files.
A security toolkit for Amazon S3
Awesome cloud enumerator
This tool will get the CNAME first if it's a valid Amazon s3 bucket and if it's not, it will try to check if the domain is a bucket name.
All-in-one AWS S3 bucket tool for pentesters.
Passive DNS-based discovery of S3 (and other cloud) buckets by resolving CNAMEs and IPs during recon—ideal for stealthy and early identification of cloud storage exposures
WPScan is a free, for non-commercial use, black box WordPress security scanner
A centralized dashboard for running and scheduling WordPress scans powered by wpscan utility.
Wordpress Recon
AI-powered WordPress plugin/theme security analysis platform with Semgrep-based static analysis and agent-assisted investigation workflows
CMSmap is a python open source CMS scanner that automates the process of detecting security flaws of the most popular CMSs.
OWASP Joomla Vulnerability Scanner Project
Free web-application vulnerability and version scanner
Tools to identify vulnerable Adobe Experience Manager (AEM) webapps.
Adobe Experience Manager Vulnerability Scanner
A toolkit for testing, tweaking and cracking JSON Web Tokens
JWT brute force cracker written in C
The Burp extension to check JWT (JSON Web Tokens) for using keys from known from public sources
Modular command-line tool to parse, create and manipulate JWT tokens for hackers
Simple python script to check against hypothetical JWT vulnerability.
jwt-hack is tool for hacking / security testing to JWT.
Simple HS256 JWT token brute force cracker
A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon
#BugBounty #BugBounty Tools #WebDeveloper Tool
Subdomain Takeover tool written in Go
A Powerful Subdomain Takeover Tool
A tool used to check if a CNAME resolves to the scope address. If the CNAME resolves to a non-scope address it might be worth checking out if subdomain takeover is possible.
Python utility to takeover domains vulnerable to AWS NS Takeover
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
take a list of resolved subdomains and output any corresponding CNAMES en masse.
Hijacking forgotten & misconfigured subdomains
A tool that can help detect and takeover subdomains with dead DNS records
This app will bruteforce for existing subdomains and provide information if the 3rd party host has been properly setup.
Second-order subdomain takeover scanner
A tool for testing subdomain takeover possibilities at a mass scale.
DNS Reaper is yet another sub-domain takeover tool, but with an emphasis on accuracy, speed and the number of signatures in our arsenal!
Subdomain takeover tool which works based on matching response fingerprints from can-i-take-over-xyz.
Nuclei is a fast tool for configurable targeted scanning based on templates offering massive extensibility and ease of use.
Community curated list of templates for the nuclei engine to find security vulnerabilities.
Automated pentest framework for offensive security experts
Metasploit Framework
Web Application Security Scanner Framework
The Swiss Army knife for automated Web Application Testing
scanner detecting the use of JavaScript libraries with known vulnerabilities
Fully automated offensive security framework for reconnaissance and vulnerability scanning
High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
Command line utility for searching and downloading exploits
A pretty sweet vulnerability scanner
Find exploits in local and online databases instantly
A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.
Finds unknown classes of injection vulnerabilities
Multithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities
Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more...
World’s most popular free web security tools and is actively maintained by a dedicated international team of volunteers
Automatic SSTI detection tool with interactive interface
Enterprise-grade web vulnerability scanner with 60+ attack modules, built in Rust for penetration testing and security assessments.
Browser-based vulnerability scanner for bug bounty and pentesting workflows, combining DAST, SAST, IAST, and SCA capabilities to detect runtime, source-level, interactive, and dependency-related security issues.
Fast and customizable subdomain wordlist generator using DSL. alterx takes patterns as input and generates subdomain permutation wordlist based on that pattern.
Gotator is a tool to generate DNS wordlists through permutations.
Rust-based high performance domain permutation generator.
DNSGen is a powerful and flexible DNS name permutation tool designed for security researchers and penetration testers. It generates intelligent domain name variations to assist in subdomain discovery and security assessments.
A permutation generation tool written in golang.
Generates permutations, alterations and mutations of subdomains and then resolves them
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
A versatile and portable proxy for capturing, manipulating, and replaying HTTP/HTTPS traffic on the go.
FoxyProxy is an open-source, advanced proxy management tool that completely replaces Chrome's limited proxying capabilities.
A tool that helps you find the real IP addresses hiding behind Cloudflare by checking subdomains.
Tool for discovering the origin host behind a reverse proxy. Useful for bypassing WAFs and other reverse proxies.
A tool for adding new lines to files, skipping duplicates
A wrapper around grep, to help you grep for things
declutters url lists for crawling/pentesting
Pull out bits of URLs provided on stdin
Accept URLs on stdin, replace all query string values with a user-supplied value
Interactsh is an open-source tool for detecting out-of-band interactions. It is a tool designed to detect vulnerabilities that cause external interactions.
The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
Notify is a Go-based assistance package that enables you to stream the output of several tools (or read from a file) and publish it to a variety of supported platforms.
Decompiles production JavaScript bundles (webpack, esbuild, Metro, and more) into readable modules, so JS files are easier to review and search.
Fully autonomous AI hacker to find actual exploits in your web apps.
Open source (GPL-3.0) autonomous AI penetration testing platform that orchestrates 80+ tools over MCP with dedicated per-technology offensive sub-agents (GraphQL, Spring Boot, ASP.NET, Node.js, Flask, PHP, Ruby) and a per-finding evidence trail.
AI-powered penetration testing assistant that helps automate security testing workflows and vulnerability discovery.
Claude Code plugin for autonomous bug bounty hunting across HackerOne, Bugcrowd, Intigriti and Immunefi — 15 skills, 33 commands and 9 agents covering recon-to-report, 21 web vuln classes, web3/meme-coin audits, LLM red-teaming, GraphQL/CORS/JWT/NoSQL scanners and persistent hunt memory. Works…
Offline-first, searchable arsenal for pentest & bug bounty: ~1500 payloads, a click-to-build command generator, GTFOBins, wordlists, an embedded CyberChef, reverse shells and 70 checklists. Self-hosted web app with a live static demo.
A powerful multi-platform RF toolbox that deploys specialized radio tools in seconds on Linux, Windows, and macOS—supporting x86_64, ARM64 (Raspberry Pi, Apple Silicon), and RISC-V architectures without disrupting your primary OS.
Automated security reporting from markdown templates (HackerOne and Bugcrowd are currently the platforms supported)
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports
A collection of android security related resources
An effort to build a single place for all useful android and iOS security related stuff.
Awesome Vulnerable Applications
It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
Go CLI and Library for quickly mapping organization network ranges using ASN information.
Utility program to perform multiple operations for a given subnet/CIDR ranges.
BigBountyRecon tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial reconnaissance on the target organisation.
Burp Suite extension that mutates ciphers to bypass TLS-fingerprint based bot detection.
Modern CLI for exploring vulnerability data with powerful search, filtering, and analysis capabilities.
Removing CDN IPs from the list of IP addresses.
A .DS_Store file disclosure exploit. It parses .DS_Store file and downloads files recursively.
awesome-selfhosted/awesome-selfhosted
A list of Free Software network services and web applications which can be hosted on your own servers
lissy93/awesome-privacy
🦄 A curated list of privacy & security-focused software and services
ashishb/android-security-awesome
A collection of android security related resources
edoardottt/awesome-hacker-search-engines
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
qazbnm456/awesome-web-security
🐶 A curated list of Web Security materials and resources.
kdeldycke/awesome-iam
👤 Identity and Access Management knowledge for cloud platforms