A semi automatic pen testing tool for mapping/pen-testing networks. Simulates a human attacker.
PythonGNU General Public License v3.0slowing
15 projectsWeb › Scanning / Pentesting
A semi automatic pen testing tool for mapping/pen-testing networks. Simulates a human attacker.
PythonGNU General Public License v3.0slowing
Recon-ng is a full-featured Web Reconnaissance framework written in Python. Recon-ng has a look and feel similar to the Metasploit Framework.
PythonGNU General Public License v3.0slowing
The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.
Pythonslowing
Full-featured C2 framework which silently persists on webserver via evil PHP oneliner. Built for stealth persistence, with many privilege-escalation & post-exploitation features.
PythonGNU General Public License v3.0slowing
finds publicly known security vulnerabilities in a website's frontend JavaScript libraries.
JavaScriptApache License 2.0active
A modular vulnerability scanner with automatic report generation capabilities.
PythonBSD 3-Clause "New" or "Revised" Licenseactive
Keyscope is an extensible key and secret validation for checking active secrets against multiple SaaS vendors built in Rust
RustApache License 2.0slowing
ACSTIS helps you to scan certain web applications for AngularJS Client-Side Template Injection (sometimes referred to as CSTI, sandbox escape or sandbox bypass). It supports scanning a single request but also crawling the entire web application for the AngularJS CSTI vulnerability.
PythonMIT Licensedormant
padding-oracle-attacker is a CLI tool and library to execute padding oracle attacks (which decrypts data encrypted in CBC mode) easily, with support for concurrent network requests and an elegant UI.
TypeScriptMIT Licensedormant
The Cyclops is a web browser with XSS detection feature, it is chromium-based xss detection that used to find the flows from a source to a sink.
GNU General Public License v3.0slowing
The ultimate web application security testing tool for CakePHP-based web applications. CakeFuzzer employs a predefined set of attacks that are randomly modified before execution. Leveraging its deep understanding of the Cake PHP framework, Cake Fuzzer launches attacks on all potential application entry points.
PythonGNU General Public License v3.0slowing
a fast Rust based CLI that uses SQL to query over files, code, or malware with content classification and processing for security experts
RustApache License 2.0dormant
URL security scanner with WHOIS, SSL, threat intelligence (URLhaus, PhishTank, Spamhaus), and 40+ scam/phishing pattern detection. Includes optional AI analysis via Ollama.
TypeScriptMIT Licensesteady
Detect indicators of compromise from the Shai Hulud 2.0 npm supply chain attack that compromised 796+ packages. Performs comprehensive security checks for malicious files, hashes, and patterns.
ShellMIT Licensesteady
Detect CVE-2025-55182 (React2Shell) RCE vulnerability in React Server Components. Scans React 19.x and Next.js projects for critical remote code execution flaws.
ShellMIT Licensesteady