Army-Knife |
jaeles |
The Swiss Army knife for automated Web Application Testing |
 |
live-audit |
    |
Proxy |
Glorp |
A CLI-based HTTP intercept and replay proxy |
 |
mitmproxy |
    |
Proxy |
hetty |
Hetty is an HTTP toolkit for security research. It aims to become an open source alternative to commercial software like Burp Suite Pro, with powerful features tailored to the needs of the infosec and bug bounty community. |
 |
mitmproxy |
    |
Proxy |
proxify |
Swiss Army knife Proxy tool for HTTP/HTTPS traffic capture, manipulation and replay |
 |
mitmproxy |
    |
Recon |
scilla |
🏴☠️ Information Gathering tool 🏴☠️ dns/subdomain/port enumeration |
 |
subdomains dns port |
    |
Recon |
csprecon |
Discover new target domains using Content Security Policy |
 |
csp |
    |
Recon |
cariddi |
Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more |
 |
crawl |
    |
Recon |
Osmedeus |
Fully automated offensive security framework for reconnaissance and vulnerability scanning |
 |
|
    |
Recon |
hakrawler |
Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application |
 |
crawl |
    |
Recon |
gospider |
Gospider - Fast web spider written in Go |
 |
crawl |
    |
Recon |
go-dork |
The fastest dork scanner written in Go. |
 |
|
    |
Recon |
SubOver |
A Powerful Subdomain Takeover Tool |
 |
subdomains takeover |
    |
Recon |
waybackurls |
Fetch all the URLs that the Wayback Machine knows about for a domain |
 |
url |
    |
Recon |
gau |
Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl. |
 |
url |
    |
Recon |
httpx |
httpx is a fast and multi-purpose HTTP toolkit allow to run multiple probers using retryablehttp library, it is designed to maintain the result reliability with increased threads. |
 |
url |
    |
Recon |
subgen |
A really simple utility to concate wordlists to a domain name - to pipe into your favourite resolver! |
 |
subdomains |
    |
Recon |
dmut |
A tool to perform permutations, mutations and alteration of subdomains in golang. |
 |
subdomains |
    |
Recon |
getJS |
A tool to fastly get all javascript sources/files |
 |
js-analysis |
    |
Recon |
subjs |
Fetches javascript file from a list of URLS or subdomains. |
 |
url subdomains |
    |
Recon |
zdns |
Fast CLI DNS Lookup Tool |
 |
dns |
    |
Recon |
chaos-client |
Go client to communicate with Chaos DNS API. |
 |
|
    |
Recon |
github-endpoints |
Find endpoints on GitHub. |
 |
|
    |
Recon |
favirecon |
Use favicon.ico to improve your target recon phase. Quickly detect technologies, WAF, exposed panels, known services. |
 |
favicon |
    |
Recon |
subjack |
Subdomain Takeover tool written in Go |
 |
subdomains takeover |
    |
Recon |
goverview |
goverview - Get an overview of the list of URLs |
 |
url |
    |
Recon |
dnsprobe |
DNSProb (beta) is a tool built on top of retryabledns that allows you to perform multiple dns queries of your choice with a list of user supplied resolvers. |
 |
dns |
    |
Recon |
dnsx |
dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers. |
 |
dns |
    |
Recon |
naabu |
A fast port scanner written in go with focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentests |
 |
portscan |
    |
Recon |
assetfinder |
Find domains and subdomains related to a given domain |
 |
subdomains |
    |
Recon |
puredns |
Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries. |
 |
subdomains dns |
    |
Recon |
gowitness |
🔍 gowitness - a golang, web screenshot utility using Chrome Headless |
 |
|
    |
Recon |
htcat |
Parallel and Pipelined HTTP GET Utility |
 |
|
    |
Recon |
gitrob |
Reconnaissance tool for GitHub organizations |
 |
|
    |
Recon |
gauplus |
A modified version of gau for personal usage. Support workers, proxies and some extra things. |
 |
url |
    |
Recon |
uncover |
Quickly discover exposed hosts on the internet using multiple search engine. |
 |
|
    |
Recon |
Sub404 |
A python tool to check subdomain takeover vulnerability |
 |
subdomains takeover |
    |
Recon |
Amass |
In-depth Attack Surface Mapping and Asset Discovery |
 |
subdomains |
    |
Recon |
shosubgo |
Small tool to Grab subdomains using Shodan api. |
 |
subdomains |
    |
Recon |
katana |
A next-generation crawling and spidering framework. |
 |
crawl |
    |
Recon |
github-subdomains |
Find subdomains on GitHub |
 |
subdomains |
    |
Recon |
hakrevdns |
Small, fast tool for performing reverse DNS lookups en masse. |
 |
|
    |
Recon |
Smap |
a drop-in replacement for Nmap powered by shodan.io |
 |
port |
    |
Recon |
urlhunter |
a recon tool that allows searching on URLs that are exposed via shortener services |
 |
url |
    |
Recon |
crawlergo |
A powerful browser crawler for web vulnerability scanners |
 |
crawl |
    |
Recon |
jsluice |
Extract URLs, paths, secrets, and other interesting bits from JavaScript |
 |
js-analysis |
    |
Recon |
shuffledns |
shuffleDNS is a wrapper around massdns written in go that allows you to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard handling and easy input-output support. |
 |
dns |
    |
Recon |
subfinder |
Subfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing. |
 |
subdomains |
    |
Recon |
gobuster |
Directory/File, DNS and VHost busting tool written in Go |
 |
subdomains |
    |
Recon |
haktrails |
Golang client for querying SecurityTrails API data |
 |
|
    |
Recon |
aquatone |
A Tool for Domain Flyovers |
 |
domain |
    |
Recon |
meg |
Fetch many paths for many hosts - without killing the hosts |
 |
|
    |
Recon |
subzy |
Subdomain takeover vulnerability checker |
 |
subdomains takeover |
    |
Fuzzer |
jwt-hack |
🔩 jwt-hack is tool for hacking / security testing to JWT. Supported for En/decoding JWT, Generate payload for JWT attack and very fast cracking(dict/brutefoce) |
 |
jwt |
    |
Fuzzer |
SmuggleFuzz |
A rapid HTTP downgrade smuggling scanner written in Go. |
 |
smuggle fuzz |
    |
Fuzzer |
kiterunner |
Contextual Content Discovery Tool |
 |
|
    |
Fuzzer |
headerpwn |
A fuzzer for finding anomalies and analyzing how servers respond to different HTTP headers |
 |
header |
    |
Fuzzer |
medusa |
Fastest recursive HTTP fuzzer, like a Ferrari. |
 |
|
    |
Fuzzer |
fuzzparam |
A fast go based param miner to fuzz possible parameters a URL can have. |
 |
param |
    |
Fuzzer |
ffuf |
Fast web fuzzer written in Go |
 |
|
    |
Scanner |
dalfox |
🌘🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation. |
 |
xss |
    |
Scanner |
dontgo403 |
Tool to bypass 40X response codes. |
 |
403 |
    |
Scanner |
headi |
Customisable and automated HTTP header injection |
 |
header |
    |
Scanner |
scan4all |
Official repository vuls Scan |
 |
|
    |
Scanner |
Deadsniper |
A fast, specialized dead-link checker |
 |
broken-link |
    |
Scanner |
CorsMe |
Cross Origin Resource Sharing MisConfiguration Scanner |
 |
cors |
    |
Scanner |
h2csmuggler |
HTTP Request Smuggling Detection Tool |
 |
smuggle |
    |
Scanner |
websocket-connection-smuggler |
websocket-connection-smuggler |
 |
smuggle |
    |
Scanner |
httprobe |
Take a list of domains and probe for working HTTP and HTTPS servers |
 |
|
    |
Scanner |
http2smugl |
This tool helps to detect and exploit HTTP request smuggling in cases it can be achieved via HTTP/2 -> HTTP/1.1 conversion by the frontend server. |
 |
|
    |
Scanner |
ws-smuggler |
WebSocket Connection Smuggler |
 |
smuggle |
    |
Scanner |
plution |
Prototype pollution scanner using headless chrome |
 |
prototypepollution prototype-pollution |
    |
Scanner |
ppmap |
A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets. |
 |
prototypepollution prototype-pollution |
    |
Scanner |
wprecon |
Hello! Welcome. Wprecon (Wordpress Recon), is a vulnerability recognition tool in CMS Wordpress, 100% developed in Go. |
 |
|
    |
Scanner |
FockCache |
Minimalized Test Cache Poisoning |
 |
cache-vuln |
    |
Scanner |
Web-Cache-Vulnerability-Scanner |
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/). |
 |
cache-vuln |
    |
Scanner |
nuclei |
Nuclei is a fast tool for configurable targeted scanning based on templates offering massive extensibility and ease of use. |
 |
|
    |
Scanner |
DirDar |
DirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it |
 |
403 |
    |
Scanner |
ditto |
A tool for IDN homograph attacks and detection. |
 |
|
    |
Scanner |
confused |
Tool to check for dependency confusion vulnerabilities in multiple package management systems |
 |
dependency-confusion |
    |
Scanner |
pphack |
The Most Advanced Client-Side Prototype Pollution Scanner |
 |
prototypepollution prototype-pollution |
    |
Scanner |
gitleaks |
Scan git repos (or files) for secrets using regex and entropy 🔑 |
 |
|
    |
Scanner |
nosqli |
NoSql Injection CLI tool |
 |
nosqli |
    |
Scanner |
hinject |
Host Header Injection Checker |
 |
header |
    |
Scanner |
ssrf-sheriff |
A simple SSRF-testing sheriff written in Go |
 |
ssrf |
    |
Exploit |
xxeserv |
A mini webserver with FTP support for XXE payloads |
 |
|
    |
Utils |
urlgrab |
A golang utility to spider through a website searching for additional links. |
 |
url |
    |
Utils |
interactsh |
An OOB interaction gathering server and client library |
 |
oast |
    |
Utils |
github-regexp |
Basically a regexp over a GitHub search. |
 |
|
    |
Utils |
cent |
Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place. |
 |
nuclei-templates |
    |
Utils |
nuclei-templates |
Community curated list of templates for the nuclei engine to find security vulnerabilities. |
 |
nuclei-templates |
    |
Utils |
godeclutter |
Declutters URLs in a fast and flexible way, for improving input for web hacking automations such as crawlers and vulnerability scans. |
 |
url |
    |
Utils |
slackcat |
CLI utility to post files and command output to slack |
 |
notify |
    |
Utils |
dsieve |
Filter and enrich a list of subdomains by level |
 |
subdomains |
    |
Utils |
wuzz |
Interactive cli tool for HTTP inspection |
 |
http |
    |
Utils |
gitls |
Listing git repository from URL/User/Org |
 |
|
    |
Utils |
hakcheckurl |
Takes a list of URLs and returns their HTTP response codes |
 |
|
    |
Utils |
gotestwaf |
An open-source project in Golang to test different web application firewalls (WAF) for detection logic and bypasses |
 |
|
    |
Utils |
hacks |
A collection of hacks and one-off scripts |
 |
|
    |
Utils |
blistener |
Blind-XSS listener with payloads |
 |
xss blind-xss |
    |
Utils |
unfurl |
Pull out bits of URLs provided on stdin |
 |
url |
    |
Utils |
gf |
A wrapper around grep, to help you grep for things |
 |
|
    |
Utils |
mubeng |
An incredibly fast proxy checker & IP rotator with ease. |
 |
|
    |
Utils |
qsreplace |
Accept URLs on stdin, replace all query string values with a user-supplied value |
 |
|
    |
Utils |
pet |
Simple command-line snippet manager, written in Go. |
 |
|
    |
Utils |
anew |
A tool for adding new lines to files, skipping duplicates |
 |
|
    |
Utils |
fzf |
A command-line fuzzy finder |
 |
|
    |
Utils |
boast |
The BOAST Outpost for AppSec Testing (v0.1.0) |
 |
oast |
    |
Utils |
TukTuk |
Tool for catching and logging different types of requests. |
 |
oast |
    |
Utils |
gee |
🏵 Gee is tool of stdin to each files and stdout. It is similar to the tee command, but there are more functions for convenience. In addition, it was written as go |
 |
|
    |
Utils |
fff |
The Fairly Fast Fetcher. Requests a bunch of URLs provided on stdin fairly quickly. |
 |
url |
    |
Utils |
Emissary |
Send notifications on different channels such as Slack, Telegram, Discord etc. |
 |
notify |
    |
Utils |
cf-check |
Cloudflare Checker written in Go |
 |
|
    |
Utils |
s3reverse |
The format of various s3 buckets is convert in one format. for bugbounty and security testing. |
 |
s3 |
    |
Utils |
urlprobe |
Urls status code & content length checker |
 |
url |
    |
Utils |
dnsobserver |
A handy DNS service written in Go to aid in the detection of several types of blind vulnerabilities. It monitors a pentester's server for out-of-band DNS interactions and sends lookup notifications via Slack. |
 |
oast dns |
    |
Utils |
burl |
A Broken-URL Checker |
 |
url |
    |
Utils |
gxss |
Blind XSS service alerting over slack or email |
 |
xss blind-xss |
    |
Utils |
gotator |
Gotator is a tool to generate DNS wordlists through permutations. |
 |
|
    |
Utils |
gron |
Make JSON greppable! |
 |
json |
    |