Stars
Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the β¦
A next-generation crawling and spidering framework.
Directory/File, DNS and VHost busting tool written in Go
httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.
Reconnaissance tool for GitHub organizations
A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentests
Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application
Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.
ππ¦ Dalfox is a powerful open-source XSS scanner and utility focused on automation.
A Security Tool for Bug Bounty, Pentest and Red Teaming.
π gowitness - a golang, web screenshot utility using Chrome Headless
Find domains and subdomains related to a given domain
Take a list of domains and probe for working HTTP and HTTPS servers
Scan for misconfigured S3 buckets across S3-compatible APIs!
Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.
Fetch many paths for many hosts - without killing the hosts
Notify is a Go-based assistance package that enables you to stream the output of several tools (or read from a file) and publish it to a variety of supported platforms.
Community curated list of public bug bounty and responsible disclosure programs.
Golang client for querying SecurityTrails API data
Fleex makes it easy to create multiple VPS on cloud providers and use them to distribute workloads.
Exploit for WebSocket Vulnerability in Apache Tomcat