Home

Awesome

<h1 align="center"> <br> <a href=""><img src="https://user-images.githubusercontent.com/13212227/104400969-9f3d9280-5596-11eb-80f4-864effae95fc.png" alt="" width="500px;"></a> <br> <img src="https://img.shields.io/github/last-commit/hahwul/WebHackersWeapons?style=flat"> <img src="https://img.shields.io/badge/PRs-welcome-cyan"> <img src="https://github.com/hahwul/WebHackersWeapons/actions/workflows/cd.yml/badge.svg"> <a href="https://twitter.com/intent/follow?screen_name=hahwul"><img src="https://img.shields.io/twitter/follow/hahwul?style=flat&logo=twitter"></a> </h1> A collection of awesome tools used by Web hackers. Happy hacking , Happy bug-hunting

Family project

WebHackersWeapons MobileHackersWeapons

Table of Contents

Weapons

Attributes

Attributes
TypesArmy-Knife Proxy Recon Fuzzer Scanner Exploit Env Utils Etc
Tagsinfra pentest live-audit mitmproxy crawl recon exploit subdomains portscan url js-analysis dns osint param apk endpoint csp attack-surface favicon port takeover domain online graphql cache-vuln ssrf prototypepollution prototype-pollution ssti crlf smuggle fuzz jwt header path-traversal xss s3 cors nosqli dependency-confusion broken-link 403 sqli aaa ssl lfi rfi oast RMI xxe rop deserialize notify dom report nuclei-templates json blind-xss wordlist documents payload note web3 http cookie browser-record encode darkmode clipboard zipbomb diff gRPC-Web
LangsShell Ruby Go Java Rust Python C Crystal Kotlin JavaScript Perl C# TypeScript Txt BlitzBasic CSS PHP C++ HTML

Tools

TypeNameDescriptionStarTagsBadges
Army-KnifeaxiomA dynamic infrastructure toolkit for red teamers and bug bounty hunters!infralinuxmacoswindowsShell
Army-KnifeMetasploitThe world’s most used penetration testing frameworkpentestlinuxmacoswindowsRuby
Army-KnifejaelesThe Swiss Army knife for automated Web Application Testinglive-auditlinuxmacoswindowsGo
Army-KnifeBurpSuiteThe BurpSuite Projectmitmproxy live-audit crawllinuxmacoswindowsburpJava
Army-KnifeZAPThe ZAP core projectmitmproxy live-audit crawllinuxmacoswindowszapJava
Army-knifeRoninFree and Open Source Ruby Toolkit for Security Research and Developmentpentest crawl recon exploitlinuxmacoswindowsRuby
ProxyhettyHetty is an HTTP toolkit for security research. It aims to become an open source alternative to commercial software like Burp Suite Pro, with powerful features tailored to the needs of the infosec and bug bounty community.mitmproxylinuxmacoswindowsGo
ProxyEcho MirageA generic network proxy that uses DLL injection to capture and alter TCP traffic.mitmproxywindows
ProxyCaidoA lightweight web security auditing toolkitmitmproxylinuxmacoswindowscaidoRust
ProxymitmproxyAn interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.mitmproxylinuxmacoswindowsPython
ProxyproxifySwiss Army knife Proxy tool for HTTP/HTTPS traffic capture, manipulation and replaymitmproxylinuxmacoswindowsGo
ProxyEvilProxyA ruby http/https proxy to do EVIL things.mitmproxylinuxmacoswindowsRuby
ProxyGlorpA CLI-based HTTP intercept and replay proxymitmproxylinuxmacoswindowsGo
ReconknockKnock Subdomain ScansubdomainslinuxmacoswindowsPython
ReconRustScanFaster Nmap Scanning with RustportscanlinuxmacoswindowsRust
RecongospiderGospider - Fast web spider written in GocrawllinuxmacoswindowsGo
RecongauplusA modified version of gau for personal usage. Support workers, proxies and some extra things.urllinuxmacoswindowsGo
ReconmegFetch many paths for many hosts - without killing the hostslinuxmacoswindowsGo
ReconjsluiceExtract URLs, paths, secrets, and other interesting bits from JavaScriptjs-analysislinuxmacoswindowsGo
ReconpurednsPuredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.subdomains dnslinuxmacoswindowsGo
ReconmegplusAutomated reconnaissance wrapper — TomNomNom's meg on steroids. [DEPRECATED]linuxmacoswindowsShell
ReconxnLinkFinderA python tool used to discover endpoints (and potential parameters) for a given targetjs-analysislinuxmacoswindowsPython
ReconOsmedeusFully automated offensive security framework for reconnaissance and vulnerability scanninglinuxmacoswindowsGo
ReconlongtongueCustomized Password/Passphrase List inputting Target InfolinuxmacoswindowsPython
ReconspiderfootSpiderFoot automates OSINT collection so that you can focus on analysis.osintlinuxmacoswindowsPython
ReconCT_subdomainsAn hourly updated list of subdomains gathered from certificate transparency logssubdomainslinuxmacoswindows
ReconuncoverQuickly discover exposed hosts on the internet using multiple search engine.linuxmacoswindowsGo
ReconArjunHTTP parameter discovery suite.paramlinuxmacoswindowsPython
RecongetJSA tool to fastly get all javascript sources/filesjs-analysislinuxmacoswindowsGo
ReconAmassIn-depth Attack Surface Mapping and Asset DiscoverysubdomainslinuxmacoswindowsGo
ReconbbotOSINT automation for hackersosintlinuxmacoswindowsPython
ReconmasscanTCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.portscanlinuxmacoswindowsC
Recongoverviewgoverview - Get an overview of the list of URLsurllinuxmacoswindowsGo
ReconapkleaksScanning APK file for URIs, endpoints & secrets.apk url endpointlinuxmacoswindowsPython
ReconGitMinerTool for advanced mining for content on GithublinuxmacoswindowsPython
ReconcspreconDiscover new target domains using Content Security PolicycsplinuxmacoswindowsGo
ReconSTEWSA Security Tool for Enumerating WebSocketslinuxmacoswindowsPython
Reconpagodopagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searchinglinuxmacoswindowsPython
Recongo-dorkThe fastest dork scanner written in Go.linuxmacoswindowsGo
ReconnoirAttack surface detector that identifies endpoints by static analysisendpoint url attack-surfacelinuxmacosCrystal
ReconaltdnsGenerates permutations, alterations and mutations of subdomains and then resolves themdns subdomainslinuxmacoswindowsPython
RecondmutA tool to perform permutations, mutations and alteration of subdomains in golang.subdomainslinuxmacoswindowsGo
ReconrusolverFast and accurate DNS resolver.dnslinuxmacoswindowsRust
ReconLinkFinderA python script that finds endpoints in JavaScript filesjs-analysislinuxmacoswindowsPython
ReconwaybackurlsFetch all the URLs that the Wayback Machine knows about for a domainurllinuxmacoswindowsGo
ReconfavireconUse favicon.ico to improve your target recon phase. Quickly detect technologies, WAF, exposed panels, known services.faviconlinuxmacoswindowsGo
ReconLepusSubdomain findersubdomainslinuxmacoswindowsPython
ReconSmapa drop-in replacement for Nmap powered by shodan.ioportlinuxmacoswindowsGo
ReconSub404A python tool to check subdomain takeover vulnerabilitysubdomains takeoverlinuxmacoswindowsGo
ReconSubBrutehttps://github.com/TheRook/subbrutesubdomainslinuxmacoswindowsPython
ReconSublist3rFast subdomains enumeration tool for penetration testerssubdomainslinuxmacoswindowsPython
Reconintrigue-coreDiscover Your Attack SurfacelinuxmacoswindowsRuby
Recongithub-endpointsFind endpoints on GitHub.linuxmacoswindowsGo
ReconBugBountyScannerA Bash script and Docker image for Bug Bounty reconnaissance.linuxmacoswindowsShell
ReconsubgenA really simple utility to concate wordlists to a domain name - to pipe into your favourite resolver!subdomainslinuxmacoswindowsGo
ReconPhotonIncredibly fast crawler designed for OSINT.osint crawllinuxmacoswindowsPython
ReconSilverMass scan IPs for vulnerable servicesportlinuxmacoswindowsPython
ReconsubjackSubdomain Takeover tool written in Gosubdomains takeoverlinuxmacoswindowsGo
ReconnaabuA fast port scanner written in go with focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentestsportscanlinuxmacoswindowsGo
ReconzdnsFast CLI DNS Lookup TooldnslinuxmacoswindowsGo
ReconSubOverA Powerful Subdomain Takeover Toolsubdomains takeoverlinuxmacoswindowsGo
ReconhaktrailsGolang client for querying SecurityTrails API datalinuxmacoswindowsGo
Recondnsxdnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.dnslinuxmacoswindowsGo
ReconShodanWorld's first search engine for Internet-connected devicesosintlinuxmacoswindows
ReconparamethThis tool can be used to brute discover GET and POST parameterslinuxmacoswindowsPython
ReconHunt3rMade your bugbounty subdomains reconnaissance easier with Hunt3r the web application reconnaissance frameworklinuxmacoswindowsRuby
ReconshosubgoSmall tool to Grab subdomains using Shodan api.subdomainslinuxmacoswindowsGo
Reconscilla🏴‍☠️ Information Gathering tool 🏴‍☠️ dns/subdomain/port enumerationsubdomains dns portlinuxmacoswindowsGo
ReconfindomainThe fastest and cross-platform subdomain enumerator, do not waste your time.subdomainslinuxmacoswindowsRust
ReconhakrawlerSimple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web applicationcrawllinuxmacoswindowsGo
Recon3klConAutomation Recon tool which works with Large & Medium scopes. It performs more than 20 tasks and gets back all the results in separated files.linuxmacoswindowsPython
ReconsubzySubdomain takeover vulnerability checkersubdomains takeoverlinuxmacoswindowsGo
ReconlazyreconThis script is intended to automate your reconnaissance process in an organized fashionlinuxmacoswindowsShell
Reconchaos-clientGo client to communicate with Chaos DNS API.linuxmacoswindowsGo
ReconFavFreakMaking Favicon.ico based Recon Great again !linuxmacoswindowsPython
ReconaquatoneA Tool for Domain FlyoversdomainlinuxmacoswindowsGo
ReconParamSpiderMining parameters from dark corners of Web ArchivesparamlinuxmacoswindowsPython
ReconcariddiTake a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and morecrawllinuxmacoswindowsGo
RecongobusterDirectory/File, DNS and VHost busting tool written in GosubdomainslinuxmacoswindowsGo
ReconOneForAllOneForAll是一款功能强大的子域收集工具linuxmacoswindowsPython
Reconurlhuntera recon tool that allows searching on URLs that are exposed via shortener servicesurllinuxmacoswindowsGo
RecongitrobReconnaissance tool for GitHub organizationslinuxmacoswindowsGo
ReconParthHeuristic Vulnerable Parameter ScannerparamlinuxmacoswindowsPython
RecondnsvalidatorMaintains a list of IPv4 DNS servers by verifying them against baseline servers, and ensuring accurate responses.dnslinuxmacoswindowsPython
Reconurodeclutters url lists for crawling/pentestingurllinuxmacoswindowsPython
ReconkatanaA next-generation crawling and spidering framework.crawllinuxmacoswindowsGo
ReconJSFScan.shAutomation for javascript recon in bug bounty.js-analysislinuxmacoswindowsShell
RecongauFetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.urllinuxmacoswindowsGo
ReconBLUTODNS Analysis TooldnslinuxmacoswindowsPython
ReconrenginereNgine is an automated reconnaissance framework meant for gathering information during penetration testing of web applications. reNgine has customizable scan engines, which can be used to scan the websites, endpoints, and gather information.linuxmacoswindowsJavaScript
RecondirsearchWeb path scannerlinuxmacoswindowsPython
Recongowitness🔍 gowitness - a golang, web screenshot utility using Chrome HeadlesslinuxmacoswindowsGo
ReconsubjsFetches javascript file from a list of URLS or subdomains.url subdomainslinuxmacoswindowsGo
ReconSudomysubdomain enumeration tool to collect subdomains and analyzing domainssubdomainslinuxmacoswindowsShell
Reconhttpxhttpx is a fast and multi-purpose HTTP toolkit allow to run multiple probers using retryablehttp library, it is designed to maintain the result reliability with increased threads.urllinuxmacoswindowsGo
Reconcc.pyExtracting URLs of a specific target based on the results of "commoncrawl.org"urllinuxmacoswindowsPython
ReconreconftwreconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilitieslinuxmacoswindowsShell
ReconshufflednsshuffleDNS is a wrapper around massdns written in go that allows you to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard handling and easy input-output support.dnslinuxmacoswindowsGo
RecondnsprobeDNSProb (beta) is a tool built on top of retryabledns that allows you to perform multiple dns queries of your choice with a list of user supplied resolvers.dnslinuxmacoswindowsGo
ReconhtcatParallel and Pipelined HTTP GET UtilitylinuxmacoswindowsGo
Reconsubs_allSubdomain Enumeration Wordlist. 8956437 unique words. Updated.subdomainslinuxmacoswindows
ReconHydraReconAll In One, Fast, Easy Recon ToollinuxmacoswindowsPython
Reconrecon_profileRecon profile (bash profile) for bugbountylinuxmacoswindowsShell
Reconx8Hidden parameters discovery suitelinuxmacoswindowsRust
ReconHostHunterRecon tool for discovering hostnames using OSINT techniques.osintlinuxmacoswindowsPython
ReconSecretFinderSecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript fileslinuxmacoswindowsPython
ReconsubfinderSubfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing.subdomainslinuxmacoswindowsGo
ReconChaos Webactively scan and maintain internet-wide assets' data. enhance research and analyse changes around DNS for better insights.linuxmacoswindows
ReconcrawlergoA powerful browser crawler for web vulnerability scannerscrawllinuxmacoswindowsGo
ReconSecurityTrailsOnline dns / subdomain / recon toolsubdomains onlinelinuxmacoswindows
Reconsn0intSemi-automatic OSINT framework and package managerosintlinuxmacoswindowsRust
ReconhakrevdnsSmall, fast tool for performing reverse DNS lookups en masse.linuxmacoswindowsGo
ReconParamWizardParamWizard is a powerful Python-based tool designed for extracting and identifying URLs with parameters from a specified website.paramlinuxmacoswindowsPython
ReconDNSDumpsterOnline dns recon & research, find & lookup dns recordsdns onlinelinuxmacoswindows
Recongraphw00fGraphQL Server Engine Fingerprinting utilitygraphqllinuxmacoswindowsPython
Recongithub-subdomainsFind subdomains on GitHubsubdomainslinuxmacoswindowsGo
ReconassetfinderFind domains and subdomains related to a given domainsubdomainslinuxmacoswindowsGo
ReconfhcFast HTTP Checker.linuxmacoswindowsRust
FuzzerkiterunnerContextual Content Discovery ToollinuxmacoswindowsGo
FuzzerSSRFireAn automated SSRF finder. Just give the domain name and your server and chillssrflinuxmacosShell
FuzzerppfuzzA fast tool to scan client-side prototype pollution vulnerability written in Rust. 🦀prototypepollution prototype-pollutionlinuxmacoswindowsRust
FuzzerfuzzparamA fast go based param miner to fuzz possible parameters a URL can have.paramlinuxmacoswindowsGo
FuzzerSSTImapAutomatic SSTI detection tool with interactive interfacesstilinuxmacoswindowsPython
FuzzercrlfuzzA fast tool to scan CRLF vulnerability written in GocrlflinuxmacoswindowsShell
FuzzerBruteXAutomatically brute force all services running on a target.linuxmacoswindowsShell
FuzzerSmuggleFuzzA rapid HTTP downgrade smuggling scanner written in Go.smuggle fuzzlinuxmacoswindowsGo
FuzzerSSRFmapAutomatic SSRF fuzzer and exploitation toolssrflinuxmacoswindowsPython
FuzzerBatchQLGraphQL security auditing script with a focus on performing batch GraphQL queries and mutationsgraphqllinuxmacoswindowsPython
Fuzzerc-jwt-crackerJWT brute force cracker written in CjwtlinuxmacoswindowsC
FuzzerhashcatWorld's fastest and most advanced password recovery utilitylinuxmacoswindowsC
Fuzzerjwt-crackerSimple HS256 JWT token brute force crackerjwtlinuxmacoswindowsJavaScript
Fuzzerjwt-hack🔩 jwt-hack is tool for hacking / security testing to JWT. Supported for En/decoding JWT, Generate payload for JWT attack and very fast cracking(dict/brutefoce)jwtlinuxmacoswindowsGo
Fuzzerthc-hydrahydralinuxmacoswindowsC
FuzzerCrackQLCrackQL is a GraphQL password brute-force and fuzzing utility.graphqllinuxmacoswindowsPython
FuzzerheaderpwnA fuzzer for finding anomalies and analyzing how servers respond to different HTTP headersheaderlinuxmacoswindowsGo
FuzzerdotdotpwnDotDotPwn - The Directory Traversal Fuzzerpath-traversallinuxmacoswindowsPerl
FuzzerClairvoyanceObtain GraphQL API schema even if the introspection is disabledgraphqllinuxmacoswindowsPython
FuzzerwfuzzWeb application fuzzerlinuxmacoswindowsPython
FuzzerferoxbusterA fast, simple, recursive content discovery tool written in Rust.linuxmacoswindowsRust
FuzzerParamPamPamThis tool for brute discover GET and POST parameters.param cache-vulnlinuxmacoswindowsPython
FuzzermedusaFastest recursive HTTP fuzzer, like a Ferrari.linuxmacoswindowsGo
FuzzerffufFast web fuzzer written in GolinuxmacoswindowsGo
FuzzerGraphQLmapGraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes.graphqllinuxmacoswindowsPython
Scannerjsprimea javascript static security analysis tooljs-analysislinuxmacoswindowsJavaScript
Scannerweb_cache_poisonweb cache poison - Top 1 web hacking technique of 2019cache-vulnlinuxmacoswindowsShell
Scannerwebsocket-connection-smugglerwebsocket-connection-smugglersmugglelinuxmacoswindowsGo
ScannerOpenRedireXA Fuzzer for OpenRedirect issueslinuxmacoswindowsPython
ScannerXSpearPowerfull XSS Scanning and Parameter analysis tool&gemxsslinuxmacoswindowsRuby
Scannerhttp-request-smugglingHTTP Request Smuggling Detection ToollinuxmacoswindowsPython
ScannerdittoA tool for IDN homograph attacks and detection.linuxmacoswindowsGo
ScannerS3cret ScannerHunting For Secrets Uploaded To Public S3 Bucketss3linuxmacoswindowsPython
ScannerCorsMeCross Origin Resource Sharing MisConfiguration ScannercorslinuxmacoswindowsGo
Scannerws-smugglerWebSocket Connection SmugglersmugglelinuxmacoswindowsGo
Scannerhttp2smuglThis tool helps to detect and exploit HTTP request smuggling in cases it can be achieved via HTTP/2 -> HTTP/1.1 conversion by the frontend server.linuxmacoswindowsGo
Scannerssrf-sheriffA simple SSRF-testing sheriff written in GossrflinuxmacoswindowsGo
ScannerChromium-based-XSS-Taint-TrackingCyclops is a web browser with XSS detection feature, it is chromium-based xss detection that used to find the flows from a source to a sink.xsslinuxmacoswindows
ScannerplutionPrototype pollution scanner using headless chromeprototypepollution prototype-pollutionlinuxmacoswindowsGo
ScannerNoSQLMapAutomated NoSQL database enumeration and web application exploitation tool.nosqlilinuxmacoswindowsPython
Scannerzap-cliA simple tool for interacting with OWASP ZAP from the commandline.linuxmacoswindowszapPython
ScannerHRSHTTP Request Smuggling demonstration Perl script, for variants 1, 2 and 5 in my BlackHat US 2020 paper HTTP Request Smuggling in 2020.linuxmacoswindowsPerl
ScannerConfusedDotnetTool to check for dependency confusion vulnerabilities in NuGet package management systemsdependency-confusionwindowsC#
ScannerdeadlinksHealth checks for your documentation links.broken-linklinuxmacoswindowsPython
ScannerLFISuiteTotally Automatic LFI Exploiter (+ Reverse Shell) and ScannerlinuxmacoswindowsPython
ScannerAWSBucketDumpSecurity Tool to Look For Interesting Files in S3 Bucketss3linuxmacoswindowsPython
Scannerdontgo403Tool to bypass 40X response codes.403linuxmacoswindowsGo
ScannerDSSSDamn Small SQLi ScannersqlilinuxmacoswindowsPython
Scannerh2csmugglerHTTP Request Smuggling Detection ToolsmugglelinuxmacoswindowsGo
ScannernucleiNuclei is a fast tool for configurable targeted scanning based on templates offering massive extensibility and ease of use.linuxmacoswindowsGo
ScannerppmapA scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.prototypepollution prototype-pollutionlinuxmacoswindowsGo
Scannerfindom-xssA fast DOM based XSS vulnerability scanner with simplicity.xsslinuxmacoswindowsShell
Scannercorsair_scanCorsair_scan is a security tool to test Cross-Origin Resource Sharing (CORS).corslinuxmacoswindowsPython
ScannerS3ScannerScan for open AWS S3 buckets and dump the contentss3linuxmacoswindowsPython
ScannerdomdigDOM XSS scanner for Single Page ApplicationsxsslinuxmacoswindowsJavaScript
ScannerFockCacheMinimalized Test Cache Poisoningcache-vulnlinuxmacoswindowsGo
ScannerrapidscanThe Multi-Tool Web Vulnerability Scanner.linuxmacoswindowsPython
ScannernosqliNoSql Injection CLI toolnosqlilinuxmacoswindowsGo
ScannerwpreconHello! Welcome. Wprecon (Wordpress Recon), is a vulnerability recognition tool in CMS Wordpress, 100% developed in Go.linuxmacoswindowsGo
ScannerhinjectHost Header Injection CheckerheaderlinuxmacoswindowsGo
ScannerconfusedTool to check for dependency confusion vulnerabilities in multiple package management systemsdependency-confusionlinuxmacoswindowsGo
ScannerautopoisonerWeb cache poisoning vulnerability scanner.cache-vulnlinuxmacoswindowsPython
ScannercommixAutomated All-in-One OS Command Injection Exploitation Tool.exploitlinuxmacoswindowsPython
ScannersmugglerSmuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3smugglelinuxmacoswindowsPython
ScannerDeadsniperA fast, specialized dead-link checkerbroken-linklinuxmacoswindowsGo
ScannerDeepVioletTool for introspection of SSL\TLS sessionsssllinuxmacoswindowsJava
Scannergithub-searchTools to perform basic search on GitHub.linuxmacoswindowsJavaScript
ScannerSQLiDetectorSimple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests with 14 payloads and checking for 152 regex patterns for different databases.sqlilinuxmacoswindowsPython
Scannera2svAuto Scanning to SSL VulnerabilityssllinuxmacoswindowsPython
ScannerDOMPurifyDOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:xsslinuxmacoswindowsJavaScript
ScannerdepenfusionA powerful pentesting tool for detecting and exploiting dependency confusion vulnerabilities in Node.js projectsdependency-confusionlinuxmacoswindowsPython
ScannerCorsyCORS Misconfiguration ScannercorslinuxmacoswindowsPython
ScannerarachniWeb Application Security Scanner FrameworklinuxmacoswindowsRuby
Scannerdependency-confusion-scannerThis small repo is meant to scan Github's repositories for potential Dependency confusion vulnerabilities.dependency-confusionlinuxmacoswindowsPython
ScannergitleaksScan git repos (or files) for secrets using regex and entropy 🔑linuxmacoswindowsGo
ScannerpphackThe Most Advanced Client-Side Prototype Pollution Scannerprototypepollution prototype-pollutionlinuxmacoswindowsGo
ScannerheadiCustomisable and automated HTTP header injectionheaderlinuxmacoswindowsGo
ScannerV3n0M-ScannerPopular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulnssqli xss lfi rfilinuxmacoswindowsPython
ScannerxsscrapyXSS/SQLi spider. Give it a URL and it'll test every link it finds for XSS and some SQLi.xsslinuxmacoswindowsPython
ScannertplmapServer-Side Template Injection and Code Injection Detection and Exploitation ToollinuxmacoswindowsPython
ScannersqlmapAutomatic SQL injection and database takeover toolsqlilinuxmacoswindowsPython
ScannerhttprobeTake a list of domains and probe for working HTTP and HTTPS serverslinuxmacoswindowsGo
ScannerPPScanClient Side Prototype Pollution Scannerprototypepollution prototype-pollutionlinuxmacoswindowsJavaScript
ScannerStrikerStriker is an offensive information and vulnerability scanner.linuxmacoswindowsPython
ScannerTaipanWeb application vulnerability scannerlinuxmacoswindows
ScannergitGrabergitGraberlinuxmacoswindowsPython
Scannerscan4allOfficial repository vuls ScanlinuxmacoswindowsGo
ScannerxsserCross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.xsslinuxmacoswindowsPython
ScannerXSStrikeMost advanced XSS scanner.xsslinuxmacoswindowsPython
Scannertestssl.shTesting TLS/SSL encryption anywhere on any portssllinuxmacoswindowsShell
Scannerdalfox🌘🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.xsslinuxmacoswindowsGo
ScannerWeb-Cache-Vulnerability-ScannerWeb Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).cache-vulnlinuxmacoswindowsGo
ScannerDirDarDirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it403linuxmacoswindowsGo
Scannersqlivmassive SQL injection vulnerability scannersqlilinuxmacoswindowsPython
ScannerniktoNikto web server scannerlinuxmacoswindowsPerl
ScannernmapNmap - the Network Mapper. Github mirror of official SVN repository.portscanlinuxmacoswindowsC
Scannerxsinator.comXS-Leak Browser Test SuitelinuxmacoswindowsJavaScript
ScannerOralyzerOpen Redirection AnalyzerlinuxmacoswindowsPython
ScannerDeadFinderFind dead-links (broken links)broken-linklinuxmacoswindowsRuby
ScannerVHostScanA virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.linuxmacoswindowsPython
ScannerwpscanWPScan is a free, for non-commercial use, black box WordPress Vulnerability Scanner written for security professionals and blog maintainers to test the security of their WordPress websites.linuxmacoswindowsRuby
ExploitXSRFProbeThe Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.linuxmacoswindowsPython
ExploitSQLNinjaSqlninja is a tool targeted to exploit SQL Injection vulnerabilities.sqlilinuxmacosPerl
ExploitBaRMIeJava RMI enumeration and attack tool.RMIlinuxmacoswindowsJava
ExploitLiffyLocal file inclusion exploitation toollfilinuxmacoswindowsPython
ExploitGopherusThis tool generates gopher link for exploiting SSRF and gaining RCE in various serversssrflinuxmacoswindowsPython
ExploitxxeservA mini webserver with FTP support for XXE payloadslinuxmacoswindowsGo
ExploitXXExploiterTool to help exploit XXE vulnerabilitiesxxelinuxmacoswindowsTypeScript
ExploitsingularityA DNS rebinding attack framework.linuxmacoswindowsJavaScript
ExploitSn1perAutomated pentest framework for offensive security expertslinuxmacoswindowsShell
ExploitbeefThe Browser Exploitation Framework ProjectxsslinuxmacoswindowsRuby
Exploitof-CORSIdentifying and exploiting CORS misconfigurations on the internal networkscorslinuxmacoswindowsPython
ExploitroprA blazing fast™ multithreaded ROP Gadget finder. ropperroplinuxmacoswindowsRust
ExploitghauriAn advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flawssqlilinuxmacoswindowsPython
ExploittoxssinAn XSS exploitation command-line interface and payload generator.xsslinuxmacoswindowsPython
ExploitXXEinjectorTool for automatic exploitation of XXE vulnerability using direct and different out of band methods.xxelinuxmacoswindowsRuby
UtilsPayloadsAllTheThingsA list of useful payloads and bypass for Web Application Security and Pentest/CTFlinuxmacoswindowsPython
Utilsysoserial.netDeserialization payload generator for a variety of .NET formattersdeserializelinuxmacoswindowsC#
UtilsslackcatCLI utility to post files and command output to slacknotifylinuxmacoswindowsGo
Utilsob_hacky_slackHacky Slack - a bash script that sends beautiful messages to SlacknotifylinuxmacoswindowsShell
UtilsbountyplzAutomated security reporting from markdown templates (HackerOne and Bugcrowd are currently the platforms supported)reportlinuxmacoswindowsShell
UtilsburlA Broken-URL CheckerurllinuxmacoswindowsGo
Utilsmissing-cve-nuclei-templatesWeekly updated list of missing CVEs in nuclei templates official repositorynuclei-templateslinuxmacoswindowsTxt
Utilsgee🏵 Gee is tool of stdin to each files and stdout. It is similar to the tee command, but there are more functions for convenience. In addition, it was written as golinuxmacoswindowsGo
UtilsSequenceDiagramOnline tool for creating UML sequence diagramsonlinelinuxmacoswindows
UtilsgotestwafAn open-source project in Golang to test different web application firewalls (WAF) for detection logic and bypasseslinuxmacoswindowsGo
UtilsgronMake JSON greppable!jsonlinuxmacoswindowsGo
UtilsanewA tool for adding new lines to files, skipping duplicateslinuxmacoswindowsGo
UtilsquickjackQuickjack is a point-and-click tool for intuitively producing advanced clickjacking and frame slicing attacks.linuxmacoswindowsJavaScript
UtilsIntruderPayloadslinuxmacoswindowsburpBlitzBasic
UtilsxlessThe Serverless Blind XSS Appxss blind-xsslinuxmacoswindowsJavaScript
Utilspwncatpwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully scriptable with Python (PSE)linuxmacoswindowsShell
UtilsAssetnote WordlistsAutomated & Manual Wordlists provided by Assetnotewordlist documentslinuxmacoswindowsCSS
UtilsCSP EvaluatorOnline CSP Evaluator from googlecsplinuxmacoswindows
Utilsreverse-shell-generatorHosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs)payloadlinuxmacoswindowsJavaScript
UtilsezXSSezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.xss blind-xsslinuxmacoswindowsPHP
UtilsAtlasQuick SQLMap Tamper SuggestersqlilinuxmacoswindowsPython
Utilspentest-toolsCustom pentesting toolslinuxmacoswindowsPython
UtilsGf-PatternsGF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic) parameters greplinuxmacoswindows
UtilsysoserialA proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.deserializelinuxmacoswindowsJava
UtilsGadgetProbeProbe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.deserializelinuxmacoswindowsJava
Utilssecurity-research-pocsProof-of-concept codes created as part of security research done by Google Security Team.linuxmacoswindowsC++
Utilscan-i-take-over-xyz"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.linuxmacoswindows
Utilsweaponised-XSS-payloadsXSS payloads designed to turn alert(1) into P1xss documentslinuxmacoswindowsJavaScript
UtilswuzzInteractive cli tool for HTTP inspectionhttplinuxmacoswindowsGo
UtilsdnsobserverA handy DNS service written in Go to aid in the detection of several types of blind vulnerabilities. It monitors a pentester's server for out-of-band DNS interactions and sends lookup notifications via Slack.oast dnslinuxmacoswindowsGo
UtilsfffThe Fairly Fast Fetcher. Requests a bunch of URLs provided on stdin fairly quickly.urllinuxmacoswindowsGo
UtilsmubengAn incredibly fast proxy checker & IP rotator with ease.linuxmacoswindowsGo
UtilshoppscotchOpen source API development ecosystemhttplinuxmacoswindowsTypeScript
UtilsblistenerBlind-XSS listener with payloadsxss blind-xsslinuxmacoswindowsGo
Utilshttpiemodern, user-friendly command-line HTTP client for the API erahttplinuxmacoswindowsPython
UtilstiscriptsTurbo Intruder ScriptslinuxmacoswindowsPython
UtilsqsreplaceAccept URLs on stdin, replace all query string values with a user-supplied valuelinuxmacoswindowsGo
Utils230-OOBAn Out-of-Band XXE server for retrieving file contents over FTP.xxelinuxmacoswindowsPython
Utilsbruteforce-listsSome files for bruteforcing certain things.wordlist documentslinuxmacoswindowsTxt
UtilsgxssBlind XSS service alerting over slack or emailxss blind-xsslinuxmacoswindowsGo
UtilseoycEncoding Only Your ChoicesencodelinuxmacoswindowsCrystal
UtilsboastThe BOAST Outpost for AppSec Testing (v0.1.0)oastlinuxmacoswindowsGo
UtilsEmissarySend notifications on different channels such as Slack, Telegram, Discord etc.notifylinuxmacoswindowsGo
UtilsdocemUility to embed XXE and XSS payloads in docx,odt,pptx,etc (OXML_XEE on steroids)xxe xsslinuxmacoswindowsPython
UtilscurlA command line tool and library for transferring data with URL syntax, supporting HTTP, HTTPS, FTP, FTPS, GOPHER, TFTP, SCP, SFTP, SMB, TELNET, DICT, LDAP, LDAPS, MQTT, FILE, IMAP, SMTP, POP3, RTSP and RTMP. libcurl offers a myriad of powerful featureslinuxmacoswindowsC
UtilshacksA collection of hacks and one-off scriptslinuxmacoswindowsGo
UtilsCyberChefThe Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysislinuxmacoswindowsJavaScript
UtilshbxssSecurity test tool for Blind XSSxss blind-xsslinuxmacoswindowsRuby
UtilsXSS-CatcherFind blind XSS but why not gather data while you're at it.xss blind-xsslinuxmacoswindowsPython
UtilsurlgrabA golang utility to spider through a website searching for additional links.urllinuxmacoswindowsGo
UtilsSecListsSecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place.wordlist documentslinuxmacoswindowsTxt
UtilshakcheckurlTakes a list of URLs and returns their HTTP response codeslinuxmacoswindowsGo
UtilsurlprobeUrls status code & content length checkerurllinuxmacoswindowsGo
Utilsxss-cheatsheet-dataThis repository contains all the XSS cheatsheet data to allow contributions from the community.xsslinuxmacoswindows
Utilsgraphql-voyager🛰️ Represent any GraphQL API as an interactive graphgraphqllinuxmacoswindowsTypeScript
UtilsClipboardAn external brain that remembers anything, anytime, anywhere.clipboardlinuxmacoswindowsC++
Utilsnuclei-templatesCommunity curated list of templates for the nuclei engine to find security vulnerabilities.nuclei-templateslinuxmacoswindowsGo
UtilsRedcloudAutomated Red Team Infrastructure deployement using DockerinfralinuxmacoswindowsPython
UtilsunfurlPull out bits of URLs provided on stdinurllinuxmacoswindowsGo
Utilsxssor2XSS'OR - Hack with JavaScript.xsslinuxmacoswindowsJavaScript
UtilsREcollapseREcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applicationsfuzzlinuxmacoswindowsPython
UtilsSerializationDumperA tool to dump Java serialization streams in a more human readable form.deserializelinuxmacoswindowsJava
UtilscentCommunity edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place.nuclei-templateslinuxmacoswindowsGo
Utilscf-checkCloudflare Checker written in GolinuxmacoswindowsGo
UtilsBug-Bounty-ToolzBBT - Bug Bounty ToolslinuxmacoswindowsPython
UtilsZipBombA simple implementation of ZipBomb in PythonzipbomblinuxmacoswindowsPython
UtilsfzfA command-line fuzzy finderlinuxmacoswindowsGo
UtilsgitlsListing git repository from URL/User/OrglinuxmacoswindowsGo
Utilsgithub-regexpBasically a regexp over a GitHub search.linuxmacoswindowsGo
UtilsinteractshAn OOB interaction gathering server and client libraryoastlinuxmacoswindowsGo
UtilsgrexA command-line tool and library for generating regular expressions from user-provided test caseslinuxmacoswindowsRust
Utilszip-bombCreate a ZIPBomb for a given uncompressed size (flat and nested modes).zipbomblinuxmacoswindowsPython
Utilsdifftastica structural diff that understands syntaxdifflinuxmacoswindowsRust
UtilsPhoenixhahwul's online toolsonlinelinuxmacoswindowsJavaScript
UtilsdsieveFilter and enrich a list of subdomains by levelsubdomainslinuxmacoswindowsGo
UtilshttptoolkitHTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Maclinuxmacoswindows
UtilsbatA cat(1) clone with wings.linuxmacoswindowsRust
UtilsjsfuckWrite any JavaScript with 6 CharactersxsslinuxmacoswindowsJavaScript
UtilsautochromeThis tool downloads, installs, and configures a shiny new copy of Chromium.linuxmacoswindowsHTML
UtilsFindsploitFind exploits in local and online databases instantlyexploitlinuxmacoswindowsShell
UtilsgodeclutterDeclutters URLs in a fast and flexible way, for improving input for web hacking automations such as crawlers and vulnerability scans.urllinuxmacoswindowsGo
UtilsTukTukTool for catching and logging different types of requests.oastlinuxmacoswindowsGo
UtilshurlHurl, run and test HTTP requests.linuxmacoswindowsRust
UtilspetSimple command-line snippet manager, written in Go.linuxmacoswindowsGo
Utilssecurity-crawl-mazeSecurity Crawl Maze is a comprehensive testbed for web security crawlers. It contains pages representing many ways in which one can link resources from a valid HTML document.crawllinuxmacoswindowsHTML
UtilsPoC-in-GitHub📡 PoC auto collect from GitHub. Be careful malware.linuxmacoswindows
UtilsGQLSpectionparses GraphQL introspection schema and generates possible queriesgraphqllinuxmacoswindowsPython
Utilss3reverseThe format of various s3 buckets is convert in one format. for bugbounty and security testing.s3linuxmacoswindowsGo
UtilsgfA wrapper around grep, to help you grep for thingslinuxmacoswindowsGo
UtilsgotatorGotator is a tool to generate DNS wordlists through permutations.linuxmacoswindowsGo
Utilsnuclei-wordfence-cveEvery single day new templates are added to this repo based on updates on Wordfence.comnuclei-templateslinuxmacoswindowsPython
UtilswssipApplication for capturing, modifying and sending custom WebSocket data from client to server and vice versa.linuxmacoswindowsJavaScript
UtilsBlacklist3rproject-blacklist3rlinuxmacoswindowsC#
Utilstemplate-generatorA simple variable based template editor using handlebarjs+strapdownjs. The idea is to use variables in markdown based files to easily replace the variables with content. Data is saved temporarily in local storage. PHP is only needed to generate the list of files in the dropdown of templates.linuxmacoswindowsJavaScript
Utilsoxml_xxeA tool for embedding XXE/XML exploits into different filetypeslinuxmacoswindowsRuby
Utilsgrcgeneric colouriserlinuxmacoswindowsPython
Envpentest-envPentest environment deployer (kali linux + targets) using vagrant and chef.pentestlinuxmacoswindowsRuby
EnvGlueApplication Security AutomationlinuxmacoswindowsRuby
EnvCrimsonWeb Application Security Testing automation.linuxmacoswindowsPython

Bookmarklets

TypeNameDescriptionStarTagsBadges

Browser Addons

TypeNameDescriptionStarTagsBadges
ReconWayback MachineHistory of websitelinuxmacoswindowssafari
ReconDotGitAn extension for checking if .git is exposed in visited websiteslinuxmacoswindowsfirefoxchromeJavaScript
UtilsUser-Agent Switcherquick and easy way to switch between user-agents.linuxmacoswindowsfirefox
UtilsDOMLogger++A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.dom xsslinuxmacoswindowsfirefoxchromeJavaScript
UtilsHack-ToolsThe all-in-one Red Team extension for Web Pentester 🛠linuxmacoswindowsfirefoxchromesafariTypeScript
Utilsclear-cacheAdd-on to clear browser cache with a single click or via the F9 key.linuxmacoswindowsfirefoxchromeJavaScript
Utilseval_villainA Firefox Web Extension to improve the discovery of DOM XSS.xsslinuxmacoswindowsfirefoxzapJavaScript
UtilsFirefox Multi-Account ContainersFirefox Multi-Account Containers lets you keep parts of your online life separated into color-coded tabslinuxmacoswindowsfirefoxJavaScript
UtilsMM3 ProxySwitchProxy Switch in Firefox and ChromelinuxmacoswindowsfirefoxchromeJavaScript
Utilscookie-quick-managerAn addon to manage (view, search, create, edit, remove, backup, restore) cookies on Firefox.cookielinuxmacoswindowsfirefoxJavaScript
UtilsZAP Browser ExtensionA browser extension which allows ZAP to interact directly with the browser.browser-recordlinuxmacoswindowsfirefoxchromezapTypeScript
UtilspostMessage-trackerA Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-iconjs-analysislinuxmacoswindowschromeJavaScript
UtilsDark ReaderDark mode to any sitedarkmodelinuxmacoswindowsfirefoxchromeTypeScript
UtilsEdit-This-CookieEditThisCookie is the famous Google Chrome/Chromium extension for editing cookiescookielinuxmacoswindowschromeJavaScript
UtilsPwnFoxFirefox/Burp extension that provide usefull tools for your security audit.linuxmacoswindowsfirefoxburpJavaScript
UtilsDark Reader for SafariDark mode to any sitelinuxmacoswindowssafari
Utilsfirefox-container-proxyAssign a proxy to a Firefox containerlinuxmacoswindowsfirefoxJavaScript
Utilsjsonwebtoken.github.ioJWT En/Decode and VerifyjwtlinuxmacoswindowsJavaScript

Burpsuite, Caido and ZAP Addons

TypeNameDescriptionStarTagsBadges
Reconattack-surface-detector-burpThe Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parametersendpoint url attack-surfacelinuxmacoswindowsburpJava
ReconDr. WatsonDr. Watson is a simple Burp Suite extension that helps find assets, keys, subdomains, IP addresses, and other useful informationparam subdomainslinuxmacoswindowsburpPython
ReconBurpJSLinkFinderjs-analysislinuxmacoswindowsburpPython
ReconBurpSuite-Secret_Finderlinuxmacoswindowsburp
Reconreflected-parametersparamlinuxmacoswindowsburpJava
ReconHUNTIdentifies common parameters vulnerable to certain vulnerability classesparamlinuxmacoswindowszapburpKotlin
Reconattack-surface-detector-zapThe Attack Surface Detector uses static code analyses to identify web app endpoints by parsing routes and identifying parametersendpoint url attack-surfacelinuxmacoswindowszapJava
Reconburp-retire-jsjs-analysislinuxmacoswindowsburpJavaScript
Fuzzerparam-minerParam Minerparam cache-vulnlinuxmacoswindowsburpJava
FuzzerGAPThis is an evolution of the original getAllParams extension for Burp. Not only does it find more potential parameters for you to investigate, but it also finds potential links to try these parameters on.paramlinuxmacoswindowsburpPython
Scannerhttp-request-smugglersmugglelinuxmacoswindowsburpJava
ScannerBurpSuiteHTTPSmugglersmugglelinuxmacoswindowsburpJava
Scannercsp-auditorcsplinuxmacoswindowszapburpJava
ScannerAuthMatrixaaalinuxmacoswindowsburpPython
ScannerAutorizeaaalinuxmacoswindowsburpPython
Scannercollaborator-everywhereoastlinuxmacoswindowsburpJava
utilsNeonmarkerlinuxmacoswindowszapJava
UtilssafecopylinuxmacoswindowsburpJava
utilsowasp-zap-jwt-addonjwtlinuxmacoswindowszapJava
UtilsAuthMatrixAutomated HTTP Request Repeating With Burp SuitelinuxmacoswindowsburpJava
UtilsnotebookNotebook Caido PluginnotelinuxmacoswindowscaidoTypeScript
Utilscommunity-scriptslinuxmacoswindowszapJavaScript
Utilscaidopecaidope - caido pluginlinuxmacoswindowscaidoTypeScript
UtilsHTTPSignaturesA Burp Suite extension implementing the Signing HTTP Messages draft-ietf-httpbis-message-signatures-01 draft.linuxmacoswindowsburpJava
UtilsCaidoReflectorAutomatically look for paramater reflections in the HTTP responsexsslinuxmacoswindowscaidoTypeScript
Utilszap-hudlinuxmacoswindowszapJava
UtilsBurpSuiteLoggerPlusPluslinuxmacoswindowsburpJava
UtilsWeb3 DecoderBurp Extension for Web3web3linuxmacoswindowsburpJava
UtilsargumentinjectionhammerA Burp Extension designed to identify argument injection vulnerabilities.linuxmacoswindowsburpPython
UtilsinqllinuxmacoswindowsburpPython
UtilsknifeA burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅linuxmacoswindowsJava
Utilshttp-script-generatorlinuxmacoswindowszapburpJava
UtilsBurpBountylinuxmacoswindowsburpBlitzBasic
Utilsburp-piperlinuxmacoswindowsburpKotlin
Utilspcap-burpPcap importer for BurplinuxmacoswindowsburpJava
UtilsMap LocalZAP add-on which allows mapping of responses to content of a chosen local file.linuxmacoswindowszapJava
Utilsburp-send-tolinuxmacoswindowsburpJava
UtilsAWSSignerBurp Extension for AWS SigninglinuxmacoswindowsburpJava
UtilsEvenBetterEvenBetter is a frontend Caido plugin that makes the Caido experience even betterencode ssrf darkmodelinuxmacoswindowscaidoTypeScript
UtilsDecoder-ImprovedImproved decoder for Burp SuitelinuxmacoswindowsburpJava
UtilsreflectlinuxmacoswindowszapKotlin
UtilsStepperlinuxmacoswindowsburpJava
UtilsBurpCustomizerBecause just a dark theme wasn't enough!linuxmacoswindowsburpJava
UtilsblackboxprotobufBlackbox protobuf is a Burp Suite extension for decoding and modifying arbitrary protobuf messages without the protobuf type definition.linuxmacoswindowsburpPython
Utilsburp-exporterlinuxmacoswindowsburpPython
UtilsgRPC-Web Pentest SuitegRPC-Pentest-Suite is set of tools for pentesting / hacking gRPC Web (gRPC-Web) applications.gRPC-WebburplinuxmacoswindowsPython
UtilstaboratoroastlinuxmacoswindowsburpJava
UtilsBerserkoBurp Suite extension to perform Kerberos authenticationlinuxmacoswindowsburpJava
Utilsturbo-intruderlinuxmacoswindowsburpKotlin
UtilsfemidalinuxmacoswindowsburpPython
UtilsEvenBetterExtensionsEvenBetterExtensions allows you to quicky install and keep updated Caido extensions.encode ssrf darkmodelinuxmacoswindowscaidoTypeScript

Thanks to (Contributor)

WHW's open-source project and made it with ❤️ if you want contribute this project, please see CONTRIBUTING.md and Pull-Request with cool your contents.