29th December 2020 74


Insider tool is secure code reviewer, which exclusively focused on covering the OWASP Top 10, to make source code analysis to find vulnerabilities right in the source code.

29th December 2020 105


Wfuzz is a command line tool written in python. It is used to discover common vulnerabilities in web applications through the method of fuzzing.

24th December 2020 84

web shell

Weevely is a web shell designed for post-exploitation purposes that can be extended over the network at runtime.Upload weevely PHP agent to a target web server to get

24th December 2020 100


Dirsearch is Tool that performs bruteforce attack of sensitive directories and files that are found on the websites.

24th December 2020 126


LFISuite, an open source local file inclusion scanner and exploiter that is coded in Python. It supports multiple attack points and also has TOR proxy support.

27th November 2020 137

DROOPESCAN-Plugin Based Scanner

A plugin-based scanner that aids security researchers in identifying issues with several CMS.

27th November 2020 120


BlackWidow is a python based web application spider to gather subdomains, URL's, dynamic parameters, email addresses and phone numbers from a target website.

27th November 2020 162


SecretFinder is a python script to discover sensitive data like api keys, access token, authorizations, jwt,..etc in JavaScript(JS) files. It verifies the files with large regular expression.

27th November 2020 165


OneForAll is a powerful chinese subdomain and dns enumeration tool.When considering about subdomain enumeration, amass might be your first and preferable...

27th November 2020 107


Filebuster is a HTTP fuzzer / content discovery script with loads of features and built to be easy to use and fast! It uses one of the fastest HTTP classes in the world...

27th November 2020 114

Security Header Check

Shcheck detects which security headers are enabled on certain websites. It just check headers and print a report about which are enabled and which not.

27th November 2020 106

Infosploit : Information Gathering Tool

Infosploit is an Information Gathering Tool that can be used during a penetration test, OSINT  to enumerate Information about...

27th November 2020 125

Tishna-Automated Pentest Framework

Complete Automated pentest framework for Servers, Application Layer to Web Security. Tishna is Web Server Security Penetration

27th November 2020 117

Pompem-Exploit and Vulnerability Finder

Pompem is an open source tool, designed to automate the search for Exploits and Vulnerability in the most important databases.

27th November 2020 131


JD-GUI is a standalone graphical utility that displays Java source codes of “.class” files. You can browse the reconstructed source code with the JD-GUI for instant access...

20th November 2020 150


The OSINT project, the main idea of which is to collect all the possible Google dorks search combinations and to find the information about the specific web-site:

20th November 2020 116

The TIDoS Framework: The Offensive Web Application Penetration Testing Framework.

A complete versatile framework to cover up everything from Reconnaissance...

20th November 2020 129


jadx is a Command line and GUI tools for produce Java source code from Android Dex and Apk files

20th November 2020 111

Incredibly fast crawler designed for OSINT.

Photon is a incredibly fast crawler designed for automating OSINT(Open Source Intelligence). This tool designed with the simple...

20th November 2020 93

Web Scanner - Exploitation - Information Gathering

20th November 2020 120


AndroBugs Framework is an Android vulnerability analysis system that helps developers or hackers find potential security vulnerabilities