
The Yuki Chan is an Automated Penetration Testing tool this tool will auditing all standard security test method for you.
Read MoreRebel framework is a module-based framework which has multiple ...
Read MoreWfuzz is a command line tool written in python. It is used to discover common vulnerabilities in web applications through the method of fuzzing.
Read MoreCross Site "Scripter" (aka XSSer) is an automatic -framework- to detect
Read MoreOffensive Security Tool for Reconnaissance and Information Gathering. Raccoon is a tool made for reconnaissance ...
Read MoreThe OWASP Amass Project is written in go which is much faster than python and it performs network ...
Read MoreSqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers.
Read MoreGraphQL is a query language for APIs and a runtime for fulfilling those queries
Read MoreCorsy is a lightweight program that scans for all known misconfigurations in CORS implementations.
Read MoreSn1per Community Edition is an automated scanner that can be used during a penetration test to enumerate and scan for vulnerabilities.
Read MoreArachni Tool to Identifies vulnerabilities in web application
Read MoreRapidScan is a python based scanning tool used for analyzing vulnerabilities ...
Read MoreIn general, Fuzzing is type of ...
Read MoreOnce cloned we need to enter into the specific directory and type python smod.py in terminal.Then, type help you will be shown ....
Read MoreThis tool  is use to find the default Ip cameras passwords over different vendors. Run the tools with the following commands
Read MoreWAFW00F is a Python tool to help you fingerprint and identify Web Application Firewall (WAF) products.
Read MoreThis tool can scan websites with open .git repositories for Bug Hunting...
Read MoreApkurlgrep Tool helps to extract endpoints from APK files. It used apktool to do the decomplie.
Read MoreAndrowarn is an instrument whose primary point is to identify and caution ...
Read MoreWapiti works as a "black-box" vulnerability scanner, that means it won't study the source code of web applications
Read MoreFfuf – Fuzz Faster U Fool is a great tool used for fuzzing. It has become really popular lately with bug bounty hunters.
Read MoreTurbolist3r is a fork of the sublist3r subdomain discovery tool. In addition to the original OSINT capabilties of sublist3r, turbolist3r ...
Read MoreW9scan is an excellent Plug-in type web vulnerability scanner that scan the code with the 1200+ built-in plugins...
Read MoreFinal Recon follows a modular structure so in future new modules can be added with ease.
Read MoreA pentesting tool designed to assist with finding all sinks and sources of a web application and display these results...
Read MoreScant3r Scans all URLs with multiple HTTP Methods and Tries to look for bugs with basic exploits as XSS - SQLI - RCE - CRLF -SSTI from Headers and URL Parameters
Read MorePhoton is a incredibly fast crawler designed for automating OSINT(Open Source Intelligence). This tool designed with the simple...
Read MoreA complete versatile framework to cover up everything from Reconnaissance...
Read MoreThe OSINT project, the main idea of which is to collect all the possible Google dorks search combinations and to find the information about the specific web-site:
Read MoreInfosploit is an Information Gathering Tool that can be used during a penetration test, OSINTÂ to enumerate Information about...
Read MoreShcheck detects which security headers are enabled on certain websites. It just check headers and print a report about which are enabled and which not.
Read MoreFilebuster is a HTTP fuzzer / content discovery script with loads of features and built to be easy to use and fast! It uses one of the fastest HTTP classes in the world...
Read MoreOneForAll is a powerful chinese subdomain and dns enumeration tool.When considering about subdomain enumeration, amass might be your first and preferable...
Read MoreSecretFinder is a python script to discover sensitive data like api keys, access token, authorizations, jwt,..etc in JavaScript(JS) files. It verifies the files with large regular expression.
Read MoreJD-GUI is a standalone graphical utility that displays Java source codes of “.class” files. You can browse the reconstructed source code with the JD-GUI for instant access...
Read MorePompem is an open source tool, designed to automate the search for Exploits and Vulnerability in the most important databases.
Read MoreComplete Automated pentest framework for Servers, Application Layer to Web Security. Tishna is Web Server Security Penetration
Read MoreA plugin-based scanner that aids security researchers in identifying issues with several CMS.
Read MoreLFISuite, an open source local file inclusion scanner and exploiter that is coded in Python. It supports multiple attack points and also has TOR proxy support.
Read MoreDirsearch is Tool that performs bruteforce attack of sensitive directories and files that are found on the websites.
Read MoreWeevely is a web shell designed for post-exploitation purposes that can be extended over the network at runtime.Upload weevely PHP agent to a target web server to get
Read MoreInsider tool is secure code reviewer, which exclusively focused on covering the OWASP Top 10, to make source code analysis to find vulnerabilities right in the source code.
Read MoreSpaghetti is an Open Source web application scanner, it is designed to find various default and insecure files...
Read MoreDex2Jar is an instrument whose primary point is to convert .dex files into jar and smali files. The Dex2jar is mainly used for reverse engineering Android applications.
Read More--xss : Scan Site if vulnerable [Xss] url must be between double citation --sql : Scan Site if vulnerable [Sql] url must be between double citation
Read MoreRVuln:-- A multi-threaded-vulnerability-scanner written in Rust. Automated #Web Vulnerability Scanner.
Read MoreSecurity Tool For Reconnaissance And Information Gathering On A Website
Read MoreSkipfish is a powerful reconnaissance tool that has the ability to carry out security checks on web-based applications.
Read MoreDetective helps to find Sensitive information, files and directories that are not supposed to see.
Read MoreA python script designed to check if the website is vulnerable of clickjacking and creates a poc.Â
Read MoreClassyShark is a standalone binary inspection tool for Android developers/testers.
Read More multiple domain scanning with SQL injection dork by Bing, Google, or Yahoo .
Read MoreTulpar is an open source penetration testing tool that can find web application vulnerabilities.
Read MoreAltair is a Python based tool that does not require any specific packages to be installed as a pre-requisite. The SQLMAP and Lfier tools must be available on the disposal of the tool.
Read MoreXForwardy is a Host Header Injection scanning tool which can detect misconfigurations , where Host Header Injections are potentially possible.
Read MoreNikto is an Open Source (GPL) web server scanner which performs comprehensive tests against web servers for multiple items.
Read MoreXSpear is XSS Scanner tool which is written in ruby gems. It can be useful for detecting the XSS vulnerability with different level of payloads.
Read MoreXCTR is an all in one tools for Information Gathering which can admin panel,page viewer,cms,reverse IP,dork finder,prxoy viewer.
Read MoreBlazy is a modern login page bruteforcer. It has  Easy target selections  Smart form and error detection.
Read MoreScans That You Can Perform Using RED HAWK are Basic Scan ,Site Title NEW ,IP Address ,Web Server Detection IMPROVED ,CMS Detection ,Cloudflare Detection .
Read Morexsssniper is an handy xss discovery tool with mass scanning functionalities.Â
Read MoreGoSpider is a Fast web spider written in Go. It has lot of features to find the subdomains, JS files, AWSÂ details, etc.Â
Read MoreParth is a Heuristic Vulnerable Parameter Scanner. Some HTTP parameter names are commonly associated with one functionality.
Read MoreFinalRecon is a fast and simple python script for web reconnaissance. It follows a modular structure so in future new modules can be added with ease.
Read MoreUniscan is a simple Remote File Include, Local File Include and Remote Command Execution vulnerability scanner.
Read Morekaren is tools for web application vulnerability scanner build in python3
Read MoreA bash script to bypass "403 Forbidden" responses with well-known methods discussed in #bugbountytips
Read MoreWeb Application Vulnerability Scanners are automated tools that scan web applications.
Read MoreWhatWaf is an advanced firewall detection tool which works by detecting a firewall on a web application.
Read MoreA pentesting tool designed to assist with finding all sinks and sources of a web application
Read MoreParamSpider a parameter discovery suite. It finds parameters from web archives of the entered domain
Read MoreNetwork Spoofing is a simple website hacking tool which can scan a website and can also perform attack using this tool.
Read MoreScilla is a information gathering tool (DNS/Subdomain/Port Enumeration).
Read MoreRaccoon is a tool made for reconnaissance and information gathering with an emphasis on simplicity
Read MoreSkull Generate a bunch of malicious pdf files with phone-home functionality.
Read MoreGet exclusive access to our latest Threatsploit Report detailing the most recent and sophisticated cyber attacks. Stay informed and protect your business from emerging threats.