All resources
Topic

active

19 resources across 1 kinds

Tools

  1. Commixactive

    Automated command-injection detection and exploitation.

    Open ↗
  2. Corsyactive

    Scans for CORS misconfigurations.

    Open ↗
  3. CRLFuzzactive

    Probes for CRLF injection and HTTP response splitting.

    Open ↗
  4. Dalfoxactive

    XSS scanner for reflected, stored and DOM input surfaces with structured PoC output.

    Open ↗
  5. Ghauriactive

    Fast automated SQL-injection detection and exploitation, an sqlmap alternative.

    Open ↗
  6. gowitnessactive

    Headless screenshot capture of web targets.

    Open ↗
  7. Purpose-built GraphQL security audit for introspection, field suggestion, batching/DoS and CSRF issues.

    Open ↗
  8. THC-Hydraactivehigh-riskopt-in

    Network login brute-forcer (THC-Hydra) for many protocols.

    Open ↗
  9. Jaelesactiveopt-in

    Rule-based (YAML-signature) active web-vulnerability scanner complementing nuclei.

    Open ↗
  10. jwt_toolactive

    Inspects JWTs and tests for authorization weaknesses.

    Open ↗
  11. Niktoactive

    Checks web servers for misconfigurations and known issues.

    Open ↗
  12. NoSQLMapactive

    Probes for NoSQL (MongoDB/Redis) injection.

    Open ↗
  13. Property-based API testing from an OpenAPI/GraphQL spec, finding schema violations, 500s and missing-auth operations.

    Open ↗
  14. sqlmapactive

    Automated SQL-injection detection and exploitation.

    Open ↗
  15. tplmapactive

    Probes for server-side template injection (SSTI).

    Open ↗
  16. WPScanactive

    WordPress vulnerability scanner for plugins, themes and users.

    Open ↗
  17. XSStrikeactive

    Advanced XSS detection with WAF-aware payloads.

    Open ↗
  18. ShareFiltratoractivedual-usehigh-risk

    A Python CLI that uses the SharePoint search API to discover and bulk-download files across SharePoint/OneDrive in an M365 tenant, targeting documents exposed by over-permissive sharing that may contain credentials or secrets. Uses authenticated browser session cookies and ships preset queries (Snaffpoint, Credentials).

    Open ↗
  19. Collection of ~60 custom Bash/Python/PHP utilities for quick pentest tasks: DNS enumeration and zone transfers, port scanning and ping sweeps, subdomain discovery via certificate transparency, web vulnerability checks (XSS, CORS, CRLF, SSRF, open redirect), and OSINT (Shodan, dorking). ~3.3k stars.

    Open ↗