All resources

Tools

Scanners, crawlers, and probes — grouped by the phase of an assessment.

104 shown
  1. Aktoapi-securityhostedopt-in

    Open-source API-security platform with a large BOLA/IDOR/broken-auth test library, usable as an independent authorization cross-check.

    Open ↗
  2. Amassrecon

    Deep passive subdomain enumeration across many public sources.

    Open ↗
  3. Arjundiscoveryactive

    Discovers hidden HTTP parameters using a bundled (SecLists-upsizable) wordlist.

    Open ↗
  4. assetfinderreconpassive

    Fast passive subdomain discovery drawing on crt.sh, certspotter, hackertarget, threatcrowd and wayback.

    Open ↗
  5. Commercial web vulnerability scanner and proxy, drivable via its REST API for automated active scanning.

    Open ↗
  6. cdncheckreconpassive

    Classifies a host as CDN, WAF or cloud and names the provider.

    Open ↗
  7. CeWLcustom-wordlist-generator

    Custom word-list generator that spiders a target site to build bespoke wordlists for password/discovery attacks; named as a companion collection.

    Open ↗
  8. Commixactiveactive

    Automated command-injection detection and exploitation.

    Open ↗
  9. Corsyactiveactive

    Scans for CORS misconfigurations.

    Open ↗
  10. CRLFuzzactiveactive

    Probes for CRLF injection and HTTP response splitting.

    Open ↗
  11. Dalfoxactiveactive

    XSS scanner for reflected, stored and DOM input surfaces with structured PoC output.

    Open ↗
  12. dirsearchdiscoveryactive

    Web content/path discovery driven by a shared discovery wordlist.

    Open ↗
  13. dnsxreconopt-in

    Fast DNS resolution and record enumeration from ProjectDiscovery.

    Open ↗
  14. EvoMasterapi-securityactiveopt-in

    State-of-the-art REST API fuzzer with a dedicated authorization SECURITY phase that flags access-control faults from two authenticated users.

    Open ↗
  15. feroxbusterdiscoveryactive

    Recursive content discovery that can auto-request backup/source-map variants of every hit.

    Open ↗
  16. ffufdiscoveryactive

    Fast content and parameter fuzzing with soft-404/wildcard auto-calibration.

    Open ↗
  17. garakllm-red-teaming

    LLM vulnerability / red-team scanner (standalone CLI) for probing generative-AI models for jailbreaks, data leakage, and other failure modes.

    Open ↗
  18. gaudiscoverypassive

    Retrieves historical URLs for a domain from public archives.

    Open ↗
  19. Ghauriactiveactive

    Fast automated SQL-injection detection and exploitation, an sqlmap alternative.

    Open ↗
  20. Gobusterdiscoveryactive

    Directory and file brute-forcing with optional backup/source extension probing.

    Open ↗
  21. GoSpiderdiscovery

    Fast web crawler for links, forms and JavaScript.

    Open ↗
  22. Gotatorreconactiveopt-in

    Subdomain permutation generator that emits candidate names to resolve, closing the active-permutation gap passive enumeration misses.

    Open ↗
  23. gowitnessactiveactive

    Headless screenshot capture of web targets.

    Open ↗
  24. GraphQL Copactiveactive

    Purpose-built GraphQL security audit for introspection, field suggestion, batching/DoS and CSRF issues.

    Open ↗
  25. GraphQLerapi-securityactive

    Dependency-aware GraphQL security tester that builds the query/mutation graph and runs two-profile cross-user IDOR/BOLA checks.

    Open ↗
  26. graphw00fpassivepassive

    Fingerprints the GraphQL engine behind an endpoint.

    Open ↗
  27. H2SpaceXrace-conditionsactive

    HTTP/2 single-packet-attack library for testing race conditions and limit-overrun (TOCTOU) flaws in single-use state-changing actions.

    Open ↗
  28. Hadrianapi-securityactive

    Praetorian's headless OWASP-API authorization scanner covering BOLA, BFLA, OTP-brute/no-rate-limit ATO and mass-assignment with setup-attack-verify proof.

    Open ↗
  29. hakrawlerdiscovery

    Fast crawler for links, forms and JavaScript endpoints.

    Open ↗
  30. httpxrecon

    HTTP prober for live-host, status, title and technology detection.

    Open ↗
  31. THC-Hydraactiveactivehigh-riskopt-in

    Network login brute-forcer (THC-Hydra) for many protocols.

    Open ↗
  32. Interactshvalidationopt-in

    Out-of-band interaction client for detecting blind SSRF/RCE/SQLi/XXE via callbacks.

    Open ↗
  33. Jaelesactiveactiveopt-in

    Rule-based (YAML-signature) active web-vulnerability scanner complementing nuclei.

    Open ↗
  34. JSFScan.shjavascript-recon

    Automation script for JavaScript reconnaissance — pulls JS files and extracts endpoints, parameters, and secrets as a first-class endpoint-discovery pipeline.

    Open ↗
  35. jwt_toolactiveactive

    Inspects JWTs and tests for authorization weaknesses.

    Open ↗
  36. Katanadiscovery

    JS-aware crawler that parses linked JS bundles for URLs and routes.

    Open ↗
  37. LinkFinderdiscovery

    Extracts API endpoints from JavaScript files.

    Open ↗
  38. masscanreconactive

    Mass, high-speed port scanner (typically requires root).

    Open ↗
  39. naabureconactive

    Fast SYN/CONNECT port discovery from ProjectDiscovery.

    Open ↗
  40. Niktoactiveactive

    Checks web servers for misconfigurations and known issues.

    Open ↗
  41. Nmapreconactive

    Port, service and TLS scanning of a target host.

    Open ↗
  42. NoSQLMapactiveactive

    Probes for NoSQL (MongoDB/Redis) injection.

    Open ↗
  43. Nucleipassivepassive

    Fast, high-value template scan for exposures, misconfigurations, takeovers and default logins.

    Open ↗
  44. OWASP ZAPscanningactive

    Free OWASP DAST engine: spider, active scan, OpenAPI import and an access-control add-on for authorization testing.

    Open ↗
  45. OWASP ZAP (Zed Attack Proxy)dast/web-app-scanner

    Open-source web-application security scanner and intercepting proxy with a large add-on marketplace (active/passive scan rules, AJAX/client spider, auth helper, automation framework, GraphQL/SOAP, SARIF reporting).

    Open ↗
  46. ParamSpiderdiscoverypassive

    Passively mines parameterized URLs for a domain from web-archive data.

    Open ↗
  47. retire.jspassivepassive

    Detects vulnerable JavaScript libraries in a target.

    Open ↗
  48. Schemathesisactiveactive

    Property-based API testing from an OpenAPI/GraphQL spec, finding schema violations, 500s and missing-auth operations.

    Open ↗
  49. SpiderFootreconopt-in

    Deep OSINT automation (200+ modules) for subdomains, hosts, leaks and exposure.

    Open ↗
  50. sqlmapactiveactive

    Automated SQL-injection detection and exploitation.

    Open ↗
  51. sslscanpassivepassive

    Audits TLS protocols, ciphers and certificates.

    Open ↗
  52. subfinderreconpassive

    Passive subdomain enumeration across 40+ sources.

    Open ↗
  53. Subzyrecon

    Subdomain-takeover checker matching dangling records against takeover fingerprints.

    Open ↗
  54. testssl.shpassivepassive

    Deep TLS configuration and vulnerability testing.

    Open ↗
  55. theHarvesterpassiveopt-inpassive

    Passive OSINT gathering of emails, subdomains and hosts from keyless public sources.

    Open ↗
  56. tlsxreconpassive

    Fast TLS/certificate data gathering (SANs, versions, ciphers) for host expansion and recon.

    Open ↗
  57. tplmapactiveactive

    Probes for server-side template injection (SSTI).

    Open ↗
  58. uncoverreconopt-in

    Discovers exposed hosts and assets across Shodan, Censys, FOFA and Quake.

    Open ↗
  59. wafw00frecon

    Fingerprints and identifies web application firewalls.

    Open ↗
  60. waybackurlsdiscoverypassive

    Fetches historical URLs for a domain from the Wayback Machine.

    Open ↗
  61. WhatWebrecon

    Technology-stack fingerprinting for web applications.

    Open ↗
  62. WPScanactiveactive

    WordPress vulnerability scanner for plugins, themes and users.

    Open ↗
  63. x8discoveryactive

    Fast Rust-based hidden-parameter discovery, complementing arjun.

    Open ↗
  64. XSStrikeactiveactive

    Advanced XSS detection with WAF-aware payloads.

    Open ↗
  65. XSRFProbedast/web-app-scanneractivelicence

    A Python CSRF audit toolkit that crawls a target web app and runs 25+ checks for anti-CSRF token weaknesses, referer/origin validation bypasses and SameSite cookie issues, generating exploitable PoC payloads and JSON reports. GPLv3, v3.0.0, actively maintained.

    Open ↗
  66. Unredacterredaction-recoverydual-use

    A Bishop Fox tool that recovers text hidden behind pixelation-based redaction by matching candidate characters against the pixelated block, demonstrating that pixelation is an unsafe redaction technique.

    Open ↗
  67. de4pyreverse-engineeringdual-uselicence

    A Python deobfuscator and analysis toolkit for malware analysts and reverse engineers, featuring an LLM-assisted deobfuscation engine (via Ollama), legacy deobfuscators (Jawbreaker, BlankOBF), a packer/metadata analyzer, process monitoring, and a PySide6 GUI. Licensed CC BY-NC 4.0 (non-commercial).

    Open ↗
  68. ShadowHoundreconactivedual-use

    A PowerShell-based alternative to SharpHound for Active Directory enumeration, offering an AD-module path (ADWS) and a direct-LDAP DirectorySearcher path to collect users, groups, computers, and certificates. Output converts to BloodHound via BofHound; designed to reduce detection by avoiding known-malicious binaries.

    Open ↗
  69. ShareFiltratoractiveactivedual-usehigh-risk

    A Python CLI that uses the SharePoint search API to discover and bulk-download files across SharePoint/OneDrive in an M365 tenant, targeting documents exposed by over-permissive sharing that may contain credentials or secrets. Uses authenticated browser session cookies and ships preset queries (Snaffpoint, Credentials).

    Open ↗
  70. LLMartllm-red-teamingdual-use

    Intel Labs' LLM adversarial-robustness toolkit built on PyTorch/Hugging Face, implementing discrete-optimization attacks (notably GCG) and soft-prompt/adversarial-suffix optimization to red-team text LLMs, VLMs, and diffusion models at scale, with AdvBench/HarmBench dataset integrations and CLI/programmatic interfaces.

    Open ↗
  71. Fast Google Dorks Scanreconpassivedual-use

    An automated bash tool that runs a large set of Google dork search queries against a target domain to surface admin panels, widely-exposed file types and locations, and potential path-traversal exposures. Runs directly on Linux/Kali or via Docker, takes only a domain name as input, and supports an optional request proxy.

    Open ↗
  72. GraphSpycloudactivehigh-risk

    A browser-based tool for authorized post-compromise operations against Microsoft 365 and Entra ID: it stores and switches between access/refresh tokens and Primary Refresh Tokens, runs device-code flows, browses OneDrive/SharePoint/Outlook/Teams data, enumerates users and roles, and issues arbitrary Microsoft Graph requests. It also supports adding MFA methods (TOTP, FIDO, phone) for account persistence.

    Open ↗
  73. Pacucloudactivehigh-risk

    An open-source AWS exploitation framework by Rhino Security Labs with a modular architecture for enumeration, privilege escalation, IAM user backdooring, Lambda exploitation, lateral movement, data exfiltration, and log manipulation. It tracks enumerated data in a local SQLite database and logs commands for audit trails.

    Open ↗
  74. AzureHoundcloudactivelicence

    SpecterOps's Go data collector that enumerates Microsoft Azure/Entra tenant data and formats it for BloodHound to map attack paths and privilege-escalation routes. It supports multiple auth methods (username/password, JWT, refresh tokens, Azure CLI), runs as a CLI or persistent service, and ships cross-platform binaries.

    Open ↗
  75. BurpAPISecuritySuiteapi-securityactive

    A Burp Suite extension for API security testing that auto-captures and normalizes API traffic, groups endpoints, and generates fuzzing campaigns covering OWASP API Top 10 issues (BOLA/IDOR, SQLi, XSS, NoSQLi, XXE, JWT abuse, GraphQL abuse, race conditions). It exports to Burp Intruder/Turbo Intruder, Nuclei, and external tools (SQLMap, Dalfox, HTTPX, Katana, FFUF), and is actively maintained (v1.4.15, MIT).

    Open ↗
  76. GraphRunnerpost-exploitationactivehigh-riskdual-use

    A PowerShell post-exploitation toolset for interacting with the Microsoft Graph API after obtaining authenticated access to an Azure AD / M365 account. Provides reconnaissance, persistence, and pillaging modules: email/SharePoint/OneDrive/Teams search and export, malicious app deployment, consent-grant OAuth attacks, security-group cloning, and token refresh, with a browser-based GUI and no third-party dependencies.

    Open ↗
  77. h1statsreconpassiveopt-in

    A Python3 scraper that pulls data from HackerOne's GraphQL API to compile bug-bounty program statistics into a sortable CSV, extracting 23+ data points per program (bounty ranges, response/resolution times, total payouts, report volume, program age). Scrapes public programs by default and supports authenticated access to private programs via session cookie, aiding target selection.

    Open ↗
  78. ROADtoolsreconactive

    A Python framework for exploring and attacking Azure AD / Entra ID. Comprises ROADlib (auth/DB library auto-generated from Azure AD API metadata), ROADrecon (async dump of the full Azure AD graph into a queryable database with an Angular web UI), and roadtx (token exchange supporting authentication flows, device registration, and PRT operations).

    Open ↗
  79. Hettyintercepting-proxyactive

    An open-source HTTP toolkit for security research and bug bounty positioned as a Burp Suite alternative. Provides a machine-in-the-middle HTTP proxy with request logging and advanced search, request interception/manipulation, an HTTP client for crafting and replaying requests, scope management, and project-based storage, all driven through a web-based admin interface.

    Open ↗
  80. AI Vuln Scannerdast/web-app-scanneractivecloud cost

    A security research CLI that automates web-application vulnerability scanning with OWASP ZAP (spider + active attack) and uses the Anthropic Claude API to analyze findings and generate Markdown remediation reports. Ships an intentionally vulnerable Flask app as a safe test target.

    Open ↗
  81. XSSerdast/web-app-scanneractivehigh-riskdual-uselicence

    XSSer (Cross Site Scripter) is an automated framework to detect, exploit and report XSS vulnerabilities in web apps, shipping 1,500+ attack vectors with a context-aware validation engine, WAF bypassers and encoding evasion, injection across GET/POST params, cookies and DOM, and PDF/XML/JSON reporting. Python 3 with CLI and GTK GUI.

    Open ↗
  82. g0 (Guard0)llm-red-teamingactivedual-use

    Open-source AI agent security assessment tool that scans AI/MCP codebases with rule-based static analysis (A–F grading) and runs 3,900+ adversarial payloads for red-team testing against live agents. Also does MCP supply-chain discovery, AI-BOM generation (CycloneDX), and proxy-based runtime enforcement.

    Open ↗
  83. github-searchreconactivedual-use

    Collection of Bash/Python/PHP scripts for reconnaissance against GitHub: credential/secret discovery, user and employee enumeration, dorking, subdomain enumeration, and repository/endpoint extraction. Authored by bug-bounty researcher gwen001.

    Open ↗
  84. keyhacks.shvalidationactivedual-use

    Bash tool that checks the validity of leaked API keys and tokens across 50+ services (AWS, Azure, GCP, Slack, Stripe, GitHub, etc.) by issuing test requests. Useful for triaging secrets found during authorized assessments.

    Open ↗
  85. pentest-tools (gwen001)activeactivedual-use

    Collection of ~60 custom Bash/Python/PHP utilities for quick pentest tasks: DNS enumeration and zone transfers, port scanning and ping sweeps, subdomain discovery via certificate transparency, web vulnerability checks (XSS, CORS, CRLF, SSRF, open redirect), and OSINT (Shodan, dorking). ~3.3k stars.

    Open ↗
  86. Hereticllm-red-teamingdual-usehigh-risklicence

    Heretic automatically removes safety alignment ("abliteration") from transformer language models by orthogonalizing components against identified refusal directions, using an optimizer that minimizes KL divergence on benign prompts to preserve general capability.

    Open ↗
  87. Phoenix Scopereconpassive

    A microservice application that aggregates bug bounty program scope data across HackerOne, Bugcrowd, Intigriti and YesWeHack, exposing APIs and dashboards with scope-change alerts and asset enumeration to help researchers track in-scope targets.

    Open ↗
  88. Monkey365cloud-securitypassive

    An open-source PowerShell security assessment framework for Microsoft 365, Azure, and Entra ID that identifies misconfigurations and evaluates cloud posture against CIS benchmarks. Covers workloads like Exchange Online, SharePoint, Teams and Purview, supports multiple auth methods and national clouds, and exports HTML/JSON/CSV reports.

    Open ↗
  89. Custom AI Agent (Burp)dast/web-app-scanneractivedual-use

    A Burp Suite extension (formerly Burp AI Agent) that integrates AI into web security testing: connects to 11 AI providers (Ollama, Claude, Gemini, OpenAI-compatible), exposes up to 59 MCP tools for external AI clients to drive Burp, includes passive/active scanners covering 62 vulnerability classes, and offers privacy modes with host anonymization and AES-256-GCM credential storage.

    Open ↗
  90. promptmap2llm-red-teamingactivedual-use

    promptmap2 is an automated vulnerability scanner for custom LLM applications that runs prompt-injection attacks against a target (white-box with known system prompt, or black-box HTTP endpoint). It uses a dual-LLM setup where a controller LLM judges whether attacks succeeded, with 50+ pre-built rules across categories like prompt stealing, jailbreak, and harmful-content generation; supports OpenAI, Anthropic, Gemini, Grok, and Ollama models.

    Open ↗
  91. waymorepassivepassive

    A reconnaissance tool that discovers archived URLs and content for a target domain by aggregating seven historical sources (Wayback Machine, Common Crawl, AlienVault OTX, URLScan, VirusTotal, GhostArchive, Intelligence X). It can also download the archived responses so they can be searched for additional links, developer comments, and hidden parameters, with filtering by status code, MIME type, keyword, and date range.

    Open ↗
  92. ZAP Extensionsdast/web-app-scanneractive

    The official add-on repository for OWASP ZAP (Zed Attack Proxy), the open-source dynamic application security testing (DAST) scanner. Contains the modular add-ons (in the addOns directory, built with Gradle) that extend ZAP's active/passive scanning, fuzzing, and web-app testing capabilities; tagged appsec, security, and dast.

    Open ↗
  93. Falcon MCPmcp-server

    MIT-licensed MCP server that gives AI agents access to CrowdStrike Falcon — detections, threat intel, hosts, vulnerabilities, NG-SIEM queries — with a read-only mode and tool allow/deny lists; needs Falcon API credentials.

    Open ↗
  94. Ghidra RPCreverse-engineeringdual-uselicencepassive

    Agent skill plus CLI daemon that keeps Ghidra warm in-process via PyGhidra and returns JSON, so any shell-capable coding assistant can decompile, navigate, annotate, retype, patch and diff binaries without a human in the loop.

    Open ↗
  95. Kimi Thinking Prefillllm-red-teaminglicence

    Client-side SillyTavern extension that rewrites outgoing Kimi/Moonshot chat requests to prefill an assistant reasoning_content turn, so the model continues thinking from user-seeded reasoning without a server patch.

    Open ↗
  96. Skill Security Checkagent-skill-scannerpassive

    Claude Code skill and CLI scanner that audits community skill files across 26 detection categories (prompt injection, exfiltration, permission bypass), with runtime hooks that block dangerous commands and inspect MCP responses.

    Open ↗
  97. agent-chaperoneagent-guardrailcloud costhosted

    Apache-2.0 MCP proxy and Claude Code hooks adapter that screens an agent's tool calls before they run and tool results before it reads them against thresholds in a policy file; log-only by default, needs a TypeSafe API key.

    Open ↗
  98. dsh-jev-interceptoragent-guardrailcloud costhostedopt-in

    MIT-licensed DeepSeek Harness plugin that scores non-read-only tool calls for risk, irreversibility and injection suspicion with TypeSafe's hosted Jev model, escalating or denying only in enforce mode; needs a paid API key.

    Open ↗
  99. is-maliciousscanningcloud costpassive

    MIT-licensed Node CLI that sends a project's selected source, config, build, and CI files to TypeSafe Jev and reports suspicious files and line ranges with probabilities; needs a TypeSafe API key and spends paid input tokens.

    Open ↗
  100. Jev Security Scanagent-skill-scannercloud costhostedopt-inpassive

    MIT-licensed Python CLI and Claude Code/Codex skill that reviews Agent Skills, MCP config and source code for suspicious behavior before installation: offline by default, or nine-category Jev triage with a TypeSafe API key.

    Open ↗
  101. Jev Sentinelagent-guardrailcloud costhosted

    MIT-licensed guard for coding agents (a Pi extension and Claude Code/Codex CLI plugins) that scores tool calls, outputs and replies with TypeSafe's Jev for injection and risk, then allows, asks, or blocks; needs a TypeSafe key.

    Open ↗
  102. jev-edgellm-guardrailcloud cost

    Apache-2.0 fail-open gateway filter for OpenResty, APISIX, Kong, Envoy and JS hosts that scores inbound LLM requests for prompt injection, judging with a paid TypeSafe Jev key, a fine-tuned Laya or an OpenAI-compatible endpoint.

    Open ↗
  103. jev-guardagent-guardrailcloud costhosted

    MIT-licensed hook for seven coding agents and any ACP pair that asks TypeSafe's hosted Jev typed questions about a tool call or its result, then denies, asks or allows it and flags suspected prompt injection; needs a billed key.

    Open ↗
  104. jevkit (Jev Agent Kit)mcp-servercloud costhosted

    MIT-licensed CLI and MCP server giving agents eleven typed-decision tools on TypeSafe's hosted Jev model (route, triage, guard, grep, rank, compact), plus an advisory Claude Code PreToolUse hook; needs a TypeSafe API key.

    Open ↗