Tool · custom-wordlist-generator
CeWL
Custom word-list generator that spiders a target site to build bespoke wordlists for password/discovery attacks; named as a companion collection.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
More tools
- agent-chaperoneagent-guardrailApache-2.0 MCP proxy and Claude Code hooks adapter that screens an agent's tool calls before they run and tool results before it reads them against thresholds in a policy file; log-only by default, needs a TypeSafe API key.
- AI Vuln Scannerdast/web-app-scannerA security research CLI that automates web-application vulnerability scanning with OWASP ZAP (spider + active attack) and uses the Anthropic Claude API to analyze findings and generate Markdown remediation reports. Ships an intentionally vulnerable Flask app as a safe test target.
- Aktoapi-securityOpen-source API-security platform with a large BOLA/IDOR/broken-auth test library, usable as an independent authorization cross-check.
- AmassreconDeep passive subdomain enumeration across many public sources.
- ArjundiscoveryDiscovers hidden HTTP parameters using a bundled (SecLists-upsizable) wordlist.
- assetfinderreconFast passive subdomain discovery drawing on crt.sh, certspotter, hackertarget, threatcrowd and wayback.