Tool · activeactivedual-use
pentest-tools (gwen001)
Collection of ~60 custom Bash/Python/PHP utilities for quick pentest tasks: DNS enumeration and zone transfers, port scanning and ping sweeps, subdomain discovery via certificate transparency, web vulnerability checks (XSS, CORS, CRLF, SSRF, open redirect), and OSINT (Shodan, dorking). ~3.3k stars.
Use responsibly
Test only systems you own or are explicitly authorized to test. Unauthorized testing is illegal.
Dual-use security content. We link to the upstream project rather than re-hosting ready-to-fire files. Use only in authorized security testing.
More tools
- CommixactiveAutomated command-injection detection and exploitation.
- CorsyactiveScans for CORS misconfigurations.
- CRLFuzzactiveProbes for CRLF injection and HTTP response splitting.
- DalfoxactiveXSS scanner for reflected, stored and DOM input surfaces with structured PoC output.
- GhauriactiveFast automated SQL-injection detection and exploitation, an sqlmap alternative.
- gowitnessactiveHeadless screenshot capture of web targets.