Open-source web app scanner.
Tools for web apps
HTTP/S applications and APIs.
105 tools indexed
Completely ridiculous API (training target).
Benchmark prompt-injection attacks on LLMs.
File-based agent workspace for source-guided whitebox security review
AI-powered OSINT agent with REPL, CLI and MCP server.
Burp extension for parameter discovery.
Autonomous AI agents that run full penetration tests in a sandbox.
Autonomous multi-agent AI penetration testing agent in your terminal
OSINT framework for phone numbers.
Open-source AI agent firewall for MCP and agent egress.
JavaScript deobfuscator.
Full-featured reconnaissance framework.
AI-powered agentic red team framework.
Detect vulnerable JS libraries.
Automatic SSRF fuzzer.
Self-hosted open-source WAF.
API fuzzer from OpenAPI/GraphQL.
The security tester's wordlist collection.
Autonomous AI pentester for web apps and APIs
Hunt usernames across social networks.
DNS rebinding attack framework.
Find a profile across 1000+ networks.
Social-engineering attack framework.
Automated OSINT collection.