LLM vulnerability scanner.
Tools for web apps
HTTP/S applications and APIs.
118 tools indexed
Find leaked secrets via GitHub search.
gori
—Terminal HTTP intercepting proxy and web pentest toolkit.
Check which sites an email address is registered on
Fast HTTP toolkit.
Test and exploit JWT vulnerabilities.
Audit Keycloak configuration for security misconfigurations
Interactive HTTPS proxy.
Red-team prompts, agents and RAGs.
ptai
—AI pentest tool that re-runs every exploit to verify it.
SOCKS proxy through a web shell.
Automated reconnaissance framework for web applications
Automated recon and web vulnerability-scanning framework.
Semi-automatic OSINT framework.
Scan ServiceNow instances for unauthenticated data exposure
Automatic SQL injection and database takeover.
Test TLS/SSL on any port.
E-mail and subdomain harvester.
w3af
—Web application attack and audit framework.
WAF fingerprinting.
Historical URLs from the Wayback Machine.
Java deserialization payload generator.