Template-based vulnerability scanner.
Outils pour web apps
HTTP/S applications and APIs.
118 tools indexed
Adversary emulation for AI agents, LLM apps and MCP servers
Local-first link-analysis and geospatial board for investigations.
In-depth attack surface mapping.
Modern intentionally vulnerable web app.
Automated pentest + vuln scanner.
Open-source web app scanner.
Completely ridiculous API (training target).
Benchmark prompt-injection attacks on LLMs.
File-based agent workspace for source-guided whitebox security review
AI-powered OSINT agent with REPL, CLI and MCP server.
Burp extension for parameter discovery.
Autonomous AI agents that run full penetration tests in a sandbox.
Autonomous multi-agent AI penetration testing agent in your terminal
Human-in-the-loop agentic AI CLI for pentesters and bug hunters
OSINT framework for phone numbers.
Open-source AI agent firewall for MCP and agent egress.
JavaScript deobfuscator.
Full-featured reconnaissance framework.
AI-powered agentic red team framework.
Detect vulnerable JS libraries.
Automatic SSRF fuzzer.
Self-hosted open-source WAF.
API fuzzer from OpenAPI/GraphQL.