Explore 2989 curated tools and resources
Get weekly cybersecurity updates, straight in your inbox.
Want your tool featured here?
Get maximum visibility with pinned placement
A reconnaissance tool for GitHub organizations
A powerful tool for identifying and exploiting Cross-Site Scripting (XSS) vulnerabilities.
A powerful tool for identifying and exploiting Cross-Site Scripting (XSS) vulnerabilities.
A list of services and how to claim (sub)domains with dangling DNS records.
A list of services and how to claim (sub)domains with dangling DNS records.
A Python library for automating time-based blind SQL injection attacks
A Python-based web application scanner for OSINT and fuzzing OWASP vulnerabilities
A Python-based web application scanner for OSINT and fuzzing OWASP vulnerabilities
A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys.
A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys.
Automatic tool for DNS rebinding-based SSRF attacks
A tool to enumerate S3 buckets for a specific target
A tool to escalate SSRF vulnerabilities on modern cloud environments
A GitHub repository for fuzzing and testing file formats
A tool for bruteforcing subdomains of a given domain
A Burp extension for scanning JavaScript files for endpoint links
A Burp extension for scanning JavaScript files for endpoint links
A tool for security researchers and penetration testers to automate the process of finding sensitive information on a target domain.
A tool for security researchers and penetration testers to automate the process of finding sensitive information on a target domain.
A command-line program for finding secrets and sensitive information in textual data and Git history.
A command-line program for finding secrets and sensitive information in textual data and Git history.
A toolkit for testing, tweaking and cracking JSON Web Tokens
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
Monitors GitHub for leaked secrets
Fast and customizable vulnerability scanner