Find the right solution for your security needs without any cost.Explore 2628 curated tools and resources
Want your tool featured here?
Get maximum visibility with pinned placement
A collection of tests for Local File Inclusion (LFI) vulnerabilities using Burp Suite.
A collection of tests for Local File Inclusion (LFI) vulnerabilities using Burp Suite.
Dalfox is a powerful open-source XSS scanner and utility focused on automation.
Dalfox is a powerful open-source XSS scanner and utility focused on automation.
A python tool for discovering endpoints, parameters, and wordlists in a given target
A python tool for discovering endpoints, parameters, and wordlists in a given target
Automated SSRF finder with options for XSS and open redirects
A tool for identifying potential security threats by fetching known URLs and filtering out URLs with open redirection or SSRF parameters.
A tool for identifying potential security threats by fetching known URLs and filtering out URLs with open redirection or SSRF parameters.
Fast passive subdomain enumeration tool
A tool for searching a Git repository for interesting content
A tool to fuzz query strings and identify vulnerabilities
A login cracker that can be used to crack many types of authentication protocols.
A login cracker that can be used to crack many types of authentication protocols.
InQL is a Burp Suite extension for advanced GraphQL testing and vulnerability detection
InQL is a Burp Suite extension for advanced GraphQL testing and vulnerability detection
A reconnaissance tool for GitHub organizations
A powerful tool for identifying and exploiting Cross-Site Scripting (XSS) vulnerabilities.
A powerful tool for identifying and exploiting Cross-Site Scripting (XSS) vulnerabilities.
A list of services and how to claim (sub)domains with dangling DNS records.
A list of services and how to claim (sub)domains with dangling DNS records.
A Python library for automating time-based blind SQL injection attacks
A Python-based web application scanner for OSINT and fuzzing OWASP vulnerabilities
A Python-based web application scanner for OSINT and fuzzing OWASP vulnerabilities
A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys.
A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys.
Automatic tool for DNS rebinding-based SSRF attacks
A tool to enumerate S3 buckets for a specific target
A tool to escalate SSRF vulnerabilities on modern cloud environments