Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application. It's a simple, fast and easy to use web crawler designed for easy, quick discovery of endpoints and assets within a web application. It's a great tool for security researchers, penetration testers and developers who want to quickly scan a web application for potential vulnerabilities and security issues. It's a simple, fast and easy to use web crawler designed for easy, quick discovery of endpoints and assets within a web application. It's a great tool for security researchers, penetration testers and developers who want to quickly scan a web application for potential vulnerabilities and security issues. It's a simple, fast and easy to use web crawler designed for easy, quick discovery of endpoints and assets within a web application. It's a great tool for security researchers, penetration testers and developers who want to quickly scan a web application for potential vulnerabilities and security issues.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Collection of penetration testing scripts for AWS with a focus on reconnaissance.
Rip web accessible (distributed) version control systems: SVN, GIT, Mercurial/hg, bzr, ...
Pwndrop is a self-deployable file hosting service for red teamers, allowing easy upload and sharing of payloads over HTTP and WebDAV.
A DNS rebinding attack framework for security researchers and penetration testers.
An open-source penetration testing framework for social engineering with custom attack vectors.
A tool for interacting with the MSBuild API, enabling malicious activities and evading detection.
A proxy aware C2 framework for penetration testing, red teaming, post-exploitation, and lateral movement with modular format and highly configurable payloads.
A cross-platform tool for creating malicious MS Office documents with hidden VBA macros and anti-analysis features.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.