A simple SSRF-testing sheriff written in Go. This tool is designed to test for Server-Side Request Forgery (SSRF) vulnerabilities in web applications. It works by sending HTTP requests to a target URL and analyzing the responses to identify potential SSRF vulnerabilities. The tool is easy to use and provides detailed information about the vulnerabilities it finds.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
A proxy aware C2 framework for penetration testing, red teaming, post-exploitation, and lateral movement with modular format and highly configurable payloads.
A penetration testing framework for identifying and exploiting vulnerabilities.
An AI-powered penetration testing platform that autonomously discovers, exploits, and documents vulnerabilities while generating NIST-compliant reports.
Ebowla is a tool for generating payloads in Python, GO, and PowerShell with support for Reflective DLLs.
A reconnaissance tool that retrieves information from Office 365 and Azure Active Directory using a valid credential.
A payload creation framework designed to bypass Endpoint Detection and Response (EDR) systems.
FOCA is a tool used to find metadata and hidden information in scanned documents, with capabilities to analyze various file types and extract EXIF information.
APT Simulator is a tool for simulating a compromised system on Windows.
A Live CD and Live USB for penetration testing and security assessment
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.