singularity by nccgroup

A DNS rebinding attack framework.

updated at May 25, 2024, 10:01 p.m.

JavaScript

32 +0

976 +1

135 +0

GitHub
mitmproxy by mitmproxy

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

updated at May 25, 2024, 10:21 p.m.

Python

623 +0

34,681 +83

3,913 +5

GitHub
xss-payload-list by payloadbox

🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List

updated at May 25, 2024, 10:24 p.m.

Unknown languages

139 +0

5,739 +33

1,586 +7

GitHub
FOCA by ElevenPaths

Tool to find metadata and hidden information in the documents.

updated at May 25, 2024, 10:45 p.m.

C#

141 +0

2,780 +11

530 +0

GitHub
juice-shop by juice-shop

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

updated at May 25, 2024, 11:38 p.m.

TypeScript

156 +0

9,651 +20

9,526 +49

GitHub
LinkFinder by GerbenJavado

A python script that finds endpoints in JavaScript files

updated at May 26, 2024, 12:19 a.m.

Python

63 +0

3,492 +16

584 +3

GitHub
radare2 by radareorg

UNIX-like reverse engineering framework and command-line toolset

updated at May 26, 2024, 12:29 a.m.

C

483 +0

19,752 +26

2,942 +3

GitHub
xray by evilsocket

XRay is a tool for recon, mapping and OSINT gathering from public networks.

updated at May 26, 2024, 1:24 a.m.

Go

79 +0

2,154 +5

294 +0

GitHub
wfuzz by xmendez

Web application fuzzer

updated at May 26, 2024, 1:44 a.m.

Python

168 +0

5,683 +8

1,332 +0

GitHub
sqlmap by sqlmapproject

Automatic SQL injection and database takeover tool

updated at May 26, 2024, 2:18 a.m.

Python

1,090 -1

30,810 +56

5,557 +3

GitHub
fuzzdb by fuzzdb-project

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

updated at May 26, 2024, 2:24 a.m.

PHP

367 +0

7,994 +9

2,081 +3

GitHub
EyeWitness by RedSiege

EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.

updated at May 26, 2024, 2:34 a.m.

Python

146 -1

4,756 +13

820 +0

GitHub
Sublist3r by aboul3la

Fast subdomains enumeration tool for penetration testers

updated at May 26, 2024, 2:39 a.m.

Python

233 +0

9,341 +23

2,056 +2

GitHub
gitrob by michenriksen

Reconnaissance tool for GitHub organizations

updated at May 26, 2024, 2:40 a.m.

Go

154 +0

5,850 +6

823 +0

GitHub
DOMPurify by cure53

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:

updated at May 26, 2024, 3:11 a.m.

JavaScript

149 +0

13,002 +41

677 +1

GitHub
webshell by tennc

This is a webshell open source project

updated at May 26, 2024, 3:42 a.m.

PHP

489 -1

9,833 +24

5,561 +4

GitHub
nuclei by projectdiscovery

Fast and customizable vulnerability scanner based on simple YAML based DSL.

updated at May 26, 2024, 4:15 a.m.

Go

214 -1

17,553 +69

2,269 +7

GitHub
aquatone by michenriksen

A Tool for Domain Flyovers

updated at May 26, 2024, 4:25 a.m.

Go

135 +0

5,501 +7

864 +0

GitHub
CyberChef by gchq

The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis

updated at May 26, 2024, 5:20 a.m.

JavaScript

376 -1

25,952 +85

2,985 +5

GitHub
H5SC by cure53

HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors

updated at May 26, 2024, 5:32 a.m.

JavaScript

153 +0

2,821 +2

418 +0

GitHub