Scanning & Enumeration Tools

281 tools
BlackWidow
BlackWidow
Free Exploitation Reconnaissance

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

brainstorm
brainstorm
Free Scanning & Enumeration

A smarter web fuzzing tool that combines local LLM models and ffuf to optimize directory and file discovery

brutas
brutas
Free Exploitation Password Attacks

Wordlists handcrafted (and automated) with ♥

bruter
bruter
Open Source Password Attacks Reconnaissance

Bruter is an OSINT tooling, an experiment to build a reconnaissance simple app to have fun 🕵️‍♂️

brutespray
brutespray
Open Source Exploitation Password Attacks

Fast, multi-protocol credential brute-forcer. Parses Nmap, Nessus, and Nexpose output to automatically test default and custom credentials a…

Bug-bounty-Writeups
Bug-bounty-Writeups
Free Scanning & Enumeration

Repository of Bug-Bounty Writeups

Buildware-Tools
Buildware-Tools
Free Reconnaissance Scanning & Enumeration

Buildware-Tools is an all-in-one multitool for security research and automation.

BurpAPISecuritySuite
BurpAPISecuritySuite
Open Source Exploitation Scanning & Enumeration

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration,…

BurpBounty
BurpBounty
Open Source Scanning & Enumeration Web Application

Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the activ…

cache-commander
cache-commander
Open Source Exploitation Scanning & Enumeration

Cache Commander — a TUI and MCP server to explore, audit, and clean developer cache directories. Scan for CVEs, find outdated packages, recl…

CamSniff
CamSniff
Open Source Kali Scanning & Enumeration

Automated IP Camera & Network Video Stream Reconnaissance Toolkit

cazador_unr
cazador_unr
Free Exploitation Reconnaissance

[scanner] [TcpListener] [FileMiner] [Subscrabber]…

cbrutekrag
cbrutekrag
Open Source Password Attacks Scanning & Enumeration

Penetration tests on SSH servers using brute force or dictionary attacks. Written in C.

CEH-in-bullet-points
CEH-in-bullet-points
Free Reconnaissance Scanning & Enumeration

💻 Certified ethical hacker summary in bullet points

cervantes
cervantes
Free Exploitation Scanning & Enumeration

Cervantes is an open-source, collaborative platform designed specifically for pentesters and red teams. It serves as a comprehensive managem…

chomtesh
chomtesh
Open Source Reconnaissance Scanning & Enumeration

CHOMTE.SH is a powerful shell script designed to automate reconnaissance tasks during penetration testing. It utilizes various Go-based tool…

ChYing
ChYing
Free Scanning & Enumeration Web Application

承影,愿你在光影之间,找到属于自己的锋芒。开源的类 BurpSuite 应用 ChYing — may you find your own edge between light and shadow. An open-source, BurpSuite-like applicat…

claude-bug-bounty
claude-bug-bounty
Open Source Reconnaissance Scanning & Enumeration

AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Co…

claude-cybersecurity
claude-cybersecurity
Open Source Scanning & Enumeration Web Application

AI-powered cybersecurity code review skill for Claude Code. 8 specialist agents, OWASP 2025, CWE Top 25, MITRE ATT&CK, 11 languages, zero co…

Coercer
Coercer
Open Source Post-Exploitation Scanning & Enumeration

A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.

commix
commix
Free Kali Exploitation Scanning & Enumeration

Automated All-in-One OS Command Injection Exploitation Tool

corptrace
corptrace
Open Source Reconnaissance Scanning & Enumeration

Automate Scoping, OSINT and Recon assessments.

crawlergo
crawlergo
Open Source Scanning & Enumeration

A powerful browser crawler for web vulnerability scanners

crlfuzz
crlfuzz
Open Source Scanning & Enumeration

A fast tool to scan CRLF vulnerability written in Go