Scanning & Enumeration Tools

281 tools
kimi
kimi
Open Source Reconnaissance Scanning & Enumeration

Attack Surface Discovery tool built on a microservice approach, utilizing multi-threading for fast, internet-scale asset indexing

kitsec-core
kitsec-core
Open Source Exploitation Reconnaissance

kong-loader
kong-loader
Open Source Evasion Exploitation

Using Just In Time (JIT) instruction decryption, this shellcode loader ensures that only the currently executing instruction is visible in m…

L0p4Map
L0p4Map
Open Source Kali Scanning & Enumeration

Professional network monitoring & visualization tool. L0P4Map combines high-speed ARP discovery with full nmap integration and a real-time i…

leaky-paths
leaky-paths
Free Exploitation Password Attacks

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc.…

LFITester
LFITester
Open Source Exploitation Scanning & Enumeration

LFITester is a Python3 program that automates the detection and exploitation of Local File Inclusion (LFI) vulnerabilities on a server.

Libellux-Up-and-Running
Libellux-Up-and-Running
Open Source Scanning & Enumeration

Install open-source software from source to focus on Zero Trust Network principles, enhancing security for existing applications, and deploy…

linWinPwn
linWinPwn
Open Source Exploitation Post-Exploitation

linWinPwn is a bash script that streamlines the use of a number of Active Directory tools

litefuzz
litefuzz
Open Source Exploitation Scanning & Enumeration

A multi-platform fuzzer for poking at userland binaries, network clients and servers

lorsrf
lorsrf
Open Source Scanning & Enumeration Web Application

Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:

Lucille
Lucille
Free Reconnaissance Scanning & Enumeration

Information Gatherer & Webapps Exploiter

lunasec
lunasec
Free Scanning & Enumeration Web Application

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests…

lzr
lzr
Open Source Scanning & Enumeration

LZR quickly detects and fingerprints unexpected services running on unexpected ports.

MalQR.github.io
MalQR.github.io
Open Source Exploitation Scanning & Enumeration

MalQR is a collection of malicious QR Codes and Barcodes you can use to test the security of your scanners.

Masscan
Masscan
Open Source Kali Reconnaissance Scanning & Enumeration

The fastest Internet port scanner. Can scan the entire IPv4 address space in under 6 minutes. Produces output compatible with Nmap.

MassVulScan
MassVulScan
Open Source Scanning & Enumeration

A fast network scanning tool to detect open ports and security vulnerabilities (Compatible with Debian & Red Hat OS)

mcp-security-hub
mcp-security-hub
Open Source Reconnaissance Reverse Engineering

A growing collection of MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.

medusa
medusa
Open Source Reverse Engineering Scanning & Enumeration

AI-first security scanner with 76 analyzers, 9,600+ detection rules, and repo poisoning detection for AI/ML, LLM agents, and MCP servers. Sc…

ms-exchange-version-nse
ms-exchange-version-nse
Open Source Exploitation Scanning & Enumeration

Nmap script to detect a Microsoft Exchange instance version with OWA enabled.

natlas
natlas
Open Source Reconnaissance Scanning & Enumeration

Attack Surface Management since before Attack Surface Management was a thing

Ncat
Ncat
Open Source Kali Post-Exploitation Scanning & Enumeration

Feature-packed reimplementation of Netcat from the Nmap project. Adds SSL/TLS support, connection brokering, and scripting capabilities.

Nebula
Nebula
Free Post-Exploitation Reconnaissance

Nebula is a cloud C2 Framework, which at the moment offers reconnaissance, enumeration, exploitation, post exploitation on AWS, but still wo…

nerva
nerva
Open Source Reconnaissance Scanning & Enumeration

Fast service fingerprinting CLI for 170+ protocols (TCP/UDP/SCTP) - built by Praetorian

Nessus
Nessus
Freemium Scanning & Enumeration

Industry-leading vulnerability scanner with 170,000+ plugins. Identifies vulnerabilities, misconfigurations, default passwords, and complian…