Web Application Tools

462 tools
libinjection-go
libinjection-go
Open Source Exploitation Web Application

libinjection is a Golang port of the libinjection(https://github.com/client9/libinjection)

lit-bb-hack-tools
lit-bb-hack-tools
Open Source Web Application

Little Bug Bounty & Hacking Tools⚔️

llamator
llamator
Free Exploitation Web Application

Red Teaming python-framework for testing chatbots and GenAI systems.

lonkero
lonkero
Free Web Application

Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.

lookyloo
lookyloo
Free Web Application

Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other.

lorsrf
lorsrf
Open Source Scanning & Enumeration Web Application

Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:

lunasec
lunasec
Free Scanning & Enumeration Web Application

LunaSec - Dependency Security Scanner that automatically notifies you about vulnerabilities like Log4Shell or node-ipc in your Pull Requests…

malicious-rMQR-Codes
malicious-rMQR-Codes
Open Source Exploitation Web Application

Collection of (4000+) malicious rMQR Codes for Penetration testing, Vulnerability assessments, Red Team operations, Bug Bounty and more

MalQR.github.io
MalQR.github.io
Open Source Exploitation Scanning & Enumeration

MalQR is a collection of malicious QR Codes and Barcodes you can use to test the security of your scanners.

malware-apk
malware-apk
Open Source Reverse Engineering Web Application

As a bug hunter, are your bug bounty reports getting rejected because you don't use a "malicious" Proof of Concept (PoC) app to exploit the …

malwarescanner
malwarescanner
Open Source Web Application

Simple Malware Scanner written in python

Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes
Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes
Free Web Application

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for ident…

masvs
masvs
Free Web Application

The OWASP MASVS (Mobile Application Security Verification Standard) is the industry standard for mobile app security.

medium-writeups
medium-writeups
Free Reconnaissance Web Application

This repository updates latest Bug Bounty medium writeups every 10 minutes, https://readmedium.com/Medium_URL, https://archive.ph/Medium_URL…

Meta-Owned-IT-Assets
Meta-Owned-IT-Assets
Free Reconnaissance Web Application

Curated list of Meta (formerly Facebook) owned IT assets

metabigor
metabigor
Open Source Reconnaissance Web Application

OSINT tools and more but without API key

misconfig-mapper
misconfig-mapper
Open Source Web Application

Misconfig Mapper is a fast tool to help you uncover security misconfigurations on popular third-party services used by your company and/or b…

missing-cve-nuclei-templates
missing-cve-nuclei-templates
Open Source Exploitation Web Application

Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration tests a…

Mobile-Security-Framework-MobSF
Mobile-Security-Framework-MobSF
Open Source Forensics Reverse Engineering

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and sec…

mutillidae
mutillidae
Open Source Web Application

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. This is an…

MXS
MXS
Free Web Application

A powerful asynchronous XSS scanner supporting up to 1,500 concurrent requests.

My-CyberSecurity-Store
My-CyberSecurity-Store
Free Web Application

This repository contains a comprehensive collection of learning resources and notes that I've gathered on various topics, including cybersec…

My-Methodologies
My-Methodologies
Free Reconnaissance Web Application

Tools and methods that I personally use for Recon and Exploitations

MyJWT
MyJWT
Open Source Web Application

A cli for cracking, testing vulnerabilities on Json Web Token(JWT)