ExifLooter finds geolocation on all image urls and directories also integrates with OpenStreetMap
Tips on how to write exploit scripts (faster!)
A modular external attack surface mapping tool integrating tools for automated reconnaissance and bug bounty workflows.
Takes screenshots of web pages, RDP, and VNC services. Reports on default credentials and interesting headers. Useful for rapidly assessing …
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
Collection of Facebook Bug Bounty Writeups
Find All Parameters - Tool to crawl pages, find potential parameters and generate a custom target parameter wordlist
Use favicons to improve your target recon phase. Quickly detect technologies, WAF, exposed panels, known services.
Fback is a tool that helps you create target-specific wordlists using a .json pattern.
🕵️ OSINT Tools for gathering information and actions forensics 🕵️
Detect bots, vision AI agents, and headless browsers through 40+ behavioral signals and SHA-256 proof of work. Self-hosted, privacy-first, a…
Automated API security testing
Fast, recursive content discovery tool written in Rust. Performs automatic recursive scanning and handles redirects, filters, and parallel s…
Fast web fuzzer written in Go. Supports directory discovery, parameter fuzzing, virtual host discovery, POST data fuzzing, and custom header…
Black box fuzzer for web applications
Fleex makes it easy to create multiple VPS on cloud providers and use them to distribute workloads.
Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.
One-click installer for Frida and Burp certs for SSL Pinning bypass
FrogPost: postMessage Security Testing Tool
fsociety Hacking Tools Pack – A Penetration Testing Framework
Framework for Testing WAFs (FTW!)
A collection of various awesome lists for hackers, pentesters and security researchers. With repository stars⭐ and forks🍴
Commodity Injection Signatures, Malicious Inputs, XSS, HTTP Header Injection, XXE, RCE, Javascript, XSLT
GarudRecon automates domain recon with top open-source tools to discover assets, enumerate subdomains, and detect XSS, SQLi, LFI, RCE & more…