Web Application Tools

462 tools
GDorks
GDorks
Open Source Exploitation Reconnaissance

Google Dork List - Uncover the Hidden Gems of the Internet ( There are at least 320+ categories ) + Web App

gerobug
gerobug
Open Source Web Application

The First Open Source Bug Bounty Platform

GitHacker
GitHacker
Free Web Application

🕷️ A `.git` folder exploiting tool that is able to restore the entire Git repository, including stash, common branches and common tags.

GitTools
GitTools
Open Source Reconnaissance Web Application

Tools to download and reconstruct exposed .git repositories from web servers. Includes Gitdumper (download), Extractor (extract commits), an…

GMSGadget
GMSGadget
Open Source Web Application

This repository is a collection of JavaScript gadgets that can be used to bypass XSS mitigations such as Content Security Policy (CSP) and H…

Go-Hacking
Go-Hacking
Open Source Reverse Engineering Web Application

A FREE comprehensive online Go hacking tutorial utilizing the x64, ARM64 and ARM32 architectures going step-by-step into the world of revers…

Gobuster
Gobuster
Open Source Kali Scanning & Enumeration Web Application

Directory/file and DNS busting tool written in Go. Extremely fast. Modes include directory brute-force, DNS subdomain enumeration, virtual h…

god-eye
god-eye
Free Exploitation Reconnaissance

AI-powered subdomain enumeration tool with local LLM analysis via Ollama - 100% private, zero API costs

google-hacking-assistant
google-hacking-assistant
Free Reconnaissance Web Application

🔍 Chrome扩展,为安全研究和渗透测试提供Google/百度/Bing高级搜索语法快捷执行。一键Dorking、批量提取URL、智能过滤黑名单,大幅提升信息收集效率。 🔍 Chrome extension for security research and penetrat…

goop
goop
Open Source Web Application

Yet another tool to dump a git repository from a website, focused on as-complete-as-possible dumps and handling weird edge-cases.

gotestwaf
gotestwaf
Open Source Web Application

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

goWAPT
goWAPT
Open Source Exploitation Password Attacks

Go Web Application Penetration Test

GraphQL Voyager / InQL
GraphQL Voyager / InQL
Open Source Web Application

InQL is a Burp Suite and standalone GraphQL security scanner. Analyzes introspection queries, generates operations, detects batch query atta…

graphql-armor
graphql-armor
Open Source Web Application

🛡️ The missing GraphQL security security layer for Apollo GraphQL and Yoga / Envelop servers 🛡️

graphql-cop
graphql-cop
Open Source Exploitation Web Application

Security Auditor Utility for GraphQL APIs

GraphQLer
GraphQLer
Open Source Scanning & Enumeration Web Application

🔍A cutting edge context aware GraphQL API fuzzing tool!

graphw00f
graphw00f
Open Source Reconnaissance Scanning & Enumeration

graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is…

h1-brain
h1-brain
Open Source Web Application

MCP server that connects AI assistants to HackerOne for bug bounty hunting

hackable
hackable
Free Exploitation Web Application

A python flask app that is purposefully vulnerable to SQL injection and XSS attacks. To be used for demonstrating attacks

hacker101
hacker101
Free Exploitation Web Application

Source code for Hacker101.com - a free online web and mobile security class.

hackerone-bug-bounty-reports
hackerone-bug-bounty-reports
Free Web Application

Complete collection of bug bounty reports from Hackerone.

hackerone-reports
hackerone-reports
Free Exploitation Web Application

Top disclosed reports from HackerOne

Hacking-Bug-Bounty-Books
Hacking-Bug-Bounty-Books
Free Kali Web Application

Collection of Combination of 👨🏻‍💻Ethical Hacking, 🐧Linux, Cyber security, 💰Bug Bounty, Penetration testing, Networking and more IT Related B…

Hacking-Tools
Hacking-Tools
Open Source Kali Exploitation Forensics

A curated list of penetration testing and ethical hacking tools, organized by category. This compilation includes tools from Kali Linux and …