Skip to content
Change the repository type filter

All

    Repositories list

    • GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)
      Python
      MIT License
      194000Updated Jan 16, 2023Jan 16, 2023
    • inql

      Public
      InQL - A Burp Extension for GraphQL Security Testing
      Python
      Apache License 2.0
      156000Updated Jan 14, 2023Jan 14, 2023
    • dalfox

      Public
      🌙🦊 DalFox is an powerful open source XSS scanning tool and parameter analyzer, utility
      Go
      MIT License
      412000Updated Dec 20, 2022Dec 20, 2022
    • dnstake

      Public
      DNSTake — A fast tool to check missing hosted DNS zones that can lead to subdomain takeover
      Go
      MIT License
      69000Updated Dec 14, 2022Dec 14, 2022
    • cero

      Public
      Scrape domain names from SSL certificates of arbitrary hosts
      Go
      MIT License
      79000Updated Oct 5, 2022Oct 5, 2022
    • meg

      Public
      Fetch many paths for many hosts - without killing the hosts
      Go
      MIT License
      267000Updated Feb 20, 2022Feb 20, 2022
    • gobuster

      Public
      Directory/File, DNS and VHost busting tool written in Go
      Go
      Apache License 2.0
      1.2k000Updated Jan 17, 2022Jan 17, 2022
    • Let's be scanned.
      Rust
      GNU General Public License v3.0
      15000Updated Dec 10, 2021Dec 10, 2021
    • SecLists

      Public
      SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
      PHP
      MIT License
      24k000Updated Dec 2, 2021Dec 2, 2021
    • A list of useful payloads and bypass for Web Application Security and Pentest/CTF
      Python
      MIT License
      15k000Updated Nov 24, 2021Nov 24, 2021
    • altdns

      Public
      Generates permutations, alterations and mutations of subdomains and then resolves them
      Python
      Apache License 2.0
      447000Updated Sep 9, 2021Sep 9, 2021
    • Arjun

      Public
      HTTP parameter discovery suite.
      Python
      GNU General Public License v3.0
      792000Updated Aug 29, 2021Aug 29, 2021
    • dirstalk

      Public
      Modern alternative to dirbuster/dirb
      Go
      MIT License
      47000Updated Nov 21, 2020Nov 21, 2020