mirror of
https://github.com/hahwul/WebHackersWeapons.git
synced 2025-02-23 00:19:50 -05:00
100 lines
33 KiB
Markdown
100 lines
33 KiB
Markdown
|
|
## Tools Made of Python
|
|
|
|
| Type | Name | Description | Star | Tags | Badges |
|
|
| --- | --- | --- | --- | --- | --- |
|
|
|Proxy|[mitmproxy](https://github.com/mitmproxy/mitmproxy)|An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.||[`mitmproxy`](/categorize/tags/mitmproxy.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[knock](https://github.com/guelfoweb/knock)|Knock Subdomain Scan ||[`subdomains`](/categorize/tags/subdomains.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[Lepus](https://github.com/gfek/Lepus)|Subdomain finder||[`subdomains`](/categorize/tags/subdomains.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[uro](https://github.com/s0md3v/uro)|declutters url lists for crawling/pentesting||[`url`](/categorize/tags/url.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[FavFreak](https://github.com/devanshbatham/FavFreak)|Making Favicon.ico based Recon Great again ! |||[](/categorize/langs/Python.md)|
|
|
|Recon|[SecretFinder](https://github.com/m4ll0k/SecretFinder)|SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files |||[](/categorize/langs/Python.md)|
|
|
|Recon|[Silver](https://github.com/s0md3v/Silver)|Mass scan IPs for vulnerable services ||[`port`](/categorize/tags/port.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[graphw00f](https://github.com/dolevf/graphw00f)|GraphQL Server Engine Fingerprinting utility||[`graphql`](/categorize/tags/graphql.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[pagodo](https://github.com/opsdisk/pagodo)|pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching|||[](/categorize/langs/Python.md)|
|
|
|Recon|[OneForAll](https://github.com/shmilylty/OneForAll)|OneForAll是一款功能强大的子域收集工具 |||[](/categorize/langs/Python.md)|
|
|
|Recon|[3klCon](https://github.com/eslam3kl/3klCon)|Automation Recon tool which works with Large & Medium scopes. It performs more than 20 tasks and gets back all the results in separated files.|||[](/categorize/langs/Python.md)|
|
|
|Recon|[Arjun](https://github.com/s0md3v/Arjun)|HTTP parameter discovery suite. ||[`param`](/categorize/tags/param.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[SubBrute](https://github.com/aboul3la/Sublist3r)|https://github.com/TheRook/subbrute||[`subdomains`](/categorize/tags/subdomains.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[Parth](https://github.com/s0md3v/Parth)|Heuristic Vulnerable Parameter Scanner ||[`param`](/categorize/tags/param.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[GitMiner](https://github.com/UnkL4b/GitMiner)|Tool for advanced mining for content on Github |||[](/categorize/langs/Python.md)|
|
|
|Recon|[Sublist3r](https://github.com/aboul3la/Sublist3r)|Fast subdomains enumeration tool for penetration testers ||[`subdomains`](/categorize/tags/subdomains.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[parameth](https://github.com/maK-/parameth)|This tool can be used to brute discover GET and POST parameters|||[](/categorize/langs/Python.md)|
|
|
|Recon|[spiderfoot](https://github.com/smicallef/spiderfoot)|SpiderFoot automates OSINT collection so that you can focus on analysis.||[`osint`](/categorize/tags/osint.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[ParamSpider](https://github.com/devanshbatham/ParamSpider)|Mining parameters from dark corners of Web Archives ||[`param`](/categorize/tags/param.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[Dr. Watson](https://github.com/prodigysml/Dr.-Watson)|Dr. Watson is a simple Burp Suite extension that helps find assets, keys, subdomains, IP addresses, and other useful information||[`param`](/categorize/tags/param.md) [`subdomains`](/categorize/tags/subdomains.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[HydraRecon](https://github.com/aufzayed/HydraRecon)|All In One, Fast, Easy Recon Tool|||[](/categorize/langs/Python.md)|
|
|
|Recon|[LinkFinder](https://github.com/GerbenJavado/LinkFinder)|A python script that finds endpoints in JavaScript files |||[](/categorize/langs/Python.md)|
|
|
|Recon|[xnLinkFinder](https://github.com/xnl-h4ck3r/xnLinkFinder)|A python tool used to discover endpoints (and potential parameters) for a given target|||[](/categorize/langs/Python.md)|
|
|
|Recon|[dnsvalidator](https://github.com/vortexau/dnsvalidator)|Maintains a list of IPv4 DNS servers by verifying them against baseline servers, and ensuring accurate responses.||[`dns`](/categorize/tags/dns.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[Photon](https://github.com/s0md3v/Photon)|Incredibly fast crawler designed for OSINT. ||[`osint`](/categorize/tags/osint.md) [`crawl`](/categorize/tags/crawl.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[apkleaks](https://github.com/dwisiswant0/apkleaks)|Scanning APK file for URIs, endpoints & secrets. ||[`apk`](/categorize/tags/apk.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[dirsearch](https://github.com/maurosoria/dirsearch)|Web path scanner |||[](/categorize/langs/Python.md)|
|
|
|Recon|[BLUTO](https://github.com/darryllane/Bluto)|DNS Analysis Tool||[`dns`](/categorize/tags/dns.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[longtongue](https://github.com/edoardottt/longtongue)|Customized Password/Passphrase List inputting Target Info|||[](/categorize/langs/Python.md)|
|
|
|Recon|[altdns](https://github.com/infosec-au/altdns)|Generates permutations, alterations and mutations of subdomains and then resolves them ||[`dns`](/categorize/tags/dns.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[cc.py](https://github.com/si9int/cc.py)|Extracting URLs of a specific target based on the results of "commoncrawl.org" ||[`url`](/categorize/tags/url.md)|[](/categorize/langs/Python.md)|
|
|
|Recon|[BurpJSLinkFinder](https://github.com/InitRoot/BurpJSLinkFinder)||||[](/categorize/langs/Python.md)|
|
|
|Recon|[STEWS](https://github.com/PalindromeLabs/STEWS)|A Security Tool for Enumerating WebSockets|||[](/categorize/langs/Python.md)|
|
|
|Fuzzer|[SSRFmap](https://github.com/swisskyrepo/SSRFmap)|Automatic SSRF fuzzer and exploitation tool ||[`ssrf`](/categorize/tags/ssrf.md)|[](/categorize/langs/Python.md)|
|
|
|Fuzzer|[wfuzz](https://github.com/xmendez/wfuzz)|Web application fuzzer |||[](/categorize/langs/Python.md)|
|
|
|Fuzzer|[GraphQLmap](https://github.com/swisskyrepo/GraphQLmap)|GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes.||[`graphql`](/categorize/tags/graphql.md)|[](/categorize/langs/Python.md)|
|
|
|Fuzzer|[CrackQL](https://github.com/nicholasaleks/CrackQL)|CrackQL is a GraphQL password brute-force and fuzzing utility.||[`graphql`](/categorize/tags/graphql.md)|[](/categorize/langs/Python.md)|
|
|
|Fuzzer|[BatchQL](https://github.com/assetnote/batchql)|GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations||[`graphql`](/categorize/tags/graphql.md)|[](/categorize/langs/Python.md)|
|
|
|Scanner|[corsair_scan](https://github.com/Santandersecurityresearch/corsair_scan)|Corsair_scan is a security tool to test Cross-Origin Resource Sharing (CORS).||[`cors`](/categorize/tags/cors.md)|[](/categorize/langs/Python.md)|
|
|
|Scanner|[a2sv](https://github.com/hahwul/a2sv)|Auto Scanning to SSL Vulnerability ||[`ssl`](/categorize/tags/ssl.md)|[](/categorize/langs/Python.md)|
|
|
|Scanner|[Autorize](https://github.com/Quitten/Autorize)|||[`aaa`](/categorize/tags/aaa.md)|[](/categorize/langs/Python.md)|
|
|
|Scanner|[sqlmap](https://github.com/sqlmapproject/sqlmap)|Automatic SQL injection and database takeover tool|||[](/categorize/langs/Python.md)|
|
|
|Scanner|[commix](https://github.com/commixproject/commix)|Automated All-in-One OS Command Injection Exploitation Tool.||[`exploit`](/categorize/tags/exploit.md)|[](/categorize/langs/Python.md)|
|
|
|Scanner|[deadlinks](https://github.com/butuzov/deadlinks)|Health checks for your documentation links.||[`broken-link`](/categorize/tags/broken-link.md)|[](/categorize/langs/Python.md)|
|
|
|Scanner|[NoSQLMap](https://github.com/codingo/NoSQLMap)|Automated NoSQL database enumeration and web application exploitation tool. |||[](/categorize/langs/Python.md)|
|
|
|Scanner|[LFISuite](https://github.com/D35m0nd142/LFISuite)|Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner |||[](/categorize/langs/Python.md)|
|
|
|Scanner|[S3Scanner](https://github.com/sa7mon/S3Scanner)|Scan for open AWS S3 buckets and dump the contents ||[`s3`](/categorize/tags/s3.md)|[](/categorize/langs/Python.md)|
|
|
|Scanner|[AuthMatrix](https://github.com/SecurityInnovation/AuthMatrix)|||[`aaa`](/categorize/tags/aaa.md)|[](/categorize/langs/Python.md)|
|
|
|Scanner|[tplmap](https://github.com/epinna/tplmap)|Server-Side Template Injection and Code Injection Detection and Exploitation Tool|||[](/categorize/langs/Python.md)|
|
|
|Scanner|[Corsy](https://github.com/s0md3v/Corsy)|CORS Misconfiguration Scanner ||[`cors`](/categorize/tags/cors.md)|[](/categorize/langs/Python.md)|
|
|
|Scanner|[VHostScan](https://github.com/codingo/VHostScan)|A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages. |||[](/categorize/langs/Python.md)|
|
|
|Scanner|[S3cret Scanner](https://github.com/Eilonh/s3crets_scanner)|Hunting For Secrets Uploaded To Public S3 Buckets||[`s3`](/categorize/tags/s3.md)|[](/categorize/langs/Python.md)|
|
|
|Scanner|[sqliv](https://github.com/the-robot/sqliv)|massive SQL injection vulnerability scanner||[`sqli`](/categorize/tags/sqli.md)|[](/categorize/langs/Python.md)|
|
|
|Scanner|[xsser](https://github.com/epsylon/xsser)|Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications. ||[`xss`](/categorize/tags/xss.md)|[](/categorize/langs/Python.md)|
|
|
|Scanner|[XSStrike](https://github.com/s0md3v/XSStrike)|Most advanced XSS scanner. ||[`xss`](/categorize/tags/xss.md)|[](/categorize/langs/Python.md)|
|
|
|Scanner|[zap-cli](https://github.com/Grunny/zap-cli)|A simple tool for interacting with OWASP ZAP from the commandline. |||[](/categorize/langs/Python.md)|
|
|
|Scanner|[gitGraber](https://github.com/hisxo/gitGraber)|gitGraber |||[](/categorize/langs/Python.md)|
|
|
|Scanner|[http-request-smuggling](https://github.com/anshumanpattnaik/http-request-smuggling)|HTTP Request Smuggling Detection Tool|||[](/categorize/langs/Python.md)|
|
|
|Scanner|[autopoisoner](https://github.com/Th0h0/autopoisoner)|Web cache poisoning vulnerability scanner.||[`cache-vuln`](/categorize/tags/cache-vuln.md)|[](/categorize/langs/Python.md)|
|
|
|Scanner|[rapidscan](https://github.com/skavngr/rapidscan)|The Multi-Tool Web Vulnerability Scanner. |||[](/categorize/langs/Python.md)|
|
|
|Scanner|[AWSBucketDump](https://github.com/jordanpotti/AWSBucketDump)|Security Tool to Look For Interesting Files in S3 Buckets||[`s3`](/categorize/tags/s3.md)|[](/categorize/langs/Python.md)|
|
|
|Scanner|[OpenRedireX](https://github.com/devanshbatham/OpenRedireX)|A Fuzzer for OpenRedirect issues|||[](/categorize/langs/Python.md)|
|
|
|Scanner|[DSSS](https://github.com/stamparm/DSSS)|Damn Small SQLi Scanner||[`sqli`](/categorize/tags/sqli.md)|[](/categorize/langs/Python.md)|
|
|
|Scanner|[Oralyzer](https://github.com/r0075h3ll/Oralyzer)|Open Redirection Analyzer|||[](/categorize/langs/Python.md)|
|
|
|Scanner|[Striker](https://github.com/s0md3v/Striker)|Striker is an offensive information and vulnerability scanner. |||[](/categorize/langs/Python.md)|
|
|
|Scanner|[smuggler](https://github.com/defparam/smuggler)|Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3 ||[`smuggle`](/categorize/tags/smuggle.md)|[](/categorize/langs/Python.md)|
|
|
|Scanner|[xsscrapy](https://github.com/DanMcInerney/xsscrapy)|XSS/SQLi spider. Give it a URL and it'll test every link it finds for XSS and some SQLi. ||[`xss`](/categorize/tags/xss.md)|[](/categorize/langs/Python.md)|
|
|
|Exploit|[ghauri](https://github.com/r0oth3x49/ghauri)|An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws||[`sqli`](/categorize/tags/sqli.md)|[](/categorize/langs/Python.md)|
|
|
|Exploit|[Liffy](https://github.com/mzfr/liffy)|Local file inclusion exploitation tool||[`lfi`](/categorize/tags/lfi.md)|[](/categorize/langs/Python.md)|
|
|
|Exploit|[Gopherus](https://github.com/tarunkant/Gopherus)|This tool generates gopher link for exploiting SSRF and gaining RCE in various servers ||[`ssrf`](/categorize/tags/ssrf.md)|[](/categorize/langs/Python.md)|
|
|
|Exploit|[of-CORS](https://github.com/trufflesecurity/of-CORS)|Identifying and exploiting CORS misconfigurations on the internal networks||[`cors`](/categorize/tags/cors.md)|[](/categorize/langs/Python.md)|
|
|
|Exploit|[XSRFProbe](https://github.com/0xInfection/XSRFProbe)|The Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.|||[](/categorize/langs/Python.md)|
|
|
|Exploit|[toxssin](https://github.com/t3l3machus/toxssin)|An XSS exploitation command-line interface and payload generator.||[`xss`](/categorize/tags/xss.md)|[](/categorize/langs/Python.md)|
|
|
|Utils|[grc](https://github.com/garabik/grc)|generic colouriser|||[](/categorize/langs/Python.md)|
|
|
|Utils|[230-OOB](https://github.com/lc/230-OOB)|An Out-of-Band XXE server for retrieving file contents over FTP.||[`xxe`](/categorize/tags/xxe.md)|[](/categorize/langs/Python.md)|
|
|
|Utils|[pentest-tools](https://github.com/gwen001/pentest-tools)|Custom pentesting tools |||[](/categorize/langs/Python.md)|
|
|
|Utils|[PayloadsAllTheThings](https://github.com/swisskyrepo/PayloadsAllTheThings)|A list of useful payloads and bypass for Web Application Security and Pentest/CTF |||[](/categorize/langs/Python.md)|
|
|
|Utils|[inql](https://github.com/doyensec/inql)||||[](/categorize/langs/Python.md)|
|
|
|Utils|[femida](https://github.com/wish-i-was/femida)||||[](/categorize/langs/Python.md)|
|
|
|Utils|[docem](https://github.com/whitel1st/docem)|Uility to embed XXE and XSS payloads in docx,odt,pptx,etc (OXML_XEE on steroids)||[`xxe`](/categorize/tags/xxe.md) [`xss`](/categorize/tags/xss.md)|[](/categorize/langs/Python.md)|
|
|
|Utils|[zip-bomb](https://github.com/damianrusinek/zip-bomb)|Create a ZIPBomb for a given uncompressed size (flat and nested modes).||[`zipbomb`](/categorize/tags/zipbomb.md)|[](/categorize/langs/Python.md)|
|
|
|Utils|[Atlas](https://github.com/m4ll0k/Atlas)|Quick SQLMap Tamper Suggester |||[](/categorize/langs/Python.md)|
|
|
|Utils|[httpie](https://github.com/httpie/httpie)|As easy as /aitch-tee-tee-pie/ 🥧 Modern, user-friendly command-line HTTP client for the API era. JSON support, colors, sessions, downloads, plugins & more. https://twitter.com/httpie||[`http`](/categorize/tags/http.md)|[](/categorize/langs/Python.md)|
|
|
|Utils|[Bug-Bounty-Toolz](https://github.com/m4ll0k/Bug-Bounty-Toolz)|BBT - Bug Bounty Tools |||[](/categorize/langs/Python.md)|
|
|
|Utils|[REcollapse](https://github.com/0xacb/recollapse)|REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications||[`fuzz`](/categorize/tags/fuzz.md)|[](/categorize/langs/Python.md)|
|
|
|Utils|[argumentinjectionhammer](https://github.com/nccgroup/argumentinjectionhammer)|A Burp Extension designed to identify argument injection vulnerabilities.|||[](/categorize/langs/Python.md)|
|
|
|Utils|[burp-exporter](https://github.com/artssec/burp-exporter)||||[](/categorize/langs/Python.md)|
|
|
|Utils|[blackboxprotobuf](https://github.com/nccgroup/blackboxprotobuf)|Blackbox protobuf is a Burp Suite extension for decoding and modifying arbitrary protobuf messages without the protobuf type definition.|||[](/categorize/langs/Python.md)|
|
|
|Utils|[XSS-Catcher](https://github.com/daxAKAhackerman/XSS-Catcher)|Find blind XSS but why not gather data while you're at it.||[`xss`](/categorize/tags/xss.md) [`blind-xss`](/categorize/tags/blind-xss.md)|[](/categorize/langs/Python.md)|
|
|
|Utils|[ZipBomb](https://github.com/abdulfatir/ZipBomb)|A simple implementation of ZipBomb in Python||[`zipbomb`](/categorize/tags/zipbomb.md)|[](/categorize/langs/Python.md)|
|
|
|Utils|[tiscripts](https://github.com/defparam/tiscripts)|Turbo Intruder Scripts|||[](/categorize/langs/Python.md)|
|
|
|Utils|[Redcloud](https://github.com/khast3x/Redcloud)|Automated Red Team Infrastructure deployement using Docker||[`infra`](/categorize/tags/infra.md)|[](/categorize/langs/Python.md)|
|
|
|Env|[Crimson](https://github.com/Karmaz95/crimson)|Web Application Security Testing automation.|||[](/categorize/langs/Python.md)|
|
|
|