Army-Knife |
axiom |
A dynamic infrastructure toolkit for red teamers and bug bounty hunters! |
![](https://img.shields.io/github/stars/pry0cc/axiom?label=%20) |
infra |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Shell](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/shell.png) |
Army-Knife |
jaeles |
The Swiss Army knife for automated Web Application Testing |
![](https://img.shields.io/github/stars/jaeles-project/jaeles?label=%20) |
live-audit |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Army-Knife |
BurpSuite |
The BurpSuite Project |
|
mitmproxy live-audit crawl |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![burp](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/burp.png) ![Java](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/java.png) |
Army-Knife |
Metasploit |
The world’s most used penetration testing framework |
![](https://img.shields.io/github/stars/rapid7/metasploit-framework?label=%20) |
pentest |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Ruby](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/ruby.png) |
Army-Knife |
ZAP |
The OWASP ZAP core project |
![](https://img.shields.io/github/stars/zaproxy/zaproxy?label=%20) |
mitmproxy live-audit crawl |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![zap](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/zap.png) ![Java](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/java.png) |
Proxy |
proxify |
Swiss Army knife Proxy tool for HTTP/HTTPS traffic capture, manipulation and replay |
![](https://img.shields.io/github/stars/projectdiscovery/proxify?label=%20) |
mitmproxy |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Proxy |
mitmproxy |
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers. |
![](https://img.shields.io/github/stars/mitmproxy/mitmproxy?label=%20) |
mitmproxy |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Proxy |
Echo Mirage |
A generic network proxy that uses DLL injection to capture and alter TCP traffic. |
|
mitmproxy |
![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Proxy |
hetty |
Hetty is an HTTP toolkit for security research. It aims to become an open source alternative to commercial software like Burp Suite Pro, with powerful features tailored to the needs of the infosec and bug bounty community. |
![](https://img.shields.io/github/stars/dstotijn/hetty?label=%20) |
mitmproxy |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Proxy |
EvilProxy |
A ruby http/https proxy to do EVIL things. |
![](https://img.shields.io/github/stars/bbtfr/evil-proxy?label=%20) |
mitmproxy |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Ruby](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/ruby.png) |
Proxy |
Caido |
A lightweight web security auditing toolkit |
|
mitmproxy |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Rust](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/rust.png) |
Recon |
subjack |
Subdomain Takeover tool written in Go |
![](https://img.shields.io/github/stars/haccer/subjack?label=%20) |
subdomains takeover |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
longtongue |
Customized Password/Passphrase List inputting Target Info |
![](https://img.shields.io/github/stars/edoardottt/longtongue?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
github-endpoints |
Find endpoints on GitHub. |
![](https://img.shields.io/github/stars/gwen001/github-endpoints?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
subgen |
A really simple utility to concate wordlists to a domain name - to pipe into your favourite resolver! |
![](https://img.shields.io/github/stars/pry0cc/subgen?label=%20) |
subdomains |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
knock |
Knock Subdomain Scan |
![](https://img.shields.io/github/stars/guelfoweb/knock?label=%20) |
subdomains |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
reconftw |
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities |
![](https://img.shields.io/github/stars/six2dez/reconftw?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Shell](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/shell.png) |
Recon |
crawlergo |
A powerful browser crawler for web vulnerability scanners |
![](https://img.shields.io/github/stars/Qianlitp/crawlergo?label=%20) |
crawl |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
CT_subdomains |
An hourly updated list of subdomains gathered from certificate transparency logs |
![](https://img.shields.io/github/stars/internetwache/CT_subdomains?label=%20) |
subdomains |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Recon |
chaos-client |
Go client to communicate with Chaos DNS API. |
![](https://img.shields.io/github/stars/projectdiscovery/chaos-client?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
cc.py |
Extracting URLs of a specific target based on the results of "commoncrawl.org" |
![](https://img.shields.io/github/stars/si9int/cc.py?label=%20) |
url |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
cariddi |
Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more |
![](https://img.shields.io/github/stars/edoardottt/cariddi?label=%20) |
crawl |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
meg |
Fetch many paths for many hosts - without killing the hosts |
![](https://img.shields.io/github/stars/tomnomnom/meg?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
rengine |
reNgine is an automated reconnaissance framework meant for gathering information during penetration testing of web applications. reNgine has customizable scan engines, which can be used to scan the websites, endpoints, and gather information. |
![](https://img.shields.io/github/stars/yogeshojha/rengine?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Recon |
LinkFinder |
A python script that finds endpoints in JavaScript files |
![](https://img.shields.io/github/stars/GerbenJavado/LinkFinder?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
zdns |
Fast CLI DNS Lookup Tool |
![](https://img.shields.io/github/stars/zmap/zdns?label=%20) |
dns |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
rusolver |
Fast and accurate DNS resolver. |
![](https://img.shields.io/github/stars/Edu4rdSHL/rusolver?label=%20) |
dns |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Rust](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/rust.png) |
Recon |
3klCon |
Automation Recon tool which works with Large & Medium scopes. It performs more than 20 tasks and gets back all the results in separated files. |
![](https://img.shields.io/github/stars/eslam3kl/3klCon?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
dnsprobe |
DNSProb (beta) is a tool built on top of retryabledns that allows you to perform multiple dns queries of your choice with a list of user supplied resolvers. |
![](https://img.shields.io/github/stars/projectdiscovery/dnsprobe?label=%20) |
dns |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
puredns |
Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries. |
![](https://img.shields.io/github/stars/d3mondev/puredns?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
subzy |
Subdomain takeover vulnerability checker |
![](https://img.shields.io/github/stars/LukaSikic/subzy?label=%20) |
subdomains takeover |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
SecurityTrails |
Online dns / subdomain / recon tool |
|
subdomains online |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Recon |
urlhunter |
a recon tool that allows searching on URLs that are exposed via shortener services |
![](https://img.shields.io/github/stars/utkusen/urlhunter?label=%20) |
url |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
megplus |
Automated reconnaissance wrapper — TomNomNom's meg on steroids. [DEPRECATED] |
![](https://img.shields.io/github/stars/EdOverflow/megplus?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Shell](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/shell.png) |
Recon |
Silver |
Mass scan IPs for vulnerable services |
![](https://img.shields.io/github/stars/s0md3v/Silver?label=%20) |
port |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
masscan |
TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes. |
![](https://img.shields.io/github/stars/robertdavidgraham/masscan?label=%20) |
portscan |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![C](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/c.png) |
Recon |
RustScan |
Faster Nmap Scanning with Rust |
![](https://img.shields.io/github/stars/brandonskerritt/RustScan?label=%20) |
portscan |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Rust](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/rust.png) |
Recon |
fhc |
Fast HTTP Checker. |
![](https://img.shields.io/github/stars/Edu4rdSHL/fhc?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Rust](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/rust.png) |
Recon |
dnsx |
dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers. |
![](https://img.shields.io/github/stars/projectdiscovery/dnsx?label=%20) |
dns |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
Parth |
Heuristic Vulnerable Parameter Scanner |
![](https://img.shields.io/github/stars/s0md3v/Parth?label=%20) |
param |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
github-subdomains |
Find subdomains on GitHub |
![](https://img.shields.io/github/stars/gwen001/github-subdomains?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
sn0int |
Semi-automatic OSINT framework and package manager |
![](https://img.shields.io/github/stars/kpcyrd/sn0int?label=%20) |
osint |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Rust](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/rust.png) |
Recon |
hakrawler |
Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application |
![](https://img.shields.io/github/stars/hakluke/hakrawler?label=%20) |
crawl |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
gospider |
Gospider - Fast web spider written in Go |
![](https://img.shields.io/github/stars/jaeles-project/gospider?label=%20) |
crawl |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
SecretFinder |
SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files |
![](https://img.shields.io/github/stars/m4ll0k/SecretFinder?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
shuffledns |
shuffleDNS is a wrapper around massdns written in go that allows you to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard handling and easy input-output support. |
![](https://img.shields.io/github/stars/projectdiscovery/shuffledns?label=%20) |
dns |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
subfinder |
Subfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing. |
![](https://img.shields.io/github/stars/projectdiscovery/subfinder?label=%20) |
subdomains |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
Hunt3r |
Made your bugbounty subdomains reconnaissance easier with Hunt3r the web application reconnaissance framework |
![](https://img.shields.io/github/stars/EasyRecon/Hunt3r?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Ruby](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/ruby.png) |
Recon |
lazyrecon |
This script is intended to automate your reconnaissance process in an organized fashion |
![](https://img.shields.io/github/stars/nahamsec/lazyrecon?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Shell](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/shell.png) |
Recon |
dmut |
A tool to perform permutations, mutations and alteration of subdomains in golang. |
![](https://img.shields.io/github/stars/bp0lr/dmut?label=%20) |
subdomains |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
SubOver |
A Powerful Subdomain Takeover Tool |
![](https://img.shields.io/github/stars/Ice3man543/SubOver?label=%20) |
subdomains takeover |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
Lepus |
Subdomain finder |
![](https://img.shields.io/github/stars/gfek/Lepus?label=%20) |
subdomains |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
Chaos Web |
actively scan and maintain internet-wide assets' data. enhance research and analyse changes around DNS for better insights. |
|
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Recon |
gitrob |
Reconnaissance tool for GitHub organizations |
![](https://img.shields.io/github/stars/michenriksen/gitrob?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
OneForAll |
OneForAll是一款功能强大的子域收集工具 |
![](https://img.shields.io/github/stars/shmilylty/OneForAll?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
go-dork |
The fastest dork scanner written in Go. |
![](https://img.shields.io/github/stars/dwisiswant0/go-dork?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
Smap |
a drop-in replacement for Nmap powered by shodan.io |
![](https://img.shields.io/github/stars/s0md3v/smap/?label=%20) |
port |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
Shodan |
World's first search engine for Internet-connected devices |
|
osint |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Recon |
naabu |
A fast port scanner written in go with focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentests |
![](https://img.shields.io/github/stars/projectdiscovery/naabu?label=%20) |
portscan |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
waybackurls |
Fetch all the URLs that the Wayback Machine knows about for a domain |
![](https://img.shields.io/github/stars/tomnomnom/waybackurls?label=%20) |
url |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
graphw00f |
GraphQL Server Engine Fingerprinting utility |
![](https://img.shields.io/github/stars/dolevf/graphw00f?label=%20) |
graphql |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
subjs |
Fetches javascript file from a list of URLS or subdomains. |
![](https://img.shields.io/github/stars/lc/subjs?label=%20) |
url subdomains |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
htcat |
Parallel and Pipelined HTTP GET Utility |
![](https://img.shields.io/github/stars/htcat/htcat?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
uncover |
Quickly discover exposed hosts on the internet using multiple search engine. |
![](https://img.shields.io/github/stars/projectdiscovery/uncover?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
intrigue-core |
Discover Your Attack Surface |
![](https://img.shields.io/github/stars/intrigueio/intrigue-core?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Ruby](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/ruby.png) |
Recon |
STEWS |
A Security Tool for Enumerating WebSockets |
![](https://img.shields.io/github/stars/PalindromeLabs/STEWS?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
assetfinder |
Find domains and subdomains related to a given domain |
![](https://img.shields.io/github/stars/tomnomnom/assetfinder?label=%20) |
subdomains |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
gau |
Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl. |
![](https://img.shields.io/github/stars/lc/gau?label=%20) |
url |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
JSFScan.sh |
Automation for javascript recon in bug bounty. |
![](https://img.shields.io/github/stars/KathanP19/JSFScan.sh?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Shell](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/shell.png) |
Recon |
hakrevdns |
Small, fast tool for performing reverse DNS lookups en masse. |
![](https://img.shields.io/github/stars/hakluke/hakrevdns?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
scilla |
🏴☠️ Information Gathering tool 🏴☠️ dns/subdomain/port enumeration |
![](https://img.shields.io/github/stars/edoardottt/scilla?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
dirsearch |
Web path scanner |
![](https://img.shields.io/github/stars/maurosoria/dirsearch?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
httpx |
httpx is a fast and multi-purpose HTTP toolkit allow to run multiple probers using retryablehttp library, it is designed to maintain the result reliability with increased threads. |
![](https://img.shields.io/github/stars/projectdiscovery/httpx?label=%20) |
url |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
BLUTO |
DNS Analysis Tool |
![](https://img.shields.io/github/stars/darryllane/Bluto?label=%20) |
dns |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
recon_profile |
Recon profile (bash profile) for bugbounty |
![](https://img.shields.io/github/stars/nahamsec/recon_profile?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Shell](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/shell.png) |
Recon |
dnsvalidator |
Maintains a list of IPv4 DNS servers by verifying them against baseline servers, and ensuring accurate responses. |
![](https://img.shields.io/github/stars/vortexau/dnsvalidator?label=%20) |
dns |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
x8 |
Hidden parameters discovery suite |
![](https://img.shields.io/github/stars/Sh1Yo/x8?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Rust](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/rust.png) |
Recon |
goverview |
goverview - Get an overview of the list of URLs |
![](https://img.shields.io/github/stars/j3ssie/goverview?label=%20) |
url |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
xnLinkFinder |
A python tool used to discover endpoints (and potential parameters) for a given target |
![](https://img.shields.io/github/stars/xnl-h4ck3r/xnLinkFinder?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
findomain |
The fastest and cross-platform subdomain enumerator, do not waste your time. |
![](https://img.shields.io/github/stars/Edu4rdSHL/findomain?label=%20) |
subdomains |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Rust](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/rust.png) |
Recon |
parameth |
This tool can be used to brute discover GET and POST parameters |
![](https://img.shields.io/github/stars/maK-/parameth?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
aquatone |
A Tool for Domain Flyovers |
![](https://img.shields.io/github/stars/michenriksen/aquatone?label=%20) |
domain |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
gowitness |
🔍 gowitness - a golang, web screenshot utility using Chrome Headless |
![](https://img.shields.io/github/stars/sensepost/gowitness?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
katana |
A next-generation crawling and spidering framework. |
![](https://img.shields.io/github/stars/projectdiscovery/katana?label=%20) |
crawl |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
Photon |
Incredibly fast crawler designed for OSINT. |
![](https://img.shields.io/github/stars/s0md3v/Photon?label=%20) |
osint crawl |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
HydraRecon |
All In One, Fast, Easy Recon Tool |
![](https://img.shields.io/github/stars/aufzayed/HydraRecon?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
subs_all |
Subdomain Enumeration Wordlist. 8956437 unique words. Updated. |
![](https://img.shields.io/github/stars/emadshanab/subs_all?label=%20) |
subdomains |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Recon |
pagodo |
pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching |
![](https://img.shields.io/github/stars/opsdisk/pagodo?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
Sub404 |
A python tool to check subdomain takeover vulnerability |
![](https://img.shields.io/github/stars/r3curs1v3-pr0xy/sub404?label=%20) |
subdomains takeover |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
Osmedeus |
Fully automated offensive security framework for reconnaissance and vulnerability scanning |
![](https://img.shields.io/github/stars/j3ssie/Osmedeus?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
haktrails |
Golang client for querying SecurityTrails API data |
![](https://img.shields.io/github/stars/hakluke/haktrails?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
gauplus |
A modified version of gau for personal usage. Support workers, proxies and some extra things. |
![](https://img.shields.io/github/stars/bp0lr/gauplus?label=%20) |
url |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
Amass |
In-depth Attack Surface Mapping and Asset Discovery |
![](https://img.shields.io/github/stars/OWASP/Amass?label=%20) |
subdomains |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
uro |
declutters url lists for crawling/pentesting |
![](https://img.shields.io/github/stars/s0md3v/uro?label=%20) |
url |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
SubBrute |
https://github.com/TheRook/subbrute |
![](https://img.shields.io/github/stars/aboul3la/Sublist3r?label=%20) |
subdomains |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
FavFreak |
Making Favicon.ico based Recon Great again ! |
![](https://img.shields.io/github/stars/devanshbatham/FavFreak?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
apkleaks |
Scanning APK file for URIs, endpoints & secrets. |
![](https://img.shields.io/github/stars/dwisiswant0/apkleaks?label=%20) |
apk |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
GitMiner |
Tool for advanced mining for content on Github |
![](https://img.shields.io/github/stars/UnkL4b/GitMiner?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
getJS |
A tool to fastly get all javascript sources/files |
![](https://img.shields.io/github/stars/003random/getJS?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
DNSDumpster |
Online dns recon & research, find & lookup dns records |
|
dns online |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Recon |
Arjun |
HTTP parameter discovery suite. |
![](https://img.shields.io/github/stars/s0md3v/Arjun?label=%20) |
param |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
gobuster |
Directory/File, DNS and VHost busting tool written in Go |
![](https://img.shields.io/github/stars/OJ/gobuster?label=%20) |
subdomains |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Recon |
altdns |
Generates permutations, alterations and mutations of subdomains and then resolves them |
![](https://img.shields.io/github/stars/infosec-au/altdns?label=%20) |
dns |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
ParamSpider |
Mining parameters from dark corners of Web Archives |
![](https://img.shields.io/github/stars/devanshbatham/ParamSpider?label=%20) |
param |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
Sublist3r |
Fast subdomains enumeration tool for penetration testers |
![](https://img.shields.io/github/stars/aboul3la/Sublist3r?label=%20) |
subdomains |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Recon |
spiderfoot |
SpiderFoot automates OSINT collection so that you can focus on analysis. |
![](https://img.shields.io/github/stars/smicallef/spiderfoot?label=%20) |
osint |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Fuzzer |
ppfuzz |
A fast tool to scan client-side prototype pollution vulnerability written in Rust. 🦀 |
![](https://img.shields.io/github/stars/dwisiswant0/ppfuzz?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Rust](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/rust.png) |
Fuzzer |
GraphQLmap |
GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. |
![](https://img.shields.io/github/stars/swisskyrepo/GraphQLmap?label=%20) |
graphql |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Fuzzer |
crlfuzz |
A fast tool to scan CRLF vulnerability written in Go |
![](https://img.shields.io/github/stars/dwisiswant0/crlfuzz?label=%20) |
crlf |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Shell](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/shell.png) |
Fuzzer |
kiterunner |
Contextual Content Discovery Tool |
![](https://img.shields.io/github/stars/assetnote/kiterunner?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Fuzzer |
ffuf |
Fast web fuzzer written in Go |
![](https://img.shields.io/github/stars/ffuf/ffuf?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Fuzzer |
hashcat |
World's fastest and most advanced password recovery utility |
![](https://img.shields.io/github/stars/hashcat/hashcat/?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![C](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/c.png) |
Fuzzer |
BruteX |
Automatically brute force all services running on a target. |
![](https://img.shields.io/github/stars/1N3/BruteX?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Shell](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/shell.png) |
Fuzzer |
medusa |
Fastest recursive HTTP fuzzer, like a Ferrari. |
![](https://img.shields.io/github/stars/riza/medusa?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Fuzzer |
jwt-cracker |
Simple HS256 JWT token brute force cracker |
![](https://img.shields.io/github/stars/lmammino/jwt-cracker?label=%20) |
jwt |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Fuzzer |
jwt-hack |
🔩 jwt-hack is tool for hacking / security testing to JWT. Supported for En/decoding JWT, Generate payload for JWT attack and very fast cracking(dict/brutefoce) |
![](https://img.shields.io/github/stars/hahwul/jwt-hack?label=%20) |
jwt |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Fuzzer |
CrackQL |
CrackQL is a GraphQL password brute-force and fuzzing utility. |
![](https://img.shields.io/github/stars/nicholasaleks/CrackQL?label=%20) |
graphql |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Fuzzer |
feroxbuster |
A fast, simple, recursive content discovery tool written in Rust. |
![](https://img.shields.io/github/stars/epi052/feroxbuster?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Rust](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/rust.png) |
Fuzzer |
thc-hydra |
hydra |
![](https://img.shields.io/github/stars/vanhauser-thc/thc-hydra?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![C](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/c.png) |
Fuzzer |
wfuzz |
Web application fuzzer |
![](https://img.shields.io/github/stars/xmendez/wfuzz?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Fuzzer |
fuzzparam |
A fast go based param miner to fuzz possible parameters a URL can have. |
![](https://img.shields.io/github/stars/0xsapra/fuzzparam?label=%20) |
param |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Fuzzer |
BatchQL |
GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations |
![](https://img.shields.io/github/stars/assetnote/batchql?label=%20) |
graphql |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Fuzzer |
dotdotpwn |
DotDotPwn - The Directory Traversal Fuzzer |
![](https://img.shields.io/github/stars/wireghoul/dotdotpwn?label=%20) |
path-traversal |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Perl](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/perl.png) |
Fuzzer |
SSRFmap |
Automatic SSRF fuzzer and exploitation tool |
![](https://img.shields.io/github/stars/swisskyrepo/SSRFmap?label=%20) |
ssrf |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Fuzzer |
c-jwt-cracker |
JWT brute force cracker written in C |
![](https://img.shields.io/github/stars/brendan-rius/c-jwt-cracker?label=%20) |
jwt |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![C](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/c.png) |
Scanner |
xsser |
Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications. |
![](https://img.shields.io/github/stars/epsylon/xsser?label=%20) |
xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
smuggler |
Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3 |
![](https://img.shields.io/github/stars/defparam/smuggler?label=%20) |
smuggle |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
commix |
Automated All-in-One OS Command Injection Exploitation Tool. |
![](https://img.shields.io/github/stars/commixproject/commix?label=%20) |
exploit |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
Web-Cache-Vulnerability-Scanner |
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/). |
![](https://img.shields.io/github/stars/Hackmanit/Web-Cache-Vulnerability-Scanner?label=%20) |
cache-vuln |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
deadlinks |
Health checks for your documentation links. |
![](https://img.shields.io/github/stars/butuzov/deadlinks?label=%20) |
broken-link |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
dalfox |
🌘🦊 DalFox(Finder Of XSS) / Parameter Analysis and XSS Scanning tool based on golang |
![](https://img.shields.io/github/stars/hahwul/dalfox?label=%20) |
xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
h2csmuggler |
HTTP Request Smuggling Detection Tool |
![](https://img.shields.io/github/stars/assetnote/h2csmuggler?label=%20) |
smuggle |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
a2sv |
Auto Scanning to SSL Vulnerability |
![](https://img.shields.io/github/stars/hahwul/a2sv?label=%20) |
ssl |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
http2smugl |
This tool helps to detect and exploit HTTP request smuggling in cases it can be achieved via HTTP/2 -> HTTP/1.1 conversion by the frontend server. |
![](https://img.shields.io/github/stars/neex/http2smugl?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
gitGraber |
gitGraber |
![](https://img.shields.io/github/stars/hisxo/gitGraber?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
domdig |
DOM XSS scanner for Single Page Applications |
![](https://img.shields.io/github/stars/fcavallarin/domdig?label=%20) |
xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Scanner |
corsair_scan |
Corsair_scan is a security tool to test Cross-Origin Resource Sharing (CORS). |
![](https://img.shields.io/github/stars/Santandersecurityresearch/corsair_scan?label=%20) |
cors |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
github-search |
Tools to perform basic search on GitHub. |
![](https://img.shields.io/github/stars/gwen001/github-search?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Scanner |
testssl.sh |
Testing TLS/SSL encryption anywhere on any port |
![](https://img.shields.io/github/stars/drwetter/testssl.sh?label=%20) |
ssl |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Shell](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/shell.png) |
Scanner |
DSSS |
Damn Small SQLi Scanner |
![](https://img.shields.io/github/stars/stamparm/DSSS?label=%20) |
sqli |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
DOMPurify |
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo: |
![](https://img.shields.io/github/stars/cure53/DOMPurify?label=%20) |
xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Scanner |
XSpear |
Powerfull XSS Scanning and Parameter analysis tool&gem |
![](https://img.shields.io/github/stars/hahwul/XSpear?label=%20) |
xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Ruby](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/ruby.png) |
Scanner |
nikto |
Nikto web server scanner |
![](https://img.shields.io/github/stars/sullo/nikto?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Perl](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/perl.png) |
Scanner |
Taipan |
Web application vulnerability scanner |
![](https://img.shields.io/github/stars/enkomio/Taipan?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Scanner |
headi |
Customisable and automated HTTP header injection |
![](https://img.shields.io/github/stars/mlcsec/headi?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
arachni |
Web Application Security Scanner Framework |
![](https://img.shields.io/github/stars/Arachni/arachni?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Ruby](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/ruby.png) |
Scanner |
PPScan |
Client Side Prototype Pollution Scanner |
![](https://img.shields.io/github/stars/msrkp/PPScan?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Scanner |
VHostScan |
A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages. |
![](https://img.shields.io/github/stars/codingo/VHostScan?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
Corsy |
CORS Misconfiguration Scanner |
![](https://img.shields.io/github/stars/s0md3v/Corsy?label=%20) |
cors |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
plution |
Prototype pollution scanner using headless chrome |
![](https://img.shields.io/github/stars/raverrr/plution?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
tplmap |
Server-Side Template Injection and Code Injection Detection and Exploitation Tool |
![](https://img.shields.io/github/stars/epinna/tplmap?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
findom-xss |
A fast DOM based XSS vulnerability scanner with simplicity. |
![](https://img.shields.io/github/stars/dwisiswant0/findom-xss?label=%20) |
xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Shell](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/shell.png) |
Scanner |
S3cret Scanner |
Hunting For Secrets Uploaded To Public S3 Buckets |
![](https://img.shields.io/github/stars/Eilonh/s3crets_scanner?label=%20) |
s3 |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
nuclei |
Nuclei is a fast tool for configurable targeted scanning based on templates offering massive extensibility and ease of use. |
![](https://img.shields.io/github/stars/projectdiscovery/nuclei?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
autopoisoner |
Web cache poisoning vulnerability scanner. |
![](https://img.shields.io/github/stars/Th0h0/autopoisoner?label=%20) |
cache-vuln |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
fockcache |
FockCache - Minimalized Test Cache Poisoning |
![](https://img.shields.io/github/stars/tismayil/fockcache?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
hinject |
Host Header Injection Checker |
![](https://img.shields.io/github/stars/dwisiswant0/hinject?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
DirDar |
DirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it |
![](https://img.shields.io/github/stars/M4DM0e/DirDar?label=%20) |
403 |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
rapidscan |
The Multi-Tool Web Vulnerability Scanner. |
![](https://img.shields.io/github/stars/skavngr/rapidscan?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
nmap |
Nmap - the Network Mapper. Github mirror of official SVN repository. |
![](https://img.shields.io/github/stars/nmap/nmap?label=%20) |
portscan |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![C](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/c.png) |
Scanner |
nosqli |
NoSql Injection CLI tool |
![](https://img.shields.io/github/stars/Charlie-belmer/nosqli?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
jsprime |
a javascript static security analysis tool |
![](https://img.shields.io/github/stars/dpnishant/jsprime?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Scanner |
wpscan |
WPScan is a free, for non-commercial use, black box WordPress Vulnerability Scanner written for security professionals and blog maintainers to test the security of their WordPress websites. |
![](https://img.shields.io/github/stars/wpscanteam/wpscan?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Ruby](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/ruby.png) |
Scanner |
dontgo403 |
Tool to bypass 40X response codes. |
![](https://img.shields.io/github/stars/devploit/dontgo403?label=%20) |
403 |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
Striker |
Striker is an offensive information and vulnerability scanner. |
![](https://img.shields.io/github/stars/s0md3v/Striker?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
http-request-smuggling |
HTTP Request Smuggling Detection Tool |
![](https://img.shields.io/github/stars/anshumanpattnaik/http-request-smuggling?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
xsinator.com |
XS-Leak Browser Test Suite |
![](https://img.shields.io/github/stars/RUB-NDS/xsinator.com?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Scanner |
CorsMe |
Cross Origin Resource Sharing MisConfiguration Scanner |
![](https://img.shields.io/github/stars/Shivangx01b/CorsMe?label=%20) |
cors |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
LFISuite |
Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner |
![](https://img.shields.io/github/stars/D35m0nd142/LFISuite?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
DeepViolet |
Tool for introspection of SSL\TLS sessions |
![](https://img.shields.io/github/stars/spoofzu/DeepViolet?label=%20) |
ssl |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Java](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/java.png) |
Scanner |
gitleaks |
Scan git repos (or files) for secrets using regex and entropy 🔑 |
![](https://img.shields.io/github/stars/zricethezav/gitleaks?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
HRS |
HTTP Request Smuggling demonstration Perl script, for variants 1, 2 and 5 in my BlackHat US 2020 paper HTTP Request Smuggling in 2020. |
![](https://img.shields.io/github/stars/SafeBreach-Labs/HRS?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Perl](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/perl.png) |
Scanner |
XSStrike |
Most advanced XSS scanner. |
![](https://img.shields.io/github/stars/s0md3v/XSStrike?label=%20) |
xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
DeadFinder |
Find dead-links (broken links) |
![](https://img.shields.io/github/stars/hahwul/deadfinder?label=%20) |
broken-link |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Ruby](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/ruby.png) |
Scanner |
web_cache_poison |
web cache poison - Top 1 web hacking technique of 2019 |
![](https://img.shields.io/github/stars/fngoo/web_cache_poison?label=%20) |
cache-vuln |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Shell](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/shell.png) |
Scanner |
Oralyzer |
Open Redirection Analyzer |
![](https://img.shields.io/github/stars/r0075h3ll/Oralyzer?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
sqlmap |
Automatic SQL injection and database takeover tool |
![](https://img.shields.io/github/stars/sqlmapproject/sqlmap?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
httprobe |
Take a list of domains and probe for working HTTP and HTTPS servers |
![](https://img.shields.io/github/stars/tomnomnom/httprobe?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
OpenRedireX |
A Fuzzer for OpenRedirect issues |
![](https://img.shields.io/github/stars/devanshbatham/OpenRedireX?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
S3Scanner |
Scan for open AWS S3 buckets and dump the contents |
![](https://img.shields.io/github/stars/sa7mon/S3Scanner?label=%20) |
s3 |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
sqliv |
massive SQL injection vulnerability scanner |
![](https://img.shields.io/github/stars/the-robot/sqliv?label=%20) |
sqli |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
wprecon |
Hello! Welcome. Wprecon (Wordpress Recon), is a vulnerability recognition tool in CMS Wordpress, 100% developed in Go. |
![](https://img.shields.io/github/stars/blackcrw/wprecon?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
ws-smuggler |
WebSocket Connection Smuggler |
![](https://img.shields.io/github/stars/hahwul/ws-smuggler?label=%20) |
smuggle |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
ssrf-sheriff |
A simple SSRF-testing sheriff written in Go |
![](https://img.shields.io/github/stars/teknogeek/ssrf-sheriff?label=%20) |
ssrf |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
xsscrapy |
XSS/SQLi spider. Give it a URL and it'll test every link it finds for XSS and some SQLi. |
![](https://img.shields.io/github/stars/DanMcInerney/xsscrapy?label=%20) |
xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
websocket-connection-smuggler |
websocket-connection-smuggler |
![](https://img.shields.io/github/stars/hahwul/websocket-connection-smuggler?label=%20) |
smuggle |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
confused |
Tool to check for dependency confusion vulnerabilities in multiple package management systems |
![](https://img.shields.io/github/stars/visma-prodsec/confused?label=%20) |
dependency-confusion |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
AWSBucketDump |
Security Tool to Look For Interesting Files in S3 Buckets |
![](https://img.shields.io/github/stars/jordanpotti/AWSBucketDump?label=%20) |
s3 |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
ppmap |
A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets. |
![](https://img.shields.io/github/stars/kleiton0x00/ppmap?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Scanner |
NoSQLMap |
Automated NoSQL database enumeration and web application exploitation tool. |
![](https://img.shields.io/github/stars/codingo/NoSQLMap?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
Chromium-based-XSS-Taint-Tracking |
Cyclops is a web browser with XSS detection feature, it is chromium-based xss detection that used to find the flows from a source to a sink. |
![](https://img.shields.io/github/stars/v8blink/Chromium-based-XSS-Taint-Tracking?label=%20) |
xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Scanner |
zap-cli |
A simple tool for interacting with OWASP ZAP from the commandline. |
![](https://img.shields.io/github/stars/Grunny/zap-cli?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![zap](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/zap.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Scanner |
ditto |
A tool for IDN homograph attacks and detection. |
![](https://img.shields.io/github/stars/evilsocket/ditto?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Exploit |
XXEinjector |
Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods. |
![](https://img.shields.io/github/stars/enjoiz/XXEinjector?label=%20) |
xxe |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Ruby](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/ruby.png) |
Exploit |
XXExploiter |
Tool to help exploit XXE vulnerabilities |
![](https://img.shields.io/github/stars/luisfontes19/xxexploiter?label=%20) |
xxe |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![TypeScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/typescript.png) |
Exploit |
XSRFProbe |
The Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit. |
![](https://img.shields.io/github/stars/0xInfection/XSRFProbe?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Exploit |
beef |
The Browser Exploitation Framework Project |
![](https://img.shields.io/github/stars/beefproject/beef?label=%20) |
xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Ruby](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/ruby.png) |
Exploit |
xxeserv |
A mini webserver with FTP support for XXE payloads |
![](https://img.shields.io/github/stars/staaldraad/xxeserv?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Exploit |
SQLNinja |
SQL Injection scanner |
|
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Exploit |
SQL Ninja |
SQL Injection scanner |
|
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Exploit |
singularity |
A DNS rebinding attack framework. |
![](https://img.shields.io/github/stars/nccgroup/singularity?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Exploit |
Liffy |
Local file inclusion exploitation tool |
![](https://img.shields.io/github/stars/mzfr/liffy?label=%20) |
lfi |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Exploit |
toxssin |
An XSS exploitation command-line interface and payload generator. |
![](https://img.shields.io/github/stars/t3l3machus/toxssin?label=%20) |
xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Exploit |
Sn1per |
Automated pentest framework for offensive security experts |
![](https://img.shields.io/github/stars/1N3/Sn1per?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Shell](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/shell.png) |
Exploit |
ropr |
A blazing fast™ multithreaded ROP Gadget finder. ropper |
![](https://img.shields.io/github/stars/Ben-Lichtman/ropr?label=%20) |
rop |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Rust](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/rust.png) |
Exploit |
Gopherus |
This tool generates gopher link for exploiting SSRF and gaining RCE in various servers |
![](https://img.shields.io/github/stars/tarunkant/Gopherus?label=%20) |
ssrf |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Utils |
slackcat |
CLI utility to post files and command output to slack |
![](https://img.shields.io/github/stars/bcicen/slackcat?label=%20) |
notify |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
gxss |
Blind XSS service alerting over slack or email |
![](https://img.shields.io/github/stars/rverton/gxss?label=%20) |
xss blind-xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
pentest-tools |
Custom pentesting tools |
![](https://img.shields.io/github/stars/gwen001/pentest-tools?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Utils |
pwncat |
pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully scriptable with Python (PSE) |
![](https://img.shields.io/github/stars/cytopia/pwncat?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Shell](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/shell.png) |
Utils |
cf-check |
Cloudflare Checker written in Go |
![](https://img.shields.io/github/stars/dwisiswant0/cf-check?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
urlgrab |
A golang utility to spider through a website searching for additional links. |
![](https://img.shields.io/github/stars/IAmStoxe/urlgrab?label=%20) |
url |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
Findsploit |
Find exploits in local and online databases instantly |
![](https://img.shields.io/github/stars/1N3/Findsploit?label=%20) |
exploit |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Shell](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/shell.png) |
Utils |
230-OOB |
An Out-of-Band XXE server for retrieving file contents over FTP. |
![](https://img.shields.io/github/stars/lc/230-OOB?label=%20) |
xxe |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Utils |
fzf |
A command-line fuzzy finder |
![](https://img.shields.io/github/stars/junegunn/fzf?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
difftastic |
a structural diff that understands syntax |
![](https://img.shields.io/github/stars/Wilfred/difftastic?label=%20) |
diff |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Rust](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/rust.png) |
Utils |
pet |
Simple command-line snippet manager, written in Go. |
![](https://img.shields.io/github/stars/knqyf263/pet?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
curl |
A command line tool and library for transferring data with URL syntax, supporting HTTP, HTTPS, FTP, FTPS, GOPHER, TFTP, SCP, SFTP, SMB, TELNET, DICT, LDAP, LDAPS, MQTT, FILE, IMAP, SMTP, POP3, RTSP and RTMP. libcurl offers a myriad of powerful features |
![](https://img.shields.io/github/stars/curl/curl?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![C](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/c.png) |
Utils |
IntruderPayloads |
|
![](https://img.shields.io/github/stars/1N3/IntruderPayloads?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![burp](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/burp.png) ![BlitzBasic](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/blitzbasic.png) |
Utils |
grex |
A command-line tool and library for generating regular expressions from user-provided test cases |
![](https://img.shields.io/github/stars/pemistahl/grex?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Rust](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/rust.png) |
Utils |
PoC-in-GitHub |
📡 PoC auto collect from GitHub. Be careful malware. |
![](https://img.shields.io/github/stars/nomi-sec/PoC-in-GitHub?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Utils |
jsfuck |
Write any JavaScript with 6 Characters |
![](https://img.shields.io/github/stars/aemkei/jsfuck?label=%20) |
xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Utils |
urlprobe |
Urls status code & content length checker |
![](https://img.shields.io/github/stars/1ndianl33t/urlprobe?label=%20) |
url |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
dnsobserver |
A handy DNS service written in Go to aid in the detection of several types of blind vulnerabilities. It monitors a pentester's server for out-of-band DNS interactions and sends lookup notifications via Slack. |
![](https://img.shields.io/github/stars/allyomalley/dnsobserver?label=%20) |
oast dns |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
boast |
The BOAST Outpost for AppSec Testing (v0.1.0) |
![](https://img.shields.io/github/stars/marcoagner/boast?label=%20) |
oast |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
github-regexp |
Basically a regexp over a GitHub search. |
![](https://img.shields.io/github/stars/gwen001/github-regexp?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
can-i-take-over-xyz |
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records. |
![](https://img.shields.io/github/stars/EdOverflow/can-i-take-over-xyz?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Utils |
mubeng |
An incredibly fast proxy checker & IP rotator with ease. |
![](https://img.shields.io/github/stars/kitabisa/mubeng?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
XSS-Catcher |
Find blind XSS but why not gather data while you're at it. |
![](https://img.shields.io/github/stars/daxAKAhackerman/XSS-Catcher?label=%20) |
xss blind-xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Utils |
weaponised-XSS-payloads |
XSS payloads designed to turn alert(1) into P1 |
![](https://img.shields.io/github/stars/hakluke/weaponised-XSS-payloads?label=%20) |
xss documents |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Utils |
xssor2 |
XSS'OR - Hack with JavaScript. |
![](https://img.shields.io/github/stars/evilcos/xssor2?label=%20) |
xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Utils |
gotestwaf |
An open-source project in Golang to test different web application firewalls (WAF) for detection logic and bypasses |
![](https://img.shields.io/github/stars/wallarm/gotestwaf?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
gron |
Make JSON greppable! |
![](https://img.shields.io/github/stars/tomnomnom/gron?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
hacks |
A collection of hacks and one-off scripts |
![](https://img.shields.io/github/stars/tomnomnom/hacks?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
hurl |
Hurl, run and test HTTP requests. |
![](https://img.shields.io/github/stars/Orange-OpenSource/hurl?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Rust](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/rust.png) |
Utils |
xless |
The Serverless Blind XSS App |
![](https://img.shields.io/github/stars/mazen160/xless?label=%20) |
xss blind-xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Utils |
ezXSS |
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting. |
![](https://img.shields.io/github/stars/ssl/ezXSS?label=%20) |
xss blind-xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![PHP](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/php.png) |
Utils |
Emissary |
Send notifications on different channels such as Slack, Telegram, Discord etc. |
![](https://img.shields.io/github/stars/BountyStrike/Emissary?label=%20) |
notify |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
Assetnote Wordlists |
Automated & Manual Wordlists provided by Assetnote |
![](https://img.shields.io/github/stars/assetnote/wordlists?label=%20) |
wordlist documents |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![CSS](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/css.png) |
Utils |
SequenceDiagram |
Online tool for creating UML sequence diagrams |
|
online |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Utils |
godeclutter |
Declutters URLs in a fast and flexible way, for improving input for web hacking automations such as crawlers and vulnerability scans. |
![](https://img.shields.io/github/stars/c3l3si4n/godeclutter?label=%20) |
url |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
wssip |
Application for capturing, modifying and sending custom WebSocket data from client to server and vice versa. |
![](https://img.shields.io/github/stars/nccgroup/wssip?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Utils |
blistener |
Blind-XSS listener with payloads |
![](https://img.shields.io/github/stars/fyxme/blistener?label=%20) |
xss blind-xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
SecLists |
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more. |
![](https://img.shields.io/github/stars/danielmiessler/SecLists?label=%20) |
wordlist documents |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![PHP](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/php.png) |
Utils |
gitls |
Listing git repository from URL/User/Org |
![](https://img.shields.io/github/stars/hahwul/gitls?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
hakcheckurl |
Takes a list of URLs and returns their HTTP response codes |
![](https://img.shields.io/github/stars/hakluke/hakcheckurl?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
Bug-Bounty-Toolz |
BBT - Bug Bounty Tools |
![](https://img.shields.io/github/stars/m4ll0k/Bug-Bounty-Toolz?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Utils |
security-crawl-maze |
Security Crawl Maze is a comprehensive testbed for web security crawlers. It contains pages representing many ways in which one can link resources from a valid HTML document. |
![](https://img.shields.io/github/stars/google/security-crawl-maze?label=%20) |
crawl |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![HTML](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/html.png) |
Utils |
grc |
generic colouriser |
![](https://img.shields.io/github/stars/garabik/grc?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Utils |
xss-cheatsheet-data |
This repository contains all the XSS cheatsheet data to allow contributions from the community. |
![](https://img.shields.io/github/stars/PortSwigger/xss-cheatsheet-data?label=%20) |
xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Utils |
Redcloud |
Automated Red Team Infrastructure deployement using Docker |
![](https://img.shields.io/github/stars/khast3x/Redcloud?label=%20) |
infra |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Utils |
qsreplace |
Accept URLs on stdin, replace all query string values with a user-supplied value |
![](https://img.shields.io/github/stars/tomnomnom/qsreplace?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
ysoserial.net |
Deserialization payload generator for a variety of .NET formatters |
![](https://img.shields.io/github/stars/pwntester/ysoserial.net?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![C#](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/c%23.png) |
Utils |
fff |
The Fairly Fast Fetcher. Requests a bunch of URLs provided on stdin fairly quickly. |
![](https://img.shields.io/github/stars/tomnomnom/fff?label=%20) |
url |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
wuzz |
Interactive cli tool for HTTP inspection |
![](https://img.shields.io/github/stars/asciimoo/wuzz?label=%20) |
http |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
bat |
A cat(1) clone with wings. |
![](https://img.shields.io/github/stars/sharkdp/bat?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Rust](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/rust.png) |
Utils |
interactsh |
An OOB interaction gathering server and client library |
![](https://img.shields.io/github/stars/projectdiscovery/interactsh?label=%20) |
oast |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
s3reverse |
The format of various s3 buckets is convert in one format. for bugbounty and security testing. |
![](https://img.shields.io/github/stars/hahwul/s3reverse?label=%20) |
s3 |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
gf |
A wrapper around grep, to help you grep for things |
![](https://img.shields.io/github/stars/tomnomnom/gf?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
burl |
A Broken-URL Checker |
![](https://img.shields.io/github/stars/tomnomnom/burl?label=%20) |
url |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
oxml_xxe |
A tool for embedding XXE/XML exploits into different filetypes |
![](https://img.shields.io/github/stars/BuffaloWill/oxml_xxe?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Ruby](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/ruby.png) |
Utils |
gotator |
Gotator is a tool to generate DNS wordlists through permutations. |
![](https://img.shields.io/github/stars/Josue87/gotator?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
TukTuk |
Tool for catching and logging different types of requests. |
![](https://img.shields.io/github/stars/ArturSS7/TukTuk?label=%20) |
oast |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
Phoenix |
hahwul's online tools |
|
online |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Utils |
graphql-voyager |
🛰️ Represent any GraphQL API as an interactive graph |
![](https://img.shields.io/github/stars/APIs-guru/graphql-voyager?label=%20) |
graphql |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![TypeScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/typescript.png) |
Utils |
Blacklist3r |
project-blacklist3r |
![](https://img.shields.io/github/stars/NotSoSecure/Blacklist3r?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![C#](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/c%23.png) |
Utils |
Atlas |
Quick SQLMap Tamper Suggester |
![](https://img.shields.io/github/stars/m4ll0k/Atlas?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Utils |
httpie |
As easy as /aitch-tee-tee-pie/ 🥧 Modern, user-friendly command-line HTTP client for the API era. JSON support, colors, sessions, downloads, plugins & more. https://twitter.com/httpie |
![](https://img.shields.io/github/stars/httpie/httpie?label=%20) |
http |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Utils |
unfurl |
Pull out bits of URLs provided on stdin |
![](https://img.shields.io/github/stars/tomnomnom/unfurl?label=%20) |
url |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
CyberChef |
The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis |
![](https://img.shields.io/github/stars/gchq/CyberChef?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Utils |
ob_hacky_slack |
Hacky Slack - a bash script that sends beautiful messages to Slack |
![](https://img.shields.io/github/stars/openbridge/ob_hacky_slack?label=%20) |
notify |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Shell](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/shell.png) |
Utils |
reverse-shell-generator |
Hosted Reverse Shell generator with a ton of functionality. -- (Great for CTFs) |
![](https://img.shields.io/github/stars/0dayCTF/reverse-shell-generator?label=%20) |
payload |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Utils |
ysoserial |
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization. |
![](https://img.shields.io/github/stars/frohoff/ysoserial?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Java](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/java.png) |
Utils |
httptoolkit |
HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac |
![](https://img.shields.io/github/stars/httptoolkit/httptoolkit?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Utils |
docem |
Uility to embed XXE and XSS payloads in docx,odt,pptx,etc (OXML_XEE on steroids) |
![](https://img.shields.io/github/stars/whitel1st/docem?label=%20) |
xxe xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Utils |
quickjack |
Quickjack is a point-and-click tool for intuitively producing advanced clickjacking and frame slicing attacks. |
![](https://img.shields.io/github/stars/samyk/quickjack?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Utils |
CSP Evaluator |
Online CSP Evaluator from google |
|
csp |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Utils |
bountyplz |
Automated security reporting from markdown templates (HackerOne and Bugcrowd are currently the platforms supported) |
![](https://img.shields.io/github/stars/fransr/bountyplz?label=%20) |
report |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Shell](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/shell.png) |
Utils |
gee |
🏵 Gee is tool of stdin to each files and stdout. It is similar to the tee command, but there are more functions for convenience. In addition, it was written as go |
![](https://img.shields.io/github/stars/hahwul/gee?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Utils |
security-research-pocs |
Proof-of-concept codes created as part of security research done by Google Security Team. |
![](https://img.shields.io/github/stars/google/security-research-pocs?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![C++](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/c++.png) |
Utils |
autochrome |
This tool downloads, installs, and configures a shiny new copy of Chromium. |
![](https://img.shields.io/github/stars/nccgroup/autochrome?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![HTML](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/html.png) |
Utils |
template-generator |
A simple variable based template editor using handlebarjs+strapdownjs. The idea is to use variables in markdown based files to easily replace the variables with content. Data is saved temporarily in local storage. PHP is only needed to generate the list of files in the dropdown of templates. |
![](https://img.shields.io/github/stars/fransr/template-generator?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![JavaScript](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/javascript.png) |
Utils |
Gf-Patterns |
GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic) parameters grep |
![](https://img.shields.io/github/stars/1ndianl33t/Gf-Patterns?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) |
Utils |
PayloadsAllTheThings |
A list of useful payloads and bypass for Web Application Security and Pentest/CTF |
![](https://img.shields.io/github/stars/swisskyrepo/PayloadsAllTheThings?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Utils |
tiscripts |
Turbo Intruder Scripts |
![](https://img.shields.io/github/stars/defparam/tiscripts?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Utils |
hbxss |
Security test tool for Blind XSS |
![](https://img.shields.io/github/stars/hahwul/hbxss?label=%20) |
xss blind-xss |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Ruby](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/ruby.png) |
Utils |
anew |
A tool for adding new lines to files, skipping duplicates |
![](https://img.shields.io/github/stars/tomnomnom/anew?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Go](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/go.png) |
Env |
Glue |
Application Security Automation |
![](https://img.shields.io/github/stars/OWASP/glue?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Ruby](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/ruby.png) |
Env |
Crimson |
Web Application Security Testing automation. |
![](https://img.shields.io/github/stars/Karmaz95/crimson?label=%20) |
|
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Python](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/python.png) |
Env |
pentest-env |
Pentest environment deployer (kali linux + targets) using vagrant and chef. |
![](https://img.shields.io/github/stars/Sliim/pentest-env?label=%20) |
pentest |
![linux](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/linux.png) ![macos](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/apple.png) ![windows](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/windows.png) ![Ruby](/Awesome-Mirrors/WebHackersWeapons/media/commit/d19a201a32d8e9db68c07adbed4708583824730c/images/ruby.png) |