Not The Hidden Wiki
- Burp Suite - link
- WAF Bypass - link
- Burp Alternatinve: Caido - link
- Nessus - link
- runZero - link
- nikto - link
- nuclei - link
- XSSCon - link
- Bug Bounty Hunting Search Engine - link
- Shrewdeye APp - link
- IIS Short Name Scanner - link
- DorkGPT - link
- Generate Custom Dorks - link
- reNgine: Automated reconnaissance - link
- API Hidden Endpoints - link
- ffuf - link
- katana - link
- feroxbuster - link
- Wordpress Plugin Scraper - link
- Oracle Database Attacking Tool - link
- SSRF Scanner - link
- Webhook site - link
- Beef - link
- Excessy - link
- DOM Invader - link
- Secret Finder - link
- Web App Security Testing Tools - link
- OWASP Nettacker - link
- Web Cache Vulnerability Scanner - link
- CSP Evaluator - link
- Web Check - link
- DNS Rebinder - link
- arjun: HTTP parameter discovery suite. - link
- arsenal: Powerful weapons for penetration testing. - link
- assetfinder: Tool to find subdomains and IP addresses associated with a domain. - link
- byp4xx: A Swiss Army knife for bypassing web application firewalls and filters. - link
- corscanner: a Python script for finding CORS misconfigurations. - link
- dirb: Web Content Scanner - link
- dirsearch: Tool for searching files and directories on a web site. - link
- divideandscan: Advanced subdomain scanner - link
- droopescan: Scan Drupal websites for vulnerabilities. - link
- drupwn: Drupal security scanner. - link
- ssrfmap: a tool for testing SSRF vulnerabilities. - link
- sslscan: a tool for testing SSL/TLS encryption on servers - link
- finalrecon: A web reconnaissance tool that gathers information about web pages - link
- fuxploider: a Python tool for finding and exploiting file upload forms/directories. - link
- xsser: XSS scanner. - link
- wpscan: A tool to enumerate WordPress-based websites - link
- h2csmuggler: HTTP Request Smuggling tool using H2C upgrade - link
- PHP filter chain generator - link
- git-dumper: Small script to dump a Git repository from a website - link
- gittools: A collection of Git tools including a powerful Dumper - link
- gobuster: Tool to discover hidden files and directories. - link
- gopherus: Gopherus is a simple command line tool for exploiting vulnerable Gopher servers. - link
- goshs: Goshs is a replacement for Python’s SimpleHTTPServer - link
- hakrawler: a fast web crawler for gathering URLs and other information from websites - link
- hakrevdns: Reverse DNS lookup - link
- httpmethods: Tool for exploiting HTTP methods- link
- httpx: A tool for identifying web technologies and vulnerabilities - link
- joomscan: A tool to enumerate Joomla-based websites - link
- kadimus: a tool for detecting and exploiting file upload vulnerabilities - link
- ldeep: ldeep is a tool to discover hidden paths on Web servers - link
- masscan: Masscan is an Internet-scale port scanner - link
- moodlescan: Scan Moodle sites for information and vulnerabilities. - link
- nosqlmap: a Python tool for testing NoSQL databases for security vulnerabilities. - link
- oneforall: a powerful subdomain collection tool. - link
- rustscan: The Modern Port Scanner - link
- sqlmap - link
- sublist3r: a Python tool designed to enumerate subdomains of websites. - link
- symfony-exploits: Collection of Symfony exploits and PoCs. - link
- tls-map: tls-map is a library for mapping TLS cipher algorithm names. - link
- tls-scanner: a simple script to check the security of a remote TLS/SSL web server - link
- webclientservicescanner: Scans for web service endpoints - link
- XSpear: a powerful XSS scanning and exploitation tool. - link
- xsrfprobe: a tool for detecting and exploiting Cross-Site Request Forgery (CSRF) vulnerabilities - link
- xsstrike: a Python tool for detecting and exploiting XSS vulnerabilities. - link
- ysoserial: generating payloads that exploit unsafe Java object deserialization. - link
- pp-finder: Prototype pollution finder tool for javascript - link
- subfinder: Tool to find subdomains - link
- Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3 - link
- Burp Suite alternative - link
- SubDomainRadar.io: Find subdomains with unparalleled accuracy and speed. - link
- Merklemap: Subdomain Search Engine - link
- Beyond XSS: Explore the Web Front-end Security Universe - link