Automated NoSQL database enumeration and web application exploitation tool.
-
Updated
Aug 26, 2025 - Python
Automated NoSQL database enumeration and web application exploitation tool.
Offensive Web Testing Framework (OWTF), is a framework which tries to unite great tools and make pen testing more efficient http://owtf.org https://twitter.com/owtfp
The Offensive Manual Web Application Penetration Testing Framework.
A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.
A cross-platform python based utility for information gathering and penetration testing automation!
A Security Tool for Enumerating WebSockets
A massive, curated collection of information security books, study guides, cheat sheets, and resources. This library is intended for educational purposes and to help those who cannot otherwise access this material.
Metasploit-like pentest framework derived from TIDoS (https://github.com/0xInfection/TIDoS-Framework)
An application to catch, search and analyze HTTP secure headers.
Juniper Firewalls CVE-2023-36845 - RCE
Host Header Injection Scanner
A security tool designed to perform thorough scans on a target using OpenVAS, Zap, and Nexpose. It seamlessly consolidates and integrates the scan results, providing a comprehensive overview of the security vulnerabilities identified.
TimeVault is a specialized automated tool designed to detect potential information disclosure vulnerabilities in web applications by leveraging archived URLs from the Wayback Machine.
An Advanced Web Application Firewall that protects against threats like SQL injection and XSS by filtering HTTP traffic. It combines signature-based detection and machine learning-based anomaly detection to identify obfuscated, zero-day, and unknown attacks through behavioral analysis.
An ongoing collection of awesome ethical hacking tools, software, libraries, learning tutorials, frameworks, academic and practical resources
HAProxy (community) Lua Plugin for JA4 TLS Client-Fingerprinting
Web Application Penetration Testing tools and Materials for Ethical Hackers.
Hands-on secure code review training: learn to find vulnerabilities in Flask, Django, FastAPI through production-quality examples. Whitebox pentesting for modern web frameworks.
Apache HugeGraph Server Unauthenticated RCE - CVE-2024-27348 Proof of concept Exploit
Add a description, image, and links to the web-application-security topic page so that developers can more easily learn about it.
To associate your repository with the web-application-security topic, visit your repo's landing page and select "manage topics."