CAZT (Cloud AuthoriZation Trainer) CAZT (Cloud AuthoriZation Trainer) is a simulator of cloud-provider responsible REST APIs. It...
WebApp PenTest
EasyScan EasyScan is a Python script that analyzes the security of a given website by inspecting its...
shortscan Shortscan is designed to quickly determine which files with short filenames exist on an IIS webserver....
RedCloud OS RedCloud OS is a Debian-based Cloud Adversary Simulation Operating System for Red Teams to assess the...
OSINT Toolkit OSINT Toolkit is a full-stack web application designed to assist security analysts in their work....
EscalateGPT A powerful Python tool that leverages the power of OpenAI to analyze AWS IAM misconfigurations. Features...
Sucosh Scanny “Sucosh” is an automated Source Code vulnerability scanner(SAST) and assessment framework for Python(Flask-Django) & NodeJs...
Session Hijacking Visual Exploitation Session Hijacking Visual Exploitation is a tool that allows for the hijacking of...
Pentest Mapper Pentest Mapper is a Burp Suite extension that integrates the Burp Suite request logging with...
HTMLSmuggler HTMLSmuggler – JS payload generator for IDS bypass and payload delivery via HTML smuggling. The primary...
AtlasReaper AtlasReaper is a command-line tool developed for offensive security purposes, primarily focused on a reconnaissance of...
KnockKnock Designed to validate potential usernames by querying OneDrive and/or Microsoft Teams, which are passive methods. Additionally,...
NucleiFuzzer = Nuclei + Paramspider NucleiFuzzer is an automation tool that combines ParamSpider and Nuclei to enhance web application...
web-check Get an insight into the inner workings of a given website: uncover potential attack vectors, analyse...
Pinkerton Pinkerton is a Python tool created to crawl JavaScript files and search for secrets. Features Works...