APIsec
APIsec detects real API risks legacy scanners miss, integrated into your pipeline.
aikido
DAST tool for monitoring apps/APIs to detect OWASP risks like XSS, SQLi, and CSRF.
getallurls
Fetches known URLs for a domain from OTX, Wayback, Common Crawl, and URLScan.
void
macOS domain blocker that prevents access to distracting sites using pf firewall rules.
HTTP Observatory
Scanner that checks websites for compliance with recommended security best practices.
vim-plug
Intelligent terminal for developers focused on productivity and collaboration.
cdncheck
Identifies technologies linked to DNS/IP addresses for infrastructure reconnaissance.
useragent
Comprehensive, categorized collection of User Agents for analysis and fingerprinting.
DSL
Library to create and evaluate expressions to filter, compare, or transform data sets.
shuffledns
Massdns wrapper for subdomain bruteforce and resolution with wildcard handling support.
cleanhttp
Library to detect and filter wildcard HTTP servers using signature-based rules.
Interactsh
Tool to detect out-of-band (OOB) interactions triggered by vulnerabilities.
httpx
Fast HTTP toolkit for reliable probing using multi-threading and retryable HTTP requests.
nuclei
Fast vulnerability scanner using YAML templates for accurate and customizable detection.
Awesome Search Queries
Community-driven list of OSINT queries for multiple search engines and research purposes.
rawhttp
Go library for sending HTTP requests with full control and minimal validation.
ffuf
Fast web fuzzer for discovering hidden files and directories in web applications.
fff
Fast URL fetcher sending parallel requests at intervals without waiting for responses.
waybackurls
Fetches historical URLs for domains from the Wayback Machine for surface analysis.