Open Source Security Arsenal
Curated intelligence repository of battle-tested open-source security tools, exploits, and pentesting frameworks.
Security Tools
[EXPLOIT] NoSQLMap - PoC Exploit
UnknownNoSQLMap Automated NoSQL database enumeration and web application exploitation tool.
nmap-vulners Nmap NSE scripts that turn a service scan into CVEs, CVSS scores and known exploits — fingerprints software from HTTP responses and checks every detected CPE against the Vulners database.
[EXPLOIT] K8tools - PoC Exploit
UnknownK8tools K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)
w9scan - Security Tool
Unknownw9scan Plug-in type web vulnerability scanner
Web-Cache-Vulnerability-Scanner Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).
BlackWidow - Security Tool
UnknownBlackWidow A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.
wapiti - Security Tool
Unknownwapiti Web vulnerability scanner written in Python3
rapidscan - Security Tool
Unknownrapidscan :new: The Multi-Tool Web Vulnerability Scanner.
BBScan - Security Tool
UnknownBBScan A fast vulnerability scanner helps pentesters pinpoint possibly vulnerable targets from a large number of web servers
crawlergo - Security Tool
Unknowncrawlergo A powerful browser crawler for web vulnerability scanners
w3af - Security Tool
Unknownw3af w3af: web application attack and audit framework, the open source web vulnerability scanner.
awesome-web-hacking A list of web application security