Automated NoSQL database enumeration and web application exploitation tool.
-
Updated
Feb 20, 2026 - Python
Automated NoSQL database enumeration and web application exploitation tool.
Offensive Web Testing Framework (OWTF), is a framework which tries to unite great tools and make pen testing more efficient http://owtf.org https://twitter.com/owtfp
The Offensive Manual Web Application Penetration Testing Framework.
An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses
A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.
JANUSEC Application Gateway provides secure access, including reverse proxy, K8S Ingress Controller, Automatic ACME Certificate, WAF, 5-Second Shield, CC Defense, OAuth2 Authentication, Global Server Load Balance, and Cookie Compliance etc. JANUSEC应用网关,提供安全的接入,包括反向代理、K8S Ingress Controller、自动化ACME证书、WAF、5秒盾、CC防御、OAuth2身份认证、GSLB负载均衡与Cookie合规等。
Lonkero - Wraps around your attack surface. Professional-grade scanner for real penetration testing. Fast. Modular. Rust.
Bug Bounty Tricks and useful payloads and bypasses for Web Application Security.
Pentesting and Bug Bounty Notes, Cheetsheets and Guide for Ethical Hacker, Whitehat Pentesters and CTF Players.
Fast and light-weight API proxy firewall for request and response validation by OpenAPI specs.
A collection of FREE cyber security books
List of CyberSecurity Resources and some different Sub-Domains of CyberSecurity
Find All Parameters - Tool to crawl pages, find potential parameters and generate a custom target parameter wordlist
A cross-platform python based utility for information gathering and penetration testing automation!
Second-order subdomain takeover scanner
Master cybersecurity skills with this TryHackMe free path, includes a collection of my write-ups, solutions and progress tracking.
A Security Tool for Enumerating WebSockets
✂️ Removing CDN IPs from the list of IP addresses
Awesome information for WebSockets security research
Add a description, image, and links to the web-application-security topic page so that developers can more easily learn about it.
To associate your repository with the web-application-security topic, visit your repo's landing page and select "manage topics."