WebHackersWeapons
  
  
    ⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting 
    https://github.com/hahwul/WebHackersWeapons
  
        Last synced: about 9 hours ago 
        JSON representation
    
- 
            
Weapons
- 
                    
Tools
- h2spacex - condition`](/categorize/tags/race-condition.md)|[](/categorize/langs/Python.md)|
 - race-the-web - specified number of requests to a target URL (or URLs) simultaneously, and then compares the responses from the server for uniqueness.||[`race-condition`](/categorize/tags/race-condition.md)|[](/categorize/langs/Go.md)|
 - Amass - depth Attack Surface Mapping and Asset Discovery ||[`subdomains`](/categorize/tags/subdomains.md)|[](/categorize/langs/Go.md)|
 - BurpSuite - audit`](/categorize/tags/live-audit.md) [`crawl`](/categorize/tags/crawl.md)|[](/categorize/langs/Java.md)|
 - Caido
 - Echo Mirage
 - Shodan - connected devices||[`osint`](/categorize/tags/osint.md)||
 - axiom
 - jaeles - project/jaeles?label=%20)|[`live-audit`](/categorize/tags/live-audit.md)|[](/categorize/langs/Go.md)|
 - Metasploit - framework?label=%20)|[`pentest`](/categorize/tags/pentest.md)|[](/categorize/langs/Ruby.md)|
 - ZAP - audit`](/categorize/tags/live-audit.md) [`crawl`](/categorize/tags/crawl.md)|[](/categorize/langs/Java.md)|
 - proxify
 - hetty
 - Glorp - based HTTP intercept and replay proxy||[`mitmproxy`](/categorize/tags/mitmproxy.md)|[](/categorize/langs/Go.md)|
 - mitmproxy - capable intercepting HTTP proxy for penetration testers and software developers.||[`mitmproxy`](/categorize/tags/mitmproxy.md)|[](/categorize/langs/Python.md)|
 - EvilProxy - proxy?label=%20)|[`mitmproxy`](/categorize/tags/mitmproxy.md)|[](/categorize/langs/Ruby.md)|
 - knock
 - meg - without killing the hosts |||[](/categorize/langs/Go.md)|
 - xnLinkFinder - h4ck3r/xnLinkFinder?label=%20)|[`js-analysis`](/categorize/tags/js-analysis.md)|[](/categorize/langs/Python.md)|
 - dnsprobe
 - noir - cr/noir?label=%20)|[`endpoint`](/categorize/tags/endpoint.md) [`url`](/categorize/tags/url.md) [`attack-surface`](/categorize/tags/attack-surface.md)|[](/categorize/langs/Crystal.md)|
 - gowitness - a golang, web screenshot utility using Chrome Headless |||[](/categorize/langs/Go.md)|
 - recon_profile
 - hakrawler
 - htcat
 - subfinder
 - Silver
 - Smap - in replacement for Nmap powered by shodan.io||[`port`](/categorize/tags/port.md)|[](/categorize/langs/Go.md)|
 - graphw00f
 - JSFScan.sh - analysis`](/categorize/tags/js-analysis.md)|[](/categorize/langs/Shell.md)|
 - gau
 - ParamSpider
 - subgen - to pipe into your favourite resolver!||[`subdomains`](/categorize/tags/subdomains.md)|[](/categorize/langs/Go.md)|
 - Sub404 - pr0xy/sub404?label=%20)|[`subdomains`](/categorize/tags/subdomains.md) [`takeover`](/categorize/tags/takeover.md)|[](/categorize/langs/Go.md)|
 - gobuster
 - fhc
 - aquatone
 - shosubgo
 - haktrails
 - intrigue-core - core?label=%20)||[](/categorize/langs/Ruby.md)|
 - github-endpoints - endpoints?label=%20)||[](/categorize/langs/Go.md)|
 - goverview - Get an overview of the list of URLs||[`url`](/categorize/tags/url.md)|[](/categorize/langs/Go.md)|
 - assetfinder
 - waybackurls
 - cc.py
 - shuffledns - output support. ||[`dns`](/categorize/tags/dns.md)|[](/categorize/langs/Go.md)|
 - getJS - analysis`](/categorize/tags/js-analysis.md)|[](/categorize/langs/Go.md)|
 - subs_all
 - csprecon
 - puredns
 - jsluice - analysis`](/categorize/tags/js-analysis.md)|[](/categorize/langs/Go.md)|
 - cariddi
 - subjack
 - Photon
 - dirsearch
 - bbot
 - parameth - /parameth?label=%20)||[](/categorize/langs/Python.md)|
 - spiderfoot
 - zdns
 - SubOver
 - lazyrecon
 - katana - generation crawling and spidering framework.||[`crawl`](/categorize/tags/crawl.md)|[](/categorize/langs/Go.md)|
 - dnsx - purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.||[`dns`](/categorize/tags/dns.md)|[](/categorize/langs/Go.md)|
 - gauplus
 - BLUTO
 - HostHunter
 - BugBountyScanner
 - gitrob
 - rengine
 - HydraRecon
 - rusolver
 - apkleaks
 - longtongue
 - reconftw
 - masscan
 - chaos-client - client?label=%20)||[](/categorize/langs/Go.md)|
 - megplus
 - Hunt3r
 - subjs
 - dnsvalidator
 - github-subdomains - subdomains?label=%20)|[`subdomains`](/categorize/tags/subdomains.md)|[](/categorize/langs/Go.md)|
 - crawlergo
 - favirecon
 - GitMiner
 - hakrevdns
 - LinkFinder - analysis`](/categorize/tags/js-analysis.md)|[](/categorize/langs/Python.md)|
 - Osmedeus
 - FavFreak
 - STEWS
 - naabu
 - dmut
 - OneForAll
 - x8
 - urlhunter
 - sn0int - automatic OSINT framework and package manager||[`osint`](/categorize/tags/osint.md)|[](/categorize/langs/Rust.md)|
 - CT_subdomains
 - scilla
 - 3klCon
 - uncover
 - Lepus
 - Arjun
 - go-dork - dork?label=%20)||[](/categorize/langs/Go.md)|
 - subzy
 - pagodo - Automate Google Hacking Database scraping and searching|||[](/categorize/langs/Python.md)|
 - Sudomy
 - gospider - Fast web spider written in Go ||[`crawl`](/categorize/tags/crawl.md)|[](/categorize/langs/Go.md)|
 - httpx - purpose HTTP toolkit allow to run multiple probers using retryablehttp library, it is designed to maintain the result reliability with increased threads. ||[`url`](/categorize/tags/url.md)|[](/categorize/langs/Go.md)|
 - SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files |||[](/categorize/langs/Python.md)|
 - altdns - au/altdns?label=%20)|[`dns`](/categorize/tags/dns.md) [`subdomains`](/categorize/tags/subdomains.md)|[](/categorize/langs/Python.md)|
 - Parth
 - uro
 - feroxbuster
 - BatchQL
 - jwt-cracker - cracker?label=%20)|[`jwt`](/categorize/tags/jwt.md)|[](/categorize/langs/JavaScript.md)|
 - GraphQLmap
 - CrackQL - force and fuzzing utility.||[`graphql`](/categorize/tags/graphql.md)|[](/categorize/langs/Python.md)|
 - medusa
 - crlfuzz
 - c-jwt-cracker - rius/c-jwt-cracker?label=%20)|[`jwt`](/categorize/tags/jwt.md)|[](/categorize/langs/C.md)|
 - jwt-hack - hack is tool for hacking / security testing to JWT. Supported for En/decoding JWT, Generate payload for JWT attack and very fast cracking(dict/brutefoce)||[`jwt`](/categorize/tags/jwt.md)|[](/categorize/langs/Go.md)|
 - ffuf
 - BruteX
 - SmuggleFuzz
 - SSRFire
 - fuzzparam
 - headerpwn
 - ParamPamPam - vuln`](/categorize/tags/cache-vuln.md)|[](/categorize/langs/Python.md)|
 - dotdotpwn - The Directory Traversal Fuzzer ||[`path-traversal`](/categorize/tags/path-traversal.md)|[](/categorize/langs/Perl.md)|
 - kiterunner
 - thc-hydra - thc/thc-hydra?label=%20)||[](/categorize/langs/C.md)|
 - SSRFmap
 - wfuzz
 - Clairvoyance
 - SSTImap
 - LFISuite
 - xsscrapy
 - hinject
 - DSSS
 - httprobe
 - rapidscan - Tool Web Vulnerability Scanner. |||[](/categorize/langs/Python.md)|
 - XSStrike
 - confused - prodsec/confused?label=%20)|[`dependency-confusion`](/categorize/tags/dependency-confusion.md)|[](/categorize/langs/Go.md)|
 - sqliv - robot/sqliv?label=%20)|[`sqli`](/categorize/tags/sqli.md)|[](/categorize/langs/Python.md)|
 - Chromium-based-XSS-Taint-Tracking - based xss detection that used to find the flows from a source to a sink.||[`xss`](/categorize/tags/xss.md)||
 - NoSQLMap
 - FockCache - vuln`](/categorize/tags/cache-vuln.md)|[](/categorize/langs/Go.md)|
 - autopoisoner - vuln`](/categorize/tags/cache-vuln.md)|[](/categorize/langs/Python.md)|
 - dalfox - source XSS scanner and utility focused on automation.||[`xss`](/categorize/tags/xss.md)|[](/categorize/langs/Go.md)|
 - plution - pollution`](/categorize/tags/prototype-pollution.md)|[](/categorize/langs/Go.md)|
 - nikto
 - PPScan - pollution`](/categorize/tags/prototype-pollution.md)|[](/categorize/langs/JavaScript.md)|
 - xsser - framework- to detect, exploit and report XSS vulnerabilities in web-based applications. ||[`xss`](/categorize/tags/xss.md)|[](/categorize/langs/Python.md)|
 - SQLiDetector
 - web_cache_poison - Top 1 web hacking technique of 2019||[`cache-vuln`](/categorize/tags/cache-vuln.md)|[](/categorize/langs/Shell.md)|
 - nuclei
 - xsinator.com - Leak Browser Test Suite|||[](/categorize/langs/JavaScript.md)|
 - XSpear
 - domdig
 - h2csmuggler
 - dontgo403
 - http-request-smuggling - request-smuggling?label=%20)||[](/categorize/langs/Python.md)|
 - smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3 ||[`smuggle`](/categorize/tags/smuggle.md)|[](/categorize/langs/Python.md)|
 - VHostScan - all scenarios, work around wildcards, aliases and dynamic default pages. |||[](/categorize/langs/Python.md)|
 - pphack - Side Prototype Pollution Scanner||[`prototypepollution`](/categorize/tags/prototypepollution.md) [`prototype-pollution`](/categorize/tags/prototype-pollution.md)|[](/categorize/langs/Go.md)|
 - Striker
 - CorsMe
 - Corsy
 - Oralyzer
 - ditto
 - Web-Cache-Vulnerability-Scanner - based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).||[`cache-vuln`](/categorize/tags/cache-vuln.md)|[](/categorize/langs/Go.md)|
 - github-search - search?label=%20)||[](/categorize/langs/JavaScript.md)|
 - DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:||[`xss`](/categorize/tags/xss.md)|[](/categorize/langs/JavaScript.md)|
 - V3n0M-Scanner - Scanner/V3n0M-Scanner?label=%20)|[`sqli`](/categorize/tags/sqli.md) [`xss`](/categorize/tags/xss.md) [`lfi`](/categorize/tags/lfi.md) [`rfi`](/categorize/tags/rfi.md)|[](/categorize/langs/Python.md)|
 - nmap - the Network Mapper. Github mirror of official SVN repository. ||[`portscan`](/categorize/tags/portscan.md)|[](/categorize/langs/C.md)|
 - a2sv
 - jsprime - analysis`](/categorize/tags/js-analysis.md)|[](/categorize/langs/JavaScript.md)|
 - headi
 - sqlmap
 - AWSBucketDump
 - http2smugl - > HTTP/1.1 conversion by the frontend server.|||[](/categorize/langs/Go.md)|
 - DeepViolet
 - gitGraber
 - deadlinks - link`](/categorize/tags/broken-link.md)|[](/categorize/langs/Python.md)|
 - commix - in-One OS Command Injection Exploitation Tool.||[`exploit`](/categorize/tags/exploit.md)|[](/categorize/langs/Python.md)|
 - findom-xss - xss?label=%20)|[`xss`](/categorize/tags/xss.md)|[](/categorize/langs/Shell.md)|
 - HRS - Labs/HRS?label=%20)||[](/categorize/langs/Perl.md)|
 - websocket-connection-smuggler - connection-smuggler||[`smuggle`](/categorize/tags/smuggle.md)|[](/categorize/langs/Go.md)|
 - corsair_scan - Origin Resource Sharing (CORS).||[`cors`](/categorize/tags/cors.md)|[](/categorize/langs/Python.md)|
 - tplmap - Side Template Injection and Code Injection Detection and Exploitation Tool|||[](/categorize/langs/Python.md)|
 - DeadFinder - links (broken links)||[`broken-link`](/categorize/tags/broken-link.md)|[](/categorize/langs/Ruby.md)|
 - ppmap - side Prototype Pollution to XSS by exploiting known gadgets.||[`prototypepollution`](/categorize/tags/prototypepollution.md) [`prototype-pollution`](/categorize/tags/prototype-pollution.md)|[](/categorize/langs/Go.md)|
 - OpenRedireX
 - S3cret Scanner
 - ws-smuggler - smuggler?label=%20)|[`smuggle`](/categorize/tags/smuggle.md)|[](/categorize/langs/Go.md)|
 - ssrf-sheriff - testing sheriff written in Go ||[`ssrf`](/categorize/tags/ssrf.md)|[](/categorize/langs/Go.md)|
 - zap-cli - cli?label=%20)||[](/categorize/langs/Python.md)|
 - DirDar - Forbidden) directories to break it and get dir listing on it||[`403`](/categorize/tags/403.md)|[](/categorize/langs/Go.md)|
 - Taipan
 - wpscan - commercial use, black box WordPress Vulnerability Scanner written for security professionals and blog maintainers to test the security of their WordPress websites. |||[](/categorize/langs/Ruby.md)|
 - S3Scanner
 - arachni
 - ghauri - platform tool that automates the process of detecting and exploiting SQL injection security flaws||[`sqli`](/categorize/tags/sqli.md)|[](/categorize/langs/Python.md)|
 - SQLNinja
 - of-CORS - CORS?label=%20)|[`cors`](/categorize/tags/cors.md)|[](/categorize/langs/Python.md)|
 - beef
 - Gopherus
 - Sn1per
 - BaRMIe
 - XXEinjector
 - toxssin - line interface and payload generator.||[`xss`](/categorize/tags/xss.md)|[](/categorize/langs/Python.md)|
 - xxeserv
 - Liffy
 - ropr - Lichtman/ropr?label=%20)|[`rop`](/categorize/tags/rop.md)|[](/categorize/langs/Rust.md)|
 - XXExploiter
 - singularity
 - XSRFProbe
 - weaponised-XSS-payloads - XSS-payloads?label=%20)|[`xss`](/categorize/tags/xss.md) [`documents`](/categorize/tags/documents.md)|[](/categorize/langs/JavaScript.md)|
 - hurl - OpenSource/hurl?label=%20)||[](/categorize/langs/Rust.md)|
 - pentest-tools - tools?label=%20)||[](/categorize/langs/Python.md)|
 - dnsobserver - of-band DNS interactions and sends lookup notifications via Slack. ||[`oast`](/categorize/tags/oast.md) [`dns`](/categorize/tags/dns.md)|[](/categorize/langs/Go.md)|
 - missing-cve-nuclei-templates - cve-nuclei-templates?label=%20)|[`nuclei-templates`](/categorize/tags/nuclei-templates.md)|[](/categorize/langs/Txt.md)|
 - curl
 - xss-cheatsheet-data - cheatsheet-data?label=%20)|[`xss`](/categorize/tags/xss.md)||
 - cent - templates`](/categorize/tags/nuclei-templates.md)|[](/categorize/langs/Go.md)|
 - grc
 - interactsh
 - CyberChef - a web app for encryption, encoding, compression and data analysis |||[](/categorize/langs/JavaScript.md)|
 - grex - line tool and library for generating regular expressions from user-provided test cases|||[](/categorize/langs/Rust.md)|
 - gitls
 - jsfuck
 - github-regexp - regexp?label=%20)||[](/categorize/langs/Go.md)|
 - bat
 - XSS-Catcher - Catcher?label=%20)|[`xss`](/categorize/tags/xss.md) [`blind-xss`](/categorize/tags/blind-xss.md)|[](/categorize/langs/Python.md)|
 - ysoserial.net
 - ZipBomb
 - wuzz
 - IntruderPayloads
 - unfurl
 - wssip
 - gotestwaf - source project in Golang to test different web application firewalls (WAF) for detection logic and bypasses|||[](/categorize/langs/Go.md)|
 - gron
 - gotator
 - ezXSS - xss`](/categorize/tags/blind-xss.md)|[](/categorize/langs/PHP.md)|
 - Atlas
 - fzf - line fuzzy finder|||[](/categorize/langs/Go.md)|
 - blistener - XSS listener with payloads||[`xss`](/categorize/tags/xss.md) [`blind-xss`](/categorize/tags/blind-xss.md)|[](/categorize/langs/Go.md)|
 - TukTuk
 - hacks - off scripts |||[](/categorize/langs/Go.md)|
 - oxml_xxe
 - template-generator - generator?label=%20)||[](/categorize/langs/JavaScript.md)|
 - Findsploit
 - hbxss - xss`](/categorize/tags/blind-xss.md)|[](/categorize/langs/Ruby.md)|
 - reverse-shell-generator - - (Great for CTFs)||[`payload`](/categorize/tags/payload.md)|[](/categorize/langs/JavaScript.md)|
 - security-research-pocs - of-concept codes created as part of security research done by Google Security Team.|||[](/categorize/langs/C++.md)|
 - httptoolkit - source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac||||
 - gee
 - PayloadsAllTheThings
 - Redcloud
 - GadgetProbe
 - ysoserial - of-concept tool for generating payloads that exploit unsafe Java object deserialization. ||[`deserialize`](/categorize/tags/deserialize.md)|[](/categorize/langs/Java.md)|
 - Gf-Patterns - Patterns?label=%20)|||
 - eoyc
 - SecLists
 - gxss - xss`](/categorize/tags/blind-xss.md)|[](/categorize/langs/Go.md)|
 - bountyplz
 - Assetnote Wordlists
 - Clipboard
 - dsieve
 - GQLSpection
 - gf
 - cf-check - check?label=%20)||[](/categorize/langs/Go.md)|
 - docem
 - hoppscotch
 - Emissary
 - pet - line snippet manager, written in Go.|||[](/categorize/langs/Go.md)|
 - s3reverse
 - PoC-in-GitHub - sec/PoC-in-GitHub?label=%20)|||
 - hakcheckurl
 - bruteforce-lists - robbie/bruteforce-lists?label=%20)|[`wordlist`](/categorize/tags/wordlist.md) [`documents`](/categorize/tags/documents.md)|[](/categorize/langs/Txt.md)|
 - can-i-take-over-xyz - i-take-over-xyz?label=%20)|||
 - qsreplace - supplied value |||[](/categorize/langs/Go.md)|
 - slackcat
 - REcollapse - box regex fuzzing to bypass validations and discover normalizations in web applications||[`fuzz`](/categorize/tags/fuzz.md)|[](/categorize/langs/Python.md)|
 - fff
 - nuclei-templates - templates?label=%20)|[`nuclei-templates`](/categorize/tags/nuclei-templates.md)|[](/categorize/langs/Go.md)|
 - Blacklist3r - blacklist3r |||[](/categorize/langs/C%23.md)|
 - SerializationDumper
 - xless - xss`](/categorize/tags/blind-xss.md)|[](/categorize/langs/JavaScript.md)|
 - security-crawl-maze - crawl-maze?label=%20)|[`crawl`](/categorize/tags/crawl.md)|[](/categorize/langs/HTML.md)|
 - anew
 - urlprobe
 - difftastic
 - autochrome
 - quickjack - and-click tool for intuitively producing advanced clickjacking and frame slicing attacks.|||[](/categorize/langs/JavaScript.md)|
 - nuclei-wordfence-cve - wordfence-cve?label=%20)|[`nuclei-templates`](/categorize/tags/nuclei-templates.md)|[](/categorize/langs/Python.md)|
 - boast
 - xssor2 - Hack with JavaScript.||[`xss`](/categorize/tags/xss.md)|[](/categorize/langs/JavaScript.md)|
 - ob_hacky_slack - a bash script that sends beautiful messages to Slack||[`notify`](/categorize/tags/notify.md)|[](/categorize/langs/Shell.md)|
 - pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully scriptable with Python (PSE) |||[](/categorize/langs/Shell.md)|
 - tiscripts
 - 230-OOB - of-Band XXE server for retrieving file contents over FTP.||[`xxe`](/categorize/tags/xxe.md)|[](/categorize/langs/Python.md)|
 - urlgrab
 - burl - URL Checker ||[`url`](/categorize/tags/url.md)|[](/categorize/langs/Go.md)|
 - godeclutter
 - zip-bomb - bomb?label=%20)|[`zipbomb`](/categorize/tags/zipbomb.md)|[](/categorize/langs/Python.md)|
 - Crimson
 - pentest-env - env?label=%20)|[`pentest`](/categorize/tags/pentest.md)|[](/categorize/langs/Ruby.md)|
 - Glue
 - ConfusedDotnet - prodsec/ConfusedDotnet?label=%20)|[`dependency-confusion`](/categorize/tags/dependency-confusion.md)|[](/categorize/langs/C%23.md)|
 - nosqli - belmer/nosqli?label=%20)|[`nosqli`](/categorize/tags/nosqli.md)|[](/categorize/langs/Go.md)|
 - wprecon
 - depenfusion - mauss/depenfusion?label=%20)|[`dependency-confusion`](/categorize/tags/dependency-confusion.md)|[](/categorize/langs/Python.md)|
 - dependency-confusion-scanner - git/dependency-confusion-scanner?label=%20)|[`dependency-confusion`](/categorize/tags/dependency-confusion.md)|[](/categorize/langs/Python.md)|
 - SecurityTrails
 - ppfuzz - side prototype pollution vulnerability written in Rust. 🦀||[`prototypepollution`](/categorize/tags/prototypepollution.md) [`prototype-pollution`](/categorize/tags/prototype-pollution.md)|[](/categorize/langs/Rust.md)|
 - PwnXSS
 - NoXss - xss and dom-xss||[`xss`](/categorize/tags/xss.md)|[](/categorize/langs/Python.md)|
 - XssPy
 - xsssniper
 - ParamWizard - based tool designed for extracting and identifying URLs with parameters from a specified website.||[`param`](/categorize/tags/param.md)|[](/categorize/langs/Python.md)|
 - Deadsniper - link checker||[`broken-link`](/categorize/tags/broken-link.md)|[](/categorize/langs/Go.md)|
 - httpie - friendly command-line HTTP client for the API era||[`http`](/categorize/tags/http.md)|[](/categorize/langs/Python.md)|
 - LOXS - redirect`](/categorize/tags/open-redirect.md)|[](/categorize/langs/Python.md)|
 - gitleaks
 - RustScan
 - SubBrute
 - urx
 - waymore - h4ck3r/waymore?label=%20)|[`url`](/categorize/tags/url.md)|[](/categorize/langs/Python.md)|
 - graphql-voyager - guru/graphql-voyager?label=%20)|[`graphql`](/categorize/tags/graphql.md)|[](/categorize/langs/TypeScript.md)|
 - subzy
 - Bug-Bounty-Toolz - Bug Bounty Tools |||[](/categorize/langs/Python.md)|
 - testssl.sh
 - findomain - platform subdomain enumerator, do not waste your time. ||[`subdomains`](/categorize/tags/subdomains.md)|[](/categorize/langs/Rust.md)|
 - wprecon
 
 - 
                    
Browser Addons
- Dark Reader for Safari
 - Wayback Machine
 - MM3 ProxySwitch
 - User-Agent Switcher - agents.||||
 - DotGit
 - DOMLogger++ - mizu/domloggerpp?label=%20)|[`dom`](/categorize/tags/dom.md) [`xss`](/categorize/tags/xss.md)|[](/categorize/langs/JavaScript.md)|
 - cookie-quick-manager - quick-manager?label=%20)|[`cookie`](/categorize/tags/cookie.md)|[](/categorize/langs/JavaScript.md)|
 - firefox-container-proxy - container-proxy?label=%20)||[](/categorize/langs/JavaScript.md)|
 - ZAP Browser Extension - extension/?label=%20)|[`browser-record`](/categorize/tags/browser-record.md)|[](/categorize/langs/TypeScript.md)|
 - postMessage-tracker - icon||[`js-analysis`](/categorize/tags/js-analysis.md)|[](/categorize/langs/JavaScript.md)|
 - Edit-This-Cookie - This-Cookie?label=%20)|[`cookie`](/categorize/tags/cookie.md)|[](/categorize/langs/JavaScript.md)|
 - clear-cache - on to clear browser cache with a single click or via the F9 key.|||[](/categorize/langs/JavaScript.md)|
 - eval_villain
 - Dark Reader
 - PwnFox
 - jsonwebtoken.github.io
 - Firefox Multi-Account Containers - Account Containers lets you keep parts of your online life separated into color-coded tabs|||[](/categorize/langs/JavaScript.md)|
 - Hack-Tools - in-one Red Team extension for Web Pentester 🛠|||[](/categorize/langs/TypeScript.md)|
 
 - 
                    
Burpsuite, Caido and ZAP Addons
- Dr. Watson - Watson?label=%20)|[`param`](/categorize/tags/param.md) [`subdomains`](/categorize/tags/subdomains.md)|[](/categorize/langs/Python.md)|
 - HUNT
 - attack-surface-detector-burp - surface-detector-burp?label=%20)|[`endpoint`](/categorize/tags/endpoint.md) [`url`](/categorize/tags/url.md) [`attack-surface`](/categorize/tags/attack-surface.md)|[](/categorize/langs/Java.md)|
 - BurpJSLinkFinder - analysis`](/categorize/tags/js-analysis.md)|[](/categorize/langs/Python.md)|
 - reflected-parameters - parameters?label=%20)|[`param`](/categorize/tags/param.md)|[](/categorize/langs/Java.md)|
 - attack-surface-detector-zap - surface-detector-zap?label=%20)|[`endpoint`](/categorize/tags/endpoint.md) [`url`](/categorize/tags/url.md) [`attack-surface`](/categorize/tags/attack-surface.md)|[](/categorize/langs/Java.md)|
 - burp-retire-js - retire-js?label=%20)|[`js-analysis`](/categorize/tags/js-analysis.md)|[](/categorize/langs/JavaScript.md)|
 - param-miner - miner?label=%20)|[`param`](/categorize/tags/param.md) [`cache-vuln`](/categorize/tags/cache-vuln.md)|[](/categorize/langs/Java.md)|
 - GAP - h4ck3r/GAP-Burp-Extension?label=%20)|[`param`](/categorize/tags/param.md)|[](/categorize/langs/Python.md)|
 - AuthMatrix
 - Autorize
 - http-request-smuggler - request-smuggler?label=%20)|[`smuggle`](/categorize/tags/smuggle.md)|[](/categorize/langs/Java.md)|
 - collaborator-everywhere - everywhere?label=%20)|[`oast`](/categorize/tags/oast.md)|[](/categorize/langs/Java.md)|
 - BurpSuiteHTTPSmuggler
 - csp-auditor - auditor?label=%20)|[`csp`](/categorize/tags/csp.md)|[](/categorize/langs/Java.md)|
 - argumentinjectionhammer
 - taborator
 - zap-hud - hud?label=%20)||[](/categorize/langs/Java.md)|
 - blackboxprotobuf
 - Map Local - on which allows mapping of responses to content of a chosen local file.|||[](/categorize/langs/Java.md)|
 - EvenBetter
 - notebook - community/notebook?label=%20)|[`note`](/categorize/tags/note.md)|[](/categorize/langs/TypeScript.md)|
 - safecopy
 - Decoder-Improved - Improved?label=%20)||[](/categorize/langs/Java.md)|
 - CaidoReflector
 - burp-send-to - send-to?label=%20)||[](/categorize/langs/Java.md)|
 - BurpCustomizer
 - HTTPSignatures - ietf-httpbis-message-signatures-01 draft.|||[](/categorize/langs/Java.md)|
 - reflect
 - EvenBetterExtensions
 - caidope - caido plugin|||[](/categorize/langs/TypeScript.md)|
 - burp-piper - piper?label=%20)||[](/categorize/langs/Kotlin.md)|
 - Berserko
 - community-scripts - scripts?label=%20)||[](/categorize/langs/JavaScript.md)|
 - turbo-intruder - intruder?label=%20)||[](/categorize/langs/Kotlin.md)|
 - gRPC-Web Pentest Suite - Pentest-Suite is set of tools for pentesting / hacking gRPC Web (gRPC-Web) applications.||[`gRPC-Web`](/categorize/tags/gRPC-Web.md)|[](/categorize/langs/Python.md)|
 - burp-exporter - exporter?label=%20)||[](/categorize/langs/Python.md)|
 - Stepper
 - AWSSigner
 - Web3 Decoder - decoder?label=%20)|[`web3`](/categorize/tags/web3.md)|[](/categorize/langs/Java.md)|
 - pcap-burp - burp?label=%20)||[](/categorize/langs/Java.md)|
 - inql
 - knife
 - femida - i-was/femida?label=%20)||[](/categorize/langs/Python.md)|
 - http-script-generator - script-generator?label=%20)||[](/categorize/langs/Java.md)|
 - Neonmarker
 - BurpBounty
 - owasp-zap-jwt-addon - zap-jwt-addon?label=%20)|[`jwt`](/categorize/tags/jwt.md)|[](/categorize/langs/Java.md)|
 - BurpSuite-Secret_Finder - Secret_Finder?label=%20)|||
 - BurpSuiteLoggerPlusPlus
 
 
 - 
                    
 - 
            
Family project
 
            Programming Languages
          
          
        
            Categories
          
          
        
            Sub Categories
          
          
        
            Keywords
          
          
              
                bugbounty
                91
              
              
                security
                74
              
              
                pentesting
                53
              
              
                hacking
                42
              
              
                security-tools
                40
              
              
                golang
                35
              
              
                penetration-testing
                34
              
              
                recon
                26
              
              
                osint
                25
              
              
                scanner
                25
              
              
                reconnaissance
                24
              
              
                pentest
                22
              
              
                go
                21
              
              
                infosec
                21
              
              
                python
                21
              
              
                bug-bounty
                17
              
              
                xss
                17
              
              
                cli
                15
              
              
                pentest-tool
                14
              
              
                http
                14
              
              
                bugbounty-tool
                14
              
              
                vulnerability
                13
              
              
                information-gathering
                12
              
              
                enumeration
                12
              
              
                hacking-tool
                11
              
              
                security-scanner
                11
              
              
                subdomain
                11
              
              
                vulnerability-scanner
                11
              
              
                vulnerability-scanners
                10
              
              
                crawler
                10
              
              
                tool
                10
              
              
                burpsuite
                10
              
              
                javascript
                10
              
              
                dns
                10
              
              
                web
                9
              
              
                security-audit
                8
              
              
                bugbountytips
                8
              
              
                appsec
                8
              
              
                graphql
                7
              
              
                rust
                7
              
              
                burp-extensions
                7
              
              
                nmap
                7
              
              
                pentesting-tools
                7
              
              
                offensive-security
                7
              
              
                owasp
                7
              
              
                dast
                6
              
              
                sql-injection
                6
              
              
                websocket
                6
              
              
                exploitation
                6
              
              
                nuclei
                6