Take it like a gift

alterx
sponsor
alterx

Fast and customizable subdomain wordlist generator using DSL.

GD-Thief
GD-Thief

Exfiltrate files from a target's Google Drive that you have access to, via Google's API.

wafw00f
wafw00f

Identify and fingerprint Web Application Firewall products protecting a website.

cariddi
cariddi

Crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more.

domained
domained

Multi Tool Subdomain Enumeration.

authz
authz

Burp Suite plugin to test for authorization flaws.

CertStealer
CertStealer

A .NET tool for exporting and importing certificates without touching disk.

Comperio
Comperio

OSINT tool to find usernames across 80+ social media and social networking sites.

Aranea
Aranea

OSINT tool used for web crawling or examining JavaScript files for likely useful data.

changeme
changeme

A default credential scanner.

CloudBrute
CloudBrute

Awesome cloud enumerator.

Charles
Charles

HTTP proxy / monitor / reverse proxy that allows to view all of the HTTP(S) traffic.

CloudJack
CloudJack

Route53/CloudFront Vulnerability assessment utility.

Agartha
Agartha

Burp Suite extension for dynamic payload generation to detect injection flaws.

AttifyOS
AttifyOS

Distribution for pentesting IoT devices.