Take it like a gift

AWSGoat
AWSGoat

A damn vulnerable AWS infrastructure.

SSTImap
SSTImap

Automatic SSTI detection tool with interactive interface.

jwt-cracker
jwt-cracker

Simple JWT token brute force cracker.

kiterunner
kiterunner

Contextual content discovery tool.

Findsploit
Findsploit

Find exploits in local and online databases instantly.

domain_hunter
domain_hunter

Try to find all subdomains, similar-domains and related-domains of an organization.

IPRotate
IPRotate

Extension for Burp Suite which uses AWS API Gateway to rotate your IP on every request.

archaeologit
archaeologit

Scans the history of GitHub repositories to find sensitive things.

Certificate Ripper
Certificate Ripper

A CLI tool to extract server certificates.

ctftool
ctftool

Interactive CTF exploration tool.

attack_range
attack_range

Create vulnerable instrumented local or cloud environments to simulate attacks.

Commix
Commix

Automated All-in-One OS Command Injection Exploitation Tool.

kxss
kxss

Adaption of tomnomnom's kxss tool with a different output format.

chkrootkit
chkrootkit

Locally checks for signs of a rootkit.

codeql
codeql

Power security researchers around the world as well as code scanning.