Take it like a gift

Nginxpwner
Nginxpwner

Simple tool to look for common Nginx misconfigurations and vulnerabilities.

Sandcastle
Sandcastle

A Python script for AWS S3 bucket enumeration.

Sublert
Sublert

Monitor new subdomains deployed by specific organizations and issued TLS/SSL certificate.

uncompyle6
uncompyle6

A cross-version Python bytecode decompiler.

windapsearch
windapsearch

Enumerate users, groups and computers from a Windows domain through LDAP queries.

WebCopilot
WebCopilot

Automation tool designed to enumerate subdomains and detect bugs using different open-source tools.

vaya-ciego-nen
vaya-ciego-nen

Detect, manage and exploit Blind Cross-site scripting (XSS) vulnerabilities.

wstunnel
wstunnel

Tunneling over websocket protocol - Static binary available.

OAUTHScan
OAUTHScan

Burp Suite Extension useful to verify OAUTHv2 and OpenID security.

Nimbo-C2
Nimbo-C2

Yet another (simple and lightweight) C2 framework.

murphysec
murphysec

An open source tool focused on software supply chain security.

SQLTruncSanner
SQLTruncSanner

Messy BurpSuite plugin for SQL Truncation vulnerabilities.

LinkedInDumper
LinkedInDumper

Script that dumps employee data from the LinkedIn social networking platform.

Maigret
Maigret

Collect a dossier on a person by username from thousands of sites.

wikto
wikto

Nikto for Windows with some extra features.