Take it like a gift

mitm6
mitm6

pwning IPv4 via IPv6.

toxssin
toxssin

Open-source penetration testing tool that automates the process of exploiting XSS.

Quickjack
Quickjack

Point-and-click tool for producing advanced clickjacking and frame-slicing attacks.

JWTweak
JWTweak

Detects JWT algorithm and provides options to generate a new JWT based on another algorithm.

NoSQL Injector
NoSQL Injector

NoSql Injection CLI tool for finding vulnerable websites using MongoDB.

BugBountyHunting
BugBountyHunting

Search Bug Bounty writeups easily.

KICS
KICS

Find vulnerabilities, compliance issues and infrastructure misconfigurations in your IAC.

s3cario
s3cario

Performs buckets checks from a given list of subdomains.

csp-analyzer
csp-analyzer

Analyze Content-Security-Policy header of a given URL.

BugBountyScanner
BugBountyScanner

A Bash script and Docker image for Bug Bounty reconnaissance, intended for headless use.

jsleak
jsleak

Find secrets, paths or links in the source code.

Certificate Ripper
Certificate Ripper

A CLI tool to extract server certificates.

HTSHELLS
HTSHELLS

Self contained web shells and other attacks via .htaccess files.

SafeLine
SafeLine

A self-hosted WAF to protect web applications from cyber attacks.

BBstats
BBstats

Displays stats and graphs about your Bug Bounty activity.