Web Application Security Testing Tools
☆253Mar 13, 2024Updated 2 years ago
Alternatives and similar repositories for crimson
Users that are interested in crimson are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Guide to SSRF☆80Oct 10, 2023Updated 2 years ago
- ☆45Jun 5, 2021Updated 5 years ago
- Automated Web Recon Shell Scripts☆54Dec 6, 2021Updated 4 years ago
- Subdomain takeover scanner using Python asyncio☆18Oct 24, 2022Updated 3 years ago
- Hidden parameters discovery suite☆2,085Sep 8, 2024Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- ☆12Jan 4, 2022Updated 4 years ago
- A tools for JavaScript Recon☆24Jul 25, 2020Updated 6 years ago
- An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and…☆812May 11, 2026Updated 2 months ago
- Vajra is a highly customizable target and scope based automated web hacking framework to automate boring recon tasks and same scans for m…☆703Oct 29, 2021Updated 4 years ago
- OpenBugBounty - https://www.openbugbounty.org/ programs list☆23Mar 15, 2021Updated 5 years ago
- Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one pl…☆1,046Jun 6, 2026Updated last month
- Sweetuu is a Advance Shell which can be used to achieve RCE easily through LFI & RFI. For easy wins in bug bounty, upload sweetuu instead…☆10Dec 16, 2024Updated last year
- A Burp Suite extension for identifying injection flaws (LFI, RCE, SQLi), authentication/authorization issues, and HTTP 403 access violati…☆401May 28, 2026Updated last month
- A tool to fastly get all javascript sources/files☆885Jul 4, 2025Updated last year
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Automating XSS using Bash☆365Jan 27, 2026Updated 5 months ago
- An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects☆971Dec 8, 2021Updated 4 years ago
- reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and findin…☆7,891Jun 29, 2026Updated 3 weeks ago
- declutters url lists for crawling/pentesting☆1,584Feb 23, 2025Updated last year
- MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilitie…☆1,044Jul 23, 2024Updated 2 years ago
- A python script to scan for Apache Tomcat server vulnerabilities.☆892Jan 12, 2026Updated 6 months ago
- Small wiki for Mobile Application Penetration Testing Tools☆12Apr 8, 2021Updated 5 years ago
- A Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.☆2,018Sep 5, 2021Updated 4 years ago
- WaybackURLS + OtxURLS + CommonCrawl = The Best Results☆21Dec 7, 2019Updated 6 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- bypass-url-parser☆1,135Jul 18, 2026Updated last week
- Little Bug Bounty & Hacking Tools⚔️☆383Mar 30, 2026Updated 3 months ago
- The Swiss Army knife for automated Web Application Testing☆2,366Jun 20, 2026Updated last month
- A training course on Web Security, Exploit Development and Source Code Auditing from 2009.☆12Feb 15, 2022Updated 4 years ago
- All The Notes And Tips I FOund In Github And Twitter I Put Them Here☆35Aug 31, 2020Updated 5 years ago
- Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hu…☆2,416Jun 27, 2024Updated 2 years ago
- Tips For Bug Bounty Hunters☆86Jul 16, 2022Updated 4 years ago
- Awesome Bug bounty builder Project☆676Feb 15, 2023Updated 3 years ago
- Now, the Host is Mine! - Super Fast Sub-domain Takeover Detection!☆386Jun 7, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A collection of awesome one-liner scripts especially for bug bounty tips.☆3,170Jul 29, 2024Updated last year
- Contextual Content Discovery Tool☆3,233Jul 10, 2026Updated 2 weeks ago
- List of XSS Payloads☆18Jul 5, 2022Updated 4 years ago
- XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.☆313Jun 1, 2022Updated 4 years ago
- Passive subdomain enumeration tool with http-probe.☆32Apr 30, 2021Updated 5 years ago
- A blind XSS detection and XSS data capture framework☆177Dec 6, 2025Updated 7 months ago
- Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned ent…☆2,223Feb 23, 2026Updated 5 months ago