Adobe Experience Manager (AEM) hacking toolkit
☆117Sep 26, 2025Updated 11 months ago
Alternatives and similar repositories for hopgoblin
Users that are interested in hopgoblin are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Abuse trust-boundaries to bypass firewalls and network controls☆434Jul 10, 2026Updated last month
- Archive Alchemist is a tool for creating specially crafted archives to test extraction vulnerabilities.☆241Jul 24, 2025Updated last year
- Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.☆17Jul 11, 2025Updated last year
- A Burp Suite extension for Lightning/Aura framework security testing with advanced action management, context editing, and comprehensive …☆68Mar 2, 2026Updated 6 months ago
- Tool to scan servers and hosts using dynamic paths.☆22Oct 1, 2025Updated 11 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- CT Log Scanner☆585Dec 26, 2025Updated 8 months ago
- A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.☆875Aug 24, 2026Updated last week
- TheHulk is a dynamic analysis tool designed to detect and exploit DOM Clobbering vulnerabilities.☆95Aug 25, 2025Updated last year
- jxscout superpowers JavaScript analysis for security researchers☆473Apr 12, 2026Updated 4 months ago
- An IIS short filename enumeration tool☆1,219Nov 25, 2024Updated last year
- Unsecure time-based secret exploitation and Sandwich attack implementation Resources☆150Dec 9, 2024Updated last year
- Rust-powered HTTP Request Smuggling Scanner.☆130Aug 30, 2026Updated last week
- IIS shortname scanner written in Go☆357Mar 25, 2023Updated 3 years ago
- Unleash the power of cloud☆822Nov 19, 2024Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- ☆534Apr 29, 2024Updated 2 years ago
- HTTP testing platform for security researchers☆45Aug 21, 2026Updated 2 weeks ago
- GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations☆414Dec 24, 2022Updated 3 years ago
- Scan websites for exposed Supabase JWTs, enumerate accessible tables, and detect sensitive data exposure automatically.☆125Dec 29, 2025Updated 8 months ago
- A tool to guess the rest of the shortnames provided by vulnerable IIS instances.☆44Aug 12, 2023Updated 3 years ago
- A fancier postMessage tracker with Chrome Manifest version V3 support and a few additional features, inspired by Frans Rosens postmessage…☆131Sep 12, 2025Updated 11 months ago
- 🍪 CookieMonster helps you detect and abuse vulnerable implementations of stateless sessions.☆988Jan 10, 2025Updated last year
- A lightweight GPT model, trained to discover subdomains.☆391Dec 18, 2025Updated 8 months ago
- This repository stores some of my custom BCheck Scan configurations. Its goal is to identify intriguing elements that warrant further man…☆104Feb 9, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- IIS shortname scanner + bruteforce☆56Feb 18, 2024Updated 2 years ago
- Obtain GraphQL API schema even if the introspection is disabled☆1,516Dec 5, 2025Updated 9 months ago
- Tool to parse subdomains from dmarc.live☆154Apr 19, 2024Updated 2 years ago
- A Burp Suite extension for analyzing Next.js Server Actions - server-side functions identified by hash IDs and `Next-Action` headers.☆60Aug 8, 2025Updated last year
- JSBerg is a fast and efficient URL scraper that extracts links, JavaScript files, CSS files, images, and inline URLs from a list of websi…☆24Mar 19, 2025Updated last year
- Repro for Confusion Attacks: Exploiting Hidden Semantic Ambiguity in Apache HTTP Server!☆21Aug 25, 2024Updated 2 years ago
- Chrome extension for automating CSPT discovery☆159May 12, 2026Updated 3 months ago
- Useful scripts for tampermonkey that I used during bug hunting. Will be updated "au fil de l'eau"☆18Jun 2, 2025Updated last year
- PoC for leaking text nodes via CSS injection☆26Jul 27, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Progress Telerik Report Server pre-authenticated RCE chain (CVE-2024-4358/CVE-2024-1800)☆78Jun 6, 2024Updated 2 years ago
- Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used …☆256Dec 9, 2025Updated 8 months ago
- New exploitation tricks for hardened .NET Remoting servers☆33Aug 5, 2025Updated last year
- Orbis is an full spectrum automated external attack surface intelligent toolkit.☆410Aug 12, 2026Updated 3 weeks ago
- A smarter web fuzzing tool that combines local LLM models and ffuf to optimize directory and file discovery☆401Nov 26, 2024Updated last year
- Deserialization payload generator for a variety of .NET formatters☆229Aug 25, 2026Updated last week
- Burp plugin for jxscout☆25May 12, 2025Updated last year