assetnote / surf
Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable SSRF candidates.
☆626Updated last year
Alternatives and similar repositories for surf:
Users that are interested in surf are comparing it to the libraries listed below
- Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one pl…☆961Updated 2 months ago
- A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.☆606Updated this week
- Community curated list of nuclei templates for finding "unknown" security vulnerabilities.☆63Updated 10 months ago
- ☆475Updated 10 months ago
- Gotator is a tool to generate DNS wordlists through permutations.☆466Updated 2 years ago
- Javascript security analysis (JSA) is a program for javascript analysis during web application security assessment.☆496Updated 2 weeks ago
- Golang client for querying SecurityTrails API data☆546Updated last year
- i will upload more templates here to share with the comunity.☆541Updated 11 months ago
- hakip2host takes a list of IP addresses via stdin, then does a series of checks to return associated domain names.☆439Updated 2 years ago
- ☆377Updated last year
- An IIS short filename enumeration tool☆890Updated 4 months ago
- ☆519Updated 8 months ago
- ☆427Updated 2 months ago
- Automated learning of regexes for DNS discovery☆364Updated 2 years ago
- Fast and customizable subdomain wordlist generator using DSL☆779Updated last week
- Discover new target domains using Content Security Policy☆399Updated this week
- Small tool to Grab subdomains using Shodan api.☆423Updated 4 months ago
- jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice☆267Updated 11 months ago
- Smart context-based SSRF vulnerability scanner.☆349Updated 2 years ago
- CT Log Scanner☆321Updated last month
- AllForOne allows bug bounty hunters and security researchers to collect all Nuclei YAML templates from various public repositories,☆628Updated last year
- jsleak is a tool to find secret , paths or links in the source code during the recon.☆521Updated 2 months ago
- The only GraphQL wordlist you'll ever need. Operations, field names, type names... Collected on more than 60k distinct GraphQL schemas.☆355Updated last year
- All About Dependency Confusion Attack, (Detecting, Finding, Mitigating)☆286Updated last year
- Fast and customizable vulnerability scanner For JIRA written in Python☆317Updated 2 months ago
- De-clutter a list of URLs☆328Updated 4 months ago
- Weekly updated list of missing CVEs in nuclei templates official repository. Mainly built for bug bounty, but useful for penetration test…☆353Updated last week
- A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidde…☆360Updated last week
- ☆380Updated 3 weeks ago
- Accept URLs on stdin, replace all query string values with a user-supplied value☆798Updated 2 years ago