Curated list of open-source & paid Attack Surface Monitoring (ASM) tools.
☆463Oct 9, 2024Updated last year
Alternatives and similar repositories for awesome-attack-surface-monitoring
Users that are interested in awesome-attack-surface-monitoring are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, f…☆4,363Sep 30, 2024Updated last year
- Convolutional neural network for analyzing pentest screenshots☆1,279Mar 8, 2026Updated 2 weeks ago
- reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via E…☆8,522Updated this week
- Attack Surface Management since before Attack Surface Management was a thing☆659Mar 16, 2026Updated last week
- Nuclear Pond is a utility leveraging Nuclei to perform internet wide scans for the cost of a cup of coffee.☆185Dec 29, 2023Updated 2 years ago
- Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one pl…☆1,039Aug 23, 2025Updated 7 months ago
- Monitoring framework to detect and report newly found subdomains on a specific target using various scanning tools☆287Jul 13, 2024Updated last year
- The Distributed Scanning Framework for Everybody! Control Your Infrastructure, Scale Your Scanning-On Your Terms. Easily distribute arbit…☆735Dec 26, 2025Updated 2 months ago
- A Modern Orchestration Engine for Security☆6,155Mar 13, 2026Updated last week
- Password spraying on sites that require 2+ page loads and dynamic nonces☆32Jun 23, 2019Updated 6 years ago
- List of Awesome Asset Discovery Resources☆2,429Jan 22, 2025Updated last year
- Cloudlist is a tool for listing Assets from multiple Cloud Providers.☆1,012Mar 11, 2026Updated last week
- External monitoring for organization assets☆421Jun 5, 2024Updated last year
- Attempt zone transfers on domains☆18Jul 12, 2021Updated 4 years ago
- Wraps projectdiscovery's cdncheck library to exclude CDN hosts from input passed over stdin☆45Mar 13, 2023Updated 3 years ago
- A tool to perform permutations, mutations and alteration of subdomains in golang.☆156Nov 24, 2023Updated 2 years ago
- A projectdiscovery driven attack surface monitoring bot powered by axiom☆189Aug 11, 2022Updated 3 years ago
- Simple python script to check against hypothetical JWT vulnerability.☆51Nov 29, 2020Updated 5 years ago
- Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!☆1,337Mar 5, 2026Updated 2 weeks ago
- reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and findin…☆7,352Mar 13, 2026Updated last week
- Find cloud assets that no one wants exposed 🔎 ☁️☆347Jul 20, 2020Updated 5 years ago
- Attack Surface Management Platform☆9,466Feb 15, 2026Updated last month
- WhereToGo - is a list of popular services that might be used in organizations. By having an account of the user - you can try to find ent…☆128Jul 7, 2022Updated 3 years ago
- dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.☆2,684Updated this week
- automated web assets enumeration & scanning [DEPRECATED]☆288Mar 7, 2023Updated 3 years ago
- De-clutter a list of URLs☆385Mar 8, 2026Updated 2 weeks ago
- qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.☆303Feb 12, 2023Updated 3 years ago
- A highly configurable Framework for easy automated web scanning☆382Jul 13, 2020Updated 5 years ago
- In-depth attack surface mapping and asset discovery☆14,282Updated this week
- ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.☆2,443Jun 11, 2025Updated 9 months ago
- Find alive host from dumped subdomains, huge domain list , alive subdomains☆26Mar 29, 2021Updated 4 years ago
- WILSON Cloud Respwnder is a Web Interaction Logger Sending Out Notifications with the ability to serve custom content in order to appropr…☆50Feb 27, 2026Updated 3 weeks ago
- AttackSurfaceMapper is a tool that aims to automate the reconnaissance process.☆1,402Apr 8, 2024Updated last year
- ⚡️ Multiple target ZAP Scanning☆106Mar 14, 2026Updated last week
- Overlord - Red Teaming Infrastructure Automation☆630May 28, 2024Updated last year
- A tool for adding new lines to files, skipping duplicates☆1,618Jan 12, 2024Updated 2 years ago
- ReconNess is a platform to allow continuous recon (CR) where you can set up a pipeline of #recon tools (Agents) and trigger it base on sc…☆321Feb 20, 2026Updated last month
- A collection of awesome one-liner scripts especially for bug bounty tips.☆3,084Jul 29, 2024Updated last year
- A wordlist framework to fullfill your kinks with your wordlists. For security researchers, bug bounty and hackers.☆1,339Mar 6, 2026Updated 2 weeks ago