Curated list of open-source & paid Attack Surface Monitoring (ASM) tools.
☆468Oct 9, 2024Updated last year
Alternatives and similar repositories for awesome-attack-surface-monitoring
Users that are interested in awesome-attack-surface-monitoring are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, f…☆4,390Sep 30, 2024Updated last year
- Convolutional neural network for analyzing pentest screenshots☆1,285Mar 8, 2026Updated 3 months ago
- reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via E…☆8,688Mar 21, 2026Updated 2 months ago
- Attack Surface Management since before Attack Surface Management was a thing☆658Updated this week
- Nuclear Pond is a utility leveraging Nuclei to perform internet wide scans for the cost of a cup of coffee.☆197Dec 29, 2023Updated 2 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one pl…☆1,044Jun 6, 2026Updated last week
- Monitoring framework to detect and report newly found subdomains on a specific target using various scanning tools☆290Jul 13, 2024Updated last year
- The Distributed Scanning Framework for Everybody! Control Your Infrastructure, Scale Your Scanning-On Your Terms. Easily distribute arbit…☆761Dec 26, 2025Updated 5 months ago
- A Modern Orchestration Engine for Security☆6,411Jun 1, 2026Updated last week
- Password spraying on sites that require 2+ page loads and dynamic nonces☆32Jun 23, 2019Updated 6 years ago
- List of Awesome Asset Discovery Resources☆2,645Jan 22, 2025Updated last year
- Cloudlist is a tool for listing Assets from multiple Cloud Providers.☆1,031May 25, 2026Updated 2 weeks ago
- External monitoring for organization assets☆424Jun 5, 2024Updated 2 years ago
- Attempt zone transfers on domains☆18Jul 12, 2021Updated 4 years ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Wraps projectdiscovery's cdncheck library to exclude CDN hosts from input passed over stdin☆45Mar 13, 2023Updated 3 years ago
- A projectdiscovery driven attack surface monitoring bot powered by axiom☆190Aug 11, 2022Updated 3 years ago
- A tool to perform permutations, mutations and alteration of subdomains in golang.☆158Nov 24, 2023Updated 2 years ago
- Simple python script to check against hypothetical JWT vulnerability.☆51Nov 29, 2020Updated 5 years ago
- The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices☆645Jul 7, 2025Updated 11 months ago
- Find cloud assets that no one wants exposed 🔎 ☁️☆350Jul 20, 2020Updated 5 years ago
- Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ …☆10,139Jun 6, 2026Updated last week
- reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and findin…☆7,687May 15, 2026Updated 3 weeks ago
- Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!☆1,391May 9, 2026Updated last month
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- WhereToGo - is a list of popular services that might be used in organizations. By having an account of the user - you can try to find ent…☆127Jul 7, 2022Updated 3 years ago
- Monitor the internet attack surface of various public cloud environments. Currently supports AWS, GCP, Azure, DigitalOcean and Oracle Clo…☆134Nov 16, 2025Updated 6 months ago
- dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.☆2,747Jun 2, 2026Updated last week
- automated web assets enumeration & scanning [DEPRECATED]☆288Mar 7, 2023Updated 3 years ago
- De-clutter a list of URLs☆390Mar 8, 2026Updated 3 months ago
- qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.☆301Feb 12, 2023Updated 3 years ago
- A highly configurable Framework for easy automated web scanning☆384Jul 13, 2020Updated 5 years ago
- In-depth attack surface mapping and asset discovery☆14,671Apr 17, 2026Updated last month
- Find alive host from dumped subdomains, huge domain list , alive subdomains☆26Mar 29, 2021Updated 5 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.☆2,459Jun 11, 2025Updated last year
- WILSON Cloud Respwnder is a Web Interaction Logger Sending Out Notifications with the ability to serve custom content in order to appropr…☆50Mar 19, 2026Updated 2 months ago
- AttackSurfaceMapper is a tool that aims to automate the reconnaissance process.☆1,399Apr 8, 2024Updated 2 years ago
- ⚡️ Multiple target ZAP Scanning☆107Jun 5, 2026Updated last week
- Overlord - Red Teaming Infrastructure Automation☆633May 28, 2024Updated 2 years ago
- A tool for adding new lines to files, skipping duplicates☆1,638Jan 12, 2024Updated 2 years ago
- ReconNess is a platform to allow continuous recon (CR) where you can set up a pipeline of #recon tools (Agents) and trigger it base on sc…☆325Jun 2, 2026Updated last week