Scripts to help with different ffuf tasks and workflows
☆227Dec 24, 2023Updated 2 years ago
Alternatives and similar repositories for ffuf-scripts
Users that are interested in ffuf-scripts are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A simple tool to detect wildcards domain based on Amass's wildcards detector.☆65Apr 13, 2021Updated 5 years ago
- View screenshots as a slideshow over http☆15Mar 13, 2020Updated 6 years ago
- qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.☆300Feb 12, 2023Updated 3 years ago
- Send notifications on different channels such as Slack, Telegram, Discord etc.☆39Jan 12, 2026Updated 5 months ago
- Complex payload encoder☆244Jan 20, 2024Updated 2 years ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- You can read the writeup on this script here☆192May 9, 2026Updated last month
- Repo of useful scripts☆103Jun 30, 2020Updated 5 years ago
- A simple SSRF-testing sheriff written in Go☆338Oct 31, 2024Updated last year
- Bug Bounty statistics tool.☆34Nov 17, 2022Updated 3 years ago
- differer finds how URLs are parsed by different languages in order to help bug hunters break filters☆62May 3, 2020Updated 6 years ago
- rapid content discovery tool for recursively querying webservers, handy in pentesting and web application assessments☆250Oct 15, 2019Updated 6 years ago
- Takes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures t…☆213Mar 31, 2020Updated 6 years ago
- Continuous monitoring for JavaScript files☆223Dec 29, 2019Updated 6 years ago
- The format of various s3 buckets is convert in one format. for bugbounty and security testing.☆89May 6, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Fetches javascript file from a list of URLS or subdomains.☆855Jul 22, 2025Updated 11 months ago
- Smart ssrf scanner using different methods like parameter brute forcing in post and get...☆277Feb 11, 2021Updated 5 years ago
- OWASP Amass data source scripts (assetfinder, findomain, github, subfinder)☆106Oct 18, 2020Updated 5 years ago
- web-based-fuzzer☆31Jun 26, 2020Updated 6 years ago
- Various Payload wordlists☆243Apr 26, 2025Updated last year
- MassDNS wrapper written in go to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard filtering…☆1,644Jun 22, 2026Updated last week
- Reconnaissance tool which scans javascript files for subdomains and then iterates over all javascript files hosted on subsequent subdomai…☆224Jul 10, 2020Updated 5 years ago
- -☆11Nov 21, 2020Updated 5 years ago
- A collection of hacks and one-off scripts☆2,499Mar 13, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- An hourly updated list of subdomains gathered from certificate transparency logs☆346Oct 13, 2021Updated 4 years ago
- ASN target organization IP range attack surface mapping for reconnaissance, fast and lightweight☆221Apr 10, 2022Updated 4 years ago
- RAS(RAndom Subdomain) Fuzzer☆43Jan 22, 2020Updated 6 years ago
- Bass grabs you those "extra resolvers" you are missing out on when performing Active DNS enumeration. Add anywhere from 100-6k resolvers …☆149Apr 12, 2024Updated 2 years ago
- A highly configurable Framework for easy automated web scanning☆383Jul 13, 2020Updated 5 years ago
- A permutation generation tool written in golang☆213Jul 15, 2019Updated 6 years ago
- Push notifications to Slack channel or to custom server based on BurpSuite response conditions.☆17Nov 26, 2020Updated 5 years ago
- This tool can be used to brute discover GET and POST parameters☆1,396Aug 24, 2019Updated 6 years ago
- Dashboard/API + DNS/HTTP Servers to identify Out of Band Resolution in Payloads☆38Jun 10, 2021Updated 5 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- DNSGen is a powerful and flexible DNS name permutation tool designed for security researchers and penetration testers. It generates intel…☆1,074Jan 3, 2025Updated last year
- SubdomainDB is a simple self-hosted API that allows you to maintain your own subdomain database.☆31Jan 8, 2018Updated 8 years ago
- Generates lists of live hosts and URLs for targeting, automating the usage of MassDNS, Masscan and nmap to filter out unreachable hosts a…☆366Jul 23, 2022Updated 3 years ago
- bountytpl – template generator cli. By using a template similar to the ones for Template Generator (https://github.com/fransr/template-ge…☆47Aug 5, 2019Updated 6 years ago
- Example of a serverless web reconaissance workflow's AWS architecture.☆11Feb 25, 2023Updated 3 years ago
- Scan secrets from Continuous Integration Build Logs☆53Oct 14, 2019Updated 6 years ago
- Accept URLs on stdin, replace all query string values with a user-supplied value☆878Nov 23, 2022Updated 3 years ago