ππ¦ Dalfox is a powerful open-source XSS scanner and utility focused on automation.
β4,859Feb 28, 2026Updated last week
Alternatives and similar repositories for dalfox
Users that are interested in dalfox are comparing it to the libraries listed below
Sorting:
- Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probingβ3,012Jun 24, 2024Updated last year
- Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.β4,842Jan 1, 2025Updated last year
- HTTP parameter discovery suite.β6,109Feb 20, 2025Updated last year
- reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and findinβ¦β7,280Updated this week
- GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grepβ1,401Sep 13, 2024Updated last year
- Fetch all the URLs that the Wayback Machine knows about for a domainβ4,339May 1, 2024Updated last year
- declutters url lists for crawling/pentestingβ1,532Feb 23, 2025Updated last year
- Gospider - Fast web spider written in Goβ2,885Apr 21, 2024Updated last year
- Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web applicationβ5,000Dec 21, 2024Updated last year
- Hidden parameters discovery suiteβ2,028Sep 8, 2024Updated last year
- httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.β9,629Updated this week
- A python script that finds endpoints in JavaScript filesβ4,294Apr 13, 2024Updated last year
- A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attβ¦β5,789Updated this week
- Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.β6,089Aug 14, 2024Updated last year
- Fast web fuzzer written in Goβ15,679Apr 24, 2025Updated 10 months ago
- The Swiss Army knife for automated Web Application Testingβ2,323May 8, 2024Updated last year
- Fast passive subdomain enumeration tool.β13,159Feb 25, 2026Updated last week
- A wrapper around grep, to help you grep for thingsβ2,081Jun 8, 2024Updated last year
- An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flawsβ3,932Oct 4, 2025Updated 5 months ago
- A tool to check a bunch of URLs that contain reflecting params.β596Aug 4, 2024Updated last year
- reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Eβ¦β8,497Nov 16, 2025Updated 3 months ago
- Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokensβ¦β5,223Jan 31, 2026Updated last month
- Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X!β2,552Updated this week
- Rockyou for web fuzzingβ3,033Feb 11, 2026Updated 3 weeks ago
- Accept URLs on stdin, replace all query string values with a user-supplied valueβ865Nov 23, 2022Updated 3 years ago
- Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enablβ¦β27,300Updated this week
- SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript filesβ2,399May 26, 2024Updated last year
- Contextual Content Discovery Toolβ3,106Apr 29, 2024Updated last year
- Find domains and subdomains related to a given domainβ3,537Jun 7, 2024Updated last year
- Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entβ¦β2,131Feb 23, 2026Updated last week
- A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secretsβ1,529Jan 15, 2026Updated last month
- The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, fβ¦β4,352Sep 30, 2024Updated last year
- Community curated list of templates for the nuclei engine to find security vulnerabilities.β12,015Updated this week
- Most advanced XSS scanner.β14,787Apr 26, 2025Updated 10 months ago
- In-depth attack surface mapping and asset discoveryβ14,222Updated this week
- A collection of hacks and one-off scriptsβ2,423Mar 13, 2025Updated 11 months ago
- A tool for adding new lines to files, skipping duplicatesβ1,614Jan 12, 2024Updated 2 years ago
- A collection of awesome one-liner scripts especially for bug bounty tips.β3,077Jul 29, 2024Updated last year
- Subdomain takeover vulnerability checkerβ1,525Sep 10, 2024Updated last year