XSScope is one of the most powerful and advanced GUI Framework for Modern Browser exploitation via XSS.
☆313Jun 1, 2022Updated 4 years ago
Alternatives and similar repositories for XSScope
Users that are interested in XSScope are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A simple Bash one liner with aim to automate CRLF vulnerability scanning.☆70Aug 18, 2020Updated 6 years ago
- A one liner Bash command which finds CORS in every possible endpoint.☆152Jan 1, 2021Updated 5 years ago
- A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.☆520Jun 22, 2022Updated 4 years ago
- Perform TE.CL HTTP Request Smuggling attacks by crafting HTTP Request automatically.☆73Mar 12, 2022Updated 4 years ago
- An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects☆969Dec 8, 2021Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Automation for javascript recon in bug bounty.☆1,108Sep 9, 2023Updated 2 years ago
- A fast DOM based XSS vulnerability scanner with simplicity.☆872Sep 30, 2022Updated 3 years ago
- Automating XSS using Bash☆364Jan 27, 2026Updated 7 months ago
- ☆168Jan 7, 2022Updated 4 years ago
- Vajra is a highly customizable target and scope based automated web hacking framework to automate boring recon tasks and same scans for m…☆702Oct 29, 2021Updated 4 years ago
- R3C0Nizer is the first ever CLI based menu-driven web application B-Tier recon framework.☆151Apr 2, 2021Updated 5 years ago
- A cheat sheet that contains advanced queries for SQL Injection of all types.☆3,255May 13, 2023Updated 3 years ago
- 🔑 Authz0 is an automated authorization test tool. Unauthorized access can be identified based on URLs and Roles & Credentials.☆428Jul 21, 2026Updated last month
- XRCross is a Reconstruction, Scanner, and a tool for penetration / BugBounty testing. This tool was built to test (XSS|SSRF|CORS|SSTI|ID…☆350Jun 17, 2023Updated 3 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load☆297Sep 22, 2024Updated last year
- An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and…☆811May 11, 2026Updated 3 months ago
- Python tool that probes websites for open redirection via headers, JavaScript, and meta-tag refresh, pulls candidate URLs from the Waybac…☆824Aug 26, 2026Updated last week
- Making Favicon.ico based Recon Great again !☆1,304Aug 29, 2023Updated 3 years ago
- Web Application Security Automation Framework which recons the target for various assets to maximize the attack surface for security prof…☆411Nov 24, 2020Updated 5 years ago
- Bucky (An automatic S3 bucket discovery tool)☆197Jan 6, 2022Updated 4 years ago
- A Payload Injector for bugbounties written in go☆70Jul 18, 2020Updated 6 years ago
- An In-memory Embedding of CPython☆31May 24, 2021Updated 5 years ago
- SubzzZ to find possible subdomains using passive recon. Tool also support Permutations, Mutations, Alterations.☆38Mar 7, 2021Updated 5 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens…☆5,533Jul 1, 2026Updated 2 months ago
- Jeeves SQLI Finder☆214May 13, 2022Updated 4 years ago
- Reconnaissance tool which scans javascript files for subdomains and then iterates over all javascript files hosted on subsequent subdomai…☆222Jul 10, 2020Updated 6 years ago
- Automation Recon tool which works with Large & Medium scopes. It performs a lot of tasks and gets back all the results in separated files…☆688Jul 15, 2024Updated 2 years ago
- CRLF and open redirect fuzzer☆113Aug 31, 2021Updated 5 years ago
- Smart context-based SSRF vulnerability scanner.☆365May 5, 2022Updated 4 years ago
- XSS Finder Via SSTI☆60Sep 14, 2023Updated 2 years ago
- Signatures for jaeles scanner by @j3ssie☆117Apr 20, 2024Updated 2 years ago
- ScanT3r - Module based Bug Bounty Automation Tool ( use Lotus instead github.com/bugBlocker/lotus )☆684Aug 30, 2026Updated last week
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- ☆441Jun 1, 2021Updated 5 years ago
- A collection of awesome one-liner scripts especially for bug bounty tips.☆3,192Jul 29, 2024Updated 2 years ago
- You can read the writeup on this script here☆273Jul 12, 2020Updated 6 years ago
- Tool to find JavaScript files on Websites☆531Nov 2, 2023Updated 2 years ago
- HostHunter a recon tool for discovering hostnames using OSINT techniques.☆1,170Mar 30, 2023Updated 3 years ago
- A python tool used to discover endpoints, potential parameters, a target specific wordlist for a given target and secrets☆1,590Mar 8, 2026Updated 5 months ago
- A repository that includes all the important wordlists used while bug hunting.☆1,431Mar 11, 2023Updated 3 years ago