AI-powered SAST scanner that finds auth bypass, IDOR, and logic bugs Semgrep/CodeQL miss. Free GitHub Action. Supports Python, JS/TS, Go, PHP, Ruby.
☆84Jun 10, 2026Updated 3 months ago
Alternatives and similar repositories for vulnhawk
Users that are interested in vulnhawk are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Path traversal / LFI fuzzer in Go - 66 encoding bypass techniques, response analysis, goroutine concurrency, wordlist support, proxy (Bur…☆16Apr 10, 2026Updated 5 months ago
- Static auditor for randomness and nonce hygiene in Python source - flags weak PRNGs, hardcoded keys, reused counters, static IVs, short s…☆25Sep 5, 2026Updated last week
- Modular OSINT and attack surface analysis platform for authorized security research, with risk scoring, attack paths, and report generati…☆85Jun 4, 2026Updated 3 months ago
- Open-source static AI security scanner — prompt injection across 15 source types, broken LLM-as-judge detection, AI dependency SBOM. Beat…☆32Apr 26, 2026Updated 4 months ago
- Collection of Semgrep rules for security analysis☆10Mar 30, 2024Updated 2 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- The samples referenced in my book, Evasive Malware (No starch Press)☆62Feb 20, 2026Updated 6 months ago
- 🎯 VISTA — AI-Powered Security Testing Assistant for Burp Suite. Real-time traffic analysis, 12 expert vulnerability templates, 80+ paylo…☆20May 27, 2026Updated 3 months ago
- Mutation-driven HTTP fuzzing for Burp Suite☆15Mar 2, 2026Updated 6 months ago
- Autonomous AI-powered penetration testing platform. LLM-driven recon, vulnerability analysis, and exploit validation for internal & exter…☆34Apr 11, 2026Updated 5 months ago
- Android APK security analysis tool. Decompiles DEX, scans for vulns, parses manifests and certs. Runs in your browser.☆72May 14, 2026Updated 3 months ago
- ☆13Oct 21, 2024Updated last year
- 🔍 erroreyes – Lightweight Subdomain Enumeration Tool A Python-based tool that queries crt.sh certificate logs to discover subdomains ass…☆17May 8, 2025Updated last year
- iOS traffic interception framework which route all device HTTP/HTTPS traffic through Burp Suite via a system-wide VPN tunnel☆48Feb 15, 2026Updated 6 months ago
- ☆38Apr 24, 2024Updated 2 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- AWS X-Ray for Covert Command & Control☆51Oct 13, 2025Updated 11 months ago
- Live runtime audit for installed Android apps. Runs on the rooted phone, serves a browser dashboard.☆32May 23, 2026Updated 3 months ago
- List accounts with Service Principal Names (SPN) not linked to active dns records in an Active Directory Domain.☆46Dec 5, 2025Updated 9 months ago
- XBot - Advanced AI Cybersecurity Agent | Gemini system prompt for automated penetration testing and security assessments☆85Nov 29, 2025Updated 9 months ago
- OpenShell is a lightweight, open-source reverse shell management server written in Go.☆26Mar 9, 2026Updated 6 months ago
- ☆73Apr 20, 2026Updated 4 months ago
- Code for our opus 4.6 vulnerability detection benchmark☆19May 11, 2026Updated 4 months ago
- Educational Linux kernel rootkit PoC exploring DKOM, syscall hooking, stealth, observability and defensive detection☆33Aug 9, 2026Updated last month
- Accelerated execution for fast Windows fuzzing☆24Jan 9, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- RepShot · Generate professional security finding cards directly from Burp Suite Repeater.☆108May 31, 2026Updated 3 months ago
- AyedFuzzer is a small File-Format-Fuzzer with 3 options (File-mutating, WinDbg-interactive monitor, multi-processing) for windows executa…☆17Dec 2, 2024Updated last year
- A standalone collection of widely used technologies with default credentials enabled, which can be utilized for establishing an initial f…☆21Jun 1, 2024Updated 2 years ago
- This repository has workflows created for https://github.com/RikunjSindhwad/Task-Ninja☆25Aug 14, 2025Updated last year
- SpicyAD is a C# Active Directory penetration testing tool designed for authorized security assessments. It combines multiple AD attack te…☆108Updated this week
- Collection of Reverse, Bind & Web Shells☆16Mar 25, 2026Updated 5 months ago
- An improvement and a different approach to Mockingjay Self-Injection.☆35May 21, 2024Updated 2 years ago
- "Holy Grail PCAP" is a capture file offering exceptional coverage across nearly all tcpdump/Wireshark encapsulation types and dissectors.☆60May 3, 2026Updated 4 months ago
- Burp extension used to snip any header from all the requests.☆25Nov 12, 2023Updated 2 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Why vulnerability discovery is difficult mathematically☆28Jul 19, 2026Updated last month
- Dominate the Active Directory game. An Active Directory environments pentest tool complementary to existing ones like NetExec.☆21Aug 29, 2026Updated 2 weeks ago
- SpringbootGuiExploit漏洞利用工具测试版☆20Jun 7, 2024Updated 2 years ago
- mattew crawls target websites, extracts hidden attack surface, runs security analysis, fingerprints technology, and generates professiona…☆17Jul 2, 2026Updated 2 months ago
- label ALL kubectl, kustomize, and helm objects, inline, without extra steps.(including namespaces and CRDs)☆15Apr 22, 2024Updated 2 years ago
- Chrome extension + MCP server — AI agents control a tab in your real browser, already logged in☆32Jun 28, 2026Updated 2 months ago
- A mirror of "103_top_shell.rar" since the original disappeared.☆25Sep 27, 2015Updated 10 years ago