A fast and efficient subdomain hijacking scanner that checks for takeover vulnerabilities by matching HTTP response bodies against predefined service fingerprints.
☆43Apr 12, 2026Updated 4 months ago
Alternatives and similar repositories for subhijack
Users that are interested in subhijack are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A powerful subdomain enumeration tool that aggregates data from multiple sources to create comprehensive lists of root subdomains.☆68May 2, 2026Updated 3 months ago
- ☆18Aug 23, 2026Updated last week
- IP Finder tool, ipfinder collects IP addresses from Shodan search queries.☆17Dec 12, 2025Updated 8 months ago
- vulntechfinder is a powerful security tool that automates vulnerability scanning based on technology stack detection. It intelligently pr…☆20Aug 23, 2026Updated last week
- Simple XSS vulnerability checker tool very useful with xsschecker.☆28Nov 21, 2025Updated 9 months ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- Writeup Template. Feel free to replicate but please give me credit!☆13Nov 7, 2025Updated 9 months ago
- XSSRecon automates the process of testing URL parameters for reflection of a test payload rix4uni and further checks how special characte…☆55Aug 11, 2026Updated 2 weeks ago
- List of Fresh DNS resolvers updates every 1 hour☆23Updated this week
- A powerful command-line interface for interacting with the [RapidDNS API](https://rapiddns.io/help/api). This tool allows you to perform …☆40Feb 22, 2026Updated 6 months ago
- ☆19Sep 1, 2025Updated 11 months ago
- AI exploit simulation and continuous security pipeline for LLM apps and AI agents☆16Mar 16, 2026Updated 5 months ago
- A powerful Go tool for finding origin IPs of domains by querying multiple security APIs and validating results with built-in HTTP client.☆50Dec 4, 2025Updated 8 months ago
- NeXSS is a modern, self-hosted Blind XSS (Cross-Site Scripting) hunter and callback listener built with Next.js. It helps security resear…☆35Jan 14, 2026Updated 7 months ago
- ☆31Jun 26, 2026Updated 2 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- ☆56Jul 15, 2026Updated last month
- ☆16Jun 26, 2025Updated last year
- ☆51Apr 30, 2026Updated 4 months ago
- ☆39Jul 29, 2026Updated last month
- A powerful Burp Suite extension that automatically detects JavaScript URLs from HTTP traffic, scans them using TruffleHog for secrets det…☆31Oct 23, 2025Updated 10 months ago
- Subdomain enumeration & reconnaissance framework for bug bounty and pentesting — 20+ tools & APIs, HTTP fingerprinting, port scanning, an…☆27Aug 8, 2026Updated 3 weeks ago
- MCP server + REST API para validacao de CPFs e consulta ao TRT3 com solver de CAPTCHA CRNN☆21Apr 27, 2026Updated 4 months ago
- Extensión de Burp Suite que incorpora detección pasiva de vulnerabilidades mediante inteligencia artificial.☆17Aug 22, 2026Updated last week
- ExecEvasion is a lightweight execution-evasion toolkit that generates command variants designed to bypass naive filters and WAF rules by …☆56Jan 31, 2026Updated 6 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Free BugBounty KrazePlanetTraining☆60Dec 17, 2025Updated 8 months ago
- Automating Bug Bounty with n8n☆22Aug 25, 2025Updated last year
- Go static taint-analysis engine that finds vulnerabilities in WordPress plugins — WordPress-aware (capability tiers, nonce≠authz, REST/AJ…☆21Jun 6, 2026Updated 2 months ago
- ☆21Apr 27, 2026Updated 4 months ago
- Auto Frida is a powerful, all-in-one automation toolkit that handles everything from Frida installation to script injection. Zero manual …☆137Apr 15, 2026Updated 4 months ago
- gosqli is a fast and simple tool for detecting blind SQL injection vulnerabilities. It supports scanning URLs with custom payloads, paral…☆19Jun 22, 2026Updated 2 months ago
- Webarchive is a Go package for pentesters and developers to interacting with the Wayback Machine's CDX API and integrate web archive util…☆11Feb 25, 2024Updated 2 years ago
- SelfHosted - Bug Bounty Programs | Discover new and fresh bug bounty programs across platforms. Updated frequently to always display the …☆16Nov 24, 2025Updated 9 months ago
- Burp Suite extension that enhances Burp Active Scan by adding template engine specific SSTI payloads.☆28Feb 20, 2024Updated 2 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Generate Claude Code bug bounty skills from public HackerOne reports and GitHub writeups — 18 vuln classes, no private reports needed☆225Updated this week
- GarudRecon automates domain recon with top open-source tools to discover assets, enumerate subdomains, and detect XSS, SQLi, LFI, RCE & m…☆266Mar 28, 2026Updated 5 months ago
- Scrape all wordpress plugins (updates every 6 hour)☆26Updated this week
- subfalcon is a subdomain enumeration tool that allows you to discover and monitor subdomains for a given list of domains or a single doma…☆53Dec 9, 2024Updated last year
- PenTest and BugBounty 🕵️☆16Aug 18, 2026Updated last week
- Herramienta avanzada de escaneo XSS (Cross-Site Scripting) para auditorías de seguridad web, con capacidades de evasión de WAF y generaci…☆104Jan 7, 2026Updated 7 months ago
- An advanced Out-of-Band and In-Band SSRF fuzzing scanner with dynamic request tracking.☆40Jun 18, 2026Updated 2 months ago