🔨 A modern multiple reverse shell sessions manager written in go
-
Updated
Sep 13, 2025 - Go
🔨 A modern multiple reverse shell sessions manager written in go
An IIS short filename enumeration tool
APKHunt is a comprehensive static code analysis tool for Android apps that is based on the OWASP MASVS framework. Although APKHunt is intended primarily for mobile app developers and security testers, it can be used by anyone to identify and address potential security vulnerabilities in their code.
A fast and minimal JS endpoint extractor
Blind XSS Scanner is a tool that can be used to scan for blind XSS vulnerabilities in web applications.
Generate tens of thousands of subdomain combinations in a matter of seconds
As hackers, we put a premium on function over elegance as time is always scarce. When you need to quickly create a solution to a problem, style concerns come secondary.
[WIP] A free and open-source, modular Remote Administration Tool (RAT) / Payload Dropper written in Go(lang) with a flexible command and control (C2) system.
Use favicons to improve your target recon phase. Quickly detect technologies, WAF, exposed panels, known services.
Filter and enrich a list of subdomains by level
Whois for the Cloud: Recon tool for cloud provider attribution. Supports AWS, Azure, Google, Cloudflare, and Digital Ocean.
Make URL path combinations using a wordlist
A turbo traffic generator pentesting tool to generate random traffic with random MAC and IP addresses in addition to random sequence numbers to a particular IP and port.
Ultimate Tasks Automation Framework for Hackers, DevSecOps, Pentesters, and Bug-bounty hunters!
List all public repositories for (valid) GitHub usernames
Mobile Reconnaissance Framework is a powerful, lightweight and platform-independent offensive mobile security tool designed to help hackers and developers identify and address sensitive information within mobile applications.
Combine words from two wordlist files and concatenate them with an optional delimiter
Returns disallowed paths from robots.txt found on your target domain and snapshotted by the Wayback Machine
Run a base query (plus optional add-ons) through ask, bing, brave, duck duck go, yahoo, and yandex.
An subdomain enumerator for web URLs using the power of Goroutines.
Add a description, image, and links to the pentesting-tools topic page so that developers can more easily learn about it.
To associate your repository with the pentesting-tools topic, visit your repo's landing page and select "manage topics."