Http2Smugl : Tool to detect and exploit HTTP request smuggling

3 years ago

Http2Smugl tool helps to detect and exploit HTTP request smuggling in cases it can be achieved via HTTP/2 -> HTTP/1.1…

Whatfiles : Log What Files Are Accessed By Any Linux Process

3 years ago

Whatfiles is a Linux utility that logs what files another program reads/writes/creates/deletes on your system. It traces any new processes…

Second-Order : Subdomain Takeover Scanner

3 years ago

Second-Order is a Scans web applications for second-order subdomain takeover by crawling the app, and collecting URLs (and other data)…

Mandiant-Azure-AD-Investigator : PowerShell module for detecting artifacts

3 years ago

Mandiant-Azure-AD-Investigator repository contains a PowerShell module for detecting artifacts that may be indicators of UNC2452 and other threat actor activity.…

Pwndora : Massive IPv4 Scanner, Find And Analyze Internet-Connected Devices In Minutes

3 years ago

Pwndora is a massive and fast IPv4 address range scanner, integrated with multi-threading. Using sockets, it analyzes which ports are…

T-Reqs-HTTP-Fuzzer : A Grammar-Based HTTP Fuzzer

3 years ago

T-Reqs-HTTP-Fuzzer (Two Requests) is a grammar-based HTTP Fuzzer written as a part of the paper titled "T-Reqs: HTTP Request Smuggling with Differential Fuzzing"…

Wireshark-Forensics-Plugin : A cross-platform Wireshark plugin that correlates network traffic data

3 years ago

Wireshark-Forensics-Plugin is the most widely used network traffic analyzer. It is an important tool for both live traffic analysis &…

Dep-Scan : Fully Open-Source Security Audit For Project Dependencies

3 years ago

dep-scan is a fully open-source security audit tool for project dependencies based on known vulnerabilities, advisories and license limitations. Both…

Http-Desync-Guardian – Analyze HTTP Requests To Minimize Risks Of HTTP Desync Attacks

3 years ago

Http-Desync-Guardian is to Analyze HTTP Requests To Minimize Risks Of HTTP Desync Attacks. HTTP/1.1 went through a long evolution since 1991…

Pip-Audit : Audits Python Environments And Dependency Trees For Known Vulnerabilities

3 years ago

pip-audit is a tool for scanning Python environments for packages with known vulnerabilities. It uses the Python Packaging Advisory Database (https://github.com/pypa/advisory-database)…