Python.md

March 20, 2026 · View on GitHub

Tools Made of Python

TypeNameDescriptionStarTagsBadges
Army-knifeBaudrillard SuiteCross-platform security research toolkit with OSINT aggregation, memory forensics, social engineering tools, steganography, and predictive threat modeling.osint recon forensics social-engineering steganographylinuxmacoswindowsPython
ProxymitmproxyAn interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.mitmproxylinuxmacoswindowsPython
ReconparamethThis tool can be used to brute discover GET and POST parameterslinuxmacoswindowsPython
ReconspiderfootSpiderFoot automates OSINT collection so that you can focus on analysis.osintlinuxmacoswindowsPython
Recon3klConAutomation Recon tool which works with Large & Medium scopes. It performs more than 20 tasks and gets back all the results in separated files.linuxmacoswindowsPython
ReconapkleaksScanning APK file for URIs, endpoints & secrets.apk url endpointlinuxmacoswindowsPython
RecondirsearchWeb path scannerlinuxmacoswindowsPython
ReconParamWizardParamWizard is a powerful Python-based tool designed for extracting and identifying URLs with parameters from a specified website.paramlinuxmacoswindowsPython
Reconpagodopagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searchinglinuxmacoswindowsPython
ReconSecretFinderSecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript fileslinuxmacoswindowsPython
ReconParthHeuristic Vulnerable Parameter ScannerparamlinuxmacoswindowsPython
ReconwaymoreFind way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal & Intelligence X!urllinuxmacoswindowsPython
ReconbbotOSINT automation for hackersosintlinuxmacoswindowsPython
ReconDr. WatsonDr. Watson is a simple Burp Suite extension that helps find assets, keys, subdomains, IP addresses, and other useful informationparam subdomainslinuxmacoswindowsburpPython
ReconaltdnsGenerates permutations, alterations and mutations of subdomains and then resolves themdns subdomainslinuxmacoswindowsPython
ReconxnLinkFinderA python tool used to discover endpoints (and potential parameters) for a given targetjs-analysislinuxmacoswindowsPython
ReconBLUTODNS Analysis TooldnslinuxmacoswindowsPython
ReconArjunHTTP parameter discovery suite.paramlinuxmacoswindowsPython
ReconHydraReconAll In One, Fast, Easy Recon ToollinuxmacoswindowsPython
ReconknockKnock Subdomain ScansubdomainslinuxmacoswindowsPython
ReconSublist3rFast subdomains enumeration tool for penetration testerssubdomainslinuxmacoswindowsPython
Reconurodeclutters url lists for crawling/pentestingurllinuxmacoswindowsPython
ReconOneForAllOneForAll是一款功能强大的子域收集工具linuxmacoswindowsPython
ReconSilverMass scan IPs for vulnerable servicesportlinuxmacoswindowsPython
ReconlongtongueCustomized Password/Passphrase List inputting Target InfolinuxmacoswindowsPython
ReconGitMinerTool for advanced mining for content on GithublinuxmacoswindowsPython
ReconParamSpiderMining parameters from dark corners of Web ArchivesparamlinuxmacoswindowsPython
ReconBurpJSLinkFinderjs-analysislinuxmacoswindowsburpPython
RecondnsvalidatorMaintains a list of IPv4 DNS servers by verifying them against baseline servers, and ensuring accurate responses.dnslinuxmacoswindowsPython
ReconSTEWSA Security Tool for Enumerating WebSocketslinuxmacoswindowsPython
ReconSubBrutehttps://github.com/TheRook/subbrutesubdomainslinuxmacoswindowsPython
ReconHostHunterRecon tool for discovering hostnames using OSINT techniques.osintlinuxmacoswindowsPython
ReconPhotonIncredibly fast crawler designed for OSINT.osint crawllinuxmacoswindowsPython
ReconLepusSubdomain findersubdomainslinuxmacoswindowsPython
Recongraphw00fGraphQL Server Engine Fingerprinting utilitygraphqllinuxmacoswindowsPython
Reconcc.pyExtracting URLs of a specific target based on the results of "commoncrawl.org"urllinuxmacoswindowsPython
ReconFavFreakMaking Favicon.ico based Recon Great again !linuxmacoswindowsPython
ReconLinkFinderA python script that finds endpoints in JavaScript filesjs-analysislinuxmacoswindowsPython
FuzzerParamPamPamThis tool for brute discover GET and POST parameters.param cache-vulnlinuxmacoswindowsPython
FuzzerwfuzzWeb application fuzzerlinuxmacoswindowsPython
FuzzerClairvoyanceObtain GraphQL API schema even if the introspection is disabledgraphqllinuxmacoswindowsPython
FuzzerGAPThis is an evolution of the original getAllParams extension for Burp. Not only does it find more potential parameters for you to investigate, but it also finds potential links to try these parameters on.paramlinuxmacoswindowsburpPython
FuzzerBatchQLGraphQL security auditing script with a focus on performing batch GraphQL queries and mutationsgraphqllinuxmacoswindowsPython
FuzzerSSRFmapAutomatic SSRF fuzzer and exploitation toolssrflinuxmacoswindowsPython
FuzzerCrackQLCrackQL is a GraphQL password brute-force and fuzzing utility.graphqllinuxmacoswindowsPython
FuzzerSSTImapAutomatic SSTI detection tool with interactive interfacesstilinuxmacoswindowsPython
FuzzerGraphQLmapGraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes.graphqllinuxmacoswindowsPython
ScannerOralyzerOpen Redirection AnalyzerlinuxmacoswindowsPython
ScannerPwnXSSVulnerability (XSS) scanner exploitxsslinuxmacoswindowsPython
ScannerAWSBucketDumpSecurity Tool to Look For Interesting Files in S3 Bucketss3linuxmacoswindowsPython
Scannerzap-cliA simple tool for interacting with OWASP ZAP from the commandline.linuxmacoswindowszapPython
ScannerLFISuiteTotally Automatic LFI Exploiter (+ Reverse Shell) and ScannerlinuxmacoswindowsPython
ScannerCorsyCORS Misconfiguration ScannercorslinuxmacoswindowsPython
ScannerV3n0M-ScannerPopular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulnssqli xss lfi rfilinuxmacoswindowsPython
ScannercommixAutomated All-in-One OS Command Injection Exploitation Tool.exploitlinuxmacoswindowsPython
ScannerLOXSbest tool for finding SQLi,CRLF,XSS,LFi,OpenRedirectxss sqli crlf lfi open-redirectlinuxmacoswindowsPython
ScannerNoSQLMapAutomated NoSQL database enumeration and web application exploitation tool.nosqlilinuxmacoswindowsPython
Scannercorsair_scanCorsair_scan is a security tool to test Cross-Origin Resource Sharing (CORS).corslinuxmacoswindowsPython
ScannersqlmapAutomatic SQL injection and database takeover toolsqlilinuxmacoswindowsPython
ScannerDSSSDamn Small SQLi ScannersqlilinuxmacoswindowsPython
ScannerCMSmapCMSmap is a python open source CMS scanner that automates the process of detecting security flaws of the most popular CMSs.web-scanner vulnerability-scannerlinuxmacoswindowsPython
ScannerAuthMatrixaaalinuxmacoswindowsburpPython
ScannerNoXssFaster xss scanner,support reflected-xss and dom-xssxsslinuxmacoswindowsPython
ScannerXSStrikeMost advanced XSS scanner.xsslinuxmacoswindowsPython
Scannersqlivmassive SQL injection vulnerability scannersqlilinuxmacoswindowsPython
ScannerdepenfusionA powerful pentesting tool for detecting and exploiting dependency confusion vulnerabilities in Node.js projectsdependency-confusionlinuxmacoswindowsPython
ScannerxsssniperAn automatic XSS discovery toolxsslinuxmacoswindowsPython
ScannerSQLiDetectorSimple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests with 14 payloads and checking for 152 regex patterns for different databases.sqlilinuxmacoswindowsPython
ScannerS3ScannerScan for open AWS S3 buckets and dump the contentss3linuxmacoswindowsPython
Scannerhttp-request-smugglingHTTP Request Smuggling Detection ToollinuxmacoswindowsPython
ScannerrapidscanThe Multi-Tool Web Vulnerability Scanner.linuxmacoswindowsPython
ScannerOpenRedireXA Fuzzer for OpenRedirect issueslinuxmacoswindowsPython
ScannerS3cret ScannerHunting For Secrets Uploaded To Public S3 Bucketss3linuxmacoswindowsPython
ScannerStrikerStriker is an offensive information and vulnerability scanner.linuxmacoswindowsPython
Scannera2svAuto Scanning to SSL VulnerabilityssllinuxmacoswindowsPython
ScannerautopoisonerWeb cache poisoning vulnerability scanner.cache-vulnlinuxmacoswindowsPython
ScannertplmapServer-Side Template Injection and Code Injection Detection and Exploitation ToollinuxmacoswindowsPython
ScannergitGrabergitGraberlinuxmacoswindowsPython
ScannerxsserCross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.xsslinuxmacoswindowsPython
ScannersemgrepLightweight static analysis for many languages. Find bug variants with patterns that look like source code.sast code-analysislinuxmacoswindowsPython
ScannersmugglerSmuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3smugglelinuxmacoswindowsPython
ScannerVHostScanA virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.linuxmacoswindowsPython
Scannerdependency-confusion-scannerThis small repo is meant to scan Github's repositories for potential Dependency confusion vulnerabilities.dependency-confusionlinuxmacoswindowsPython
ScannerXssPyWeb Application XSS ScannerxsslinuxmacoswindowsPython
ScannerxsscrapyXSS/SQLi spider. Give it a URL and it'll test every link it finds for XSS and some SQLi.xsslinuxmacoswindowsPython
ScannerwapitiWeb application vulnerability scanner. Wapiti allows you to audit the security of your websites or web applications.vulnerability-scanner web-scannerlinuxmacoswindowsPython
ScannerAutorizeaaalinuxmacoswindowsburpPython
ScannerdeadlinksHealth checks for your documentation links.broken-linklinuxmacoswindowsPython
Scannercloud-auditFast, opinionated AWS security scanner with Terraform remediation and attack chain detectionaws cloud security terraformlinuxmacoswindowsPython
ExploitghauriAn advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flawssqlilinuxmacoswindowsPython
ExploittoxssinAn XSS exploitation command-line interface and payload generator.xsslinuxmacoswindowsPython
Exploitof-CORSIdentifying and exploiting CORS misconfigurations on the internal networkscorslinuxmacoswindowsPython
ExploitGopherusThis tool generates gopher link for exploiting SSRF and gaining RCE in various serversssrflinuxmacoswindowsPython
ExploitXSRFProbeThe Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.linuxmacoswindowsPython
ExploitLiffyLocal file inclusion exploitation toollfilinuxmacoswindowsPython
Exploitjwt_toolA toolkit for testing, tweaking and cracking JSON Web Tokensjwt authenticationlinuxmacoswindowsPython
Utilszip-bombCreate a ZIPBomb for a given uncompressed size (flat and nested modes).zipbomblinuxmacoswindowsPython
UtilsdocemUility to embed XXE and XSS payloads in docx,odt,pptx,etc (OXML_XEE on steroids)xxe xsslinuxmacoswindowsPython
Utilsburp-exporterlinuxmacoswindowsburpPython
UtilsAtlasQuick SQLMap Tamper SuggestersqlilinuxmacoswindowsPython
UtilsgRPC-Web Pentest SuitegRPC-Pentest-Suite is set of tools for pentesting / hacking gRPC Web (gRPC-Web) applications.gRPC-WebburplinuxmacoswindowsPython
Utils230-OOBAn Out-of-Band XXE server for retrieving file contents over FTP.xxelinuxmacoswindowsPython
UtilsargumentinjectionhammerA Burp Extension designed to identify argument injection vulnerabilities.linuxmacoswindowsburpPython
UtilstiscriptsTurbo Intruder ScriptslinuxmacoswindowsPython
Utilspentest-toolsCustom pentesting toolslinuxmacoswindowsPython
UtilsinqllinuxmacoswindowsburpPython
UtilsPayloadsAllTheThingsA list of useful payloads and bypass for Web Application Security and Pentest/CTFlinuxmacoswindowsPython
UtilsREcollapseREcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applicationsfuzzlinuxmacoswindowsPython
Utilsh2spacexHTTP/2 Single Packet Attack low level library based on Scapyrace-conditionlinuxmacoswindowsPython
Utilshttpiemodern, user-friendly command-line HTTP client for the API erahttplinuxmacoswindowsPython
UtilsfemidalinuxmacoswindowsburpPython
UtilsZipBombA simple implementation of ZipBomb in PythonzipbomblinuxmacoswindowsPython
Utilsgrcgeneric colouriserlinuxmacoswindowsPython
Utilsnuclei-wordfence-cveEvery single day new templates are added to this repo based on updates on Wordfence.comnuclei-templateslinuxmacoswindowsPython
UtilsblackboxprotobufBlackbox protobuf is a Burp Suite extension for decoding and modifying arbitrary protobuf messages without the protobuf type definition.linuxmacoswindowsburpPython
UtilsBug-Bounty-ToolzBBT - Bug Bounty ToolslinuxmacoswindowsPython
UtilsXSS-CatcherFind blind XSS but why not gather data while you're at it.xss blind-xsslinuxmacoswindowsPython
UtilsRedcloudAutomated Red Team Infrastructure deployement using DockerinfralinuxmacoswindowsPython
UtilsGQLSpectionparses GraphQL introspection schema and generates possible queriesgraphqllinuxmacoswindowsPython
EnvCrimsonWeb Application Security Testing automation.linuxmacoswindowsPython