Ruby.md
February 15, 2026 · View on GitHub
Tools Made of Ruby
| Type | Name | Description | Star | Tags | Badges |
|---|---|---|---|---|---|
| Army-Knife | Metasploit | The world’s most used penetration testing framework | pentest | ![]() ![]() ![]() ![]() | |
| Army-knife | Ronin | Free and Open Source Ruby Toolkit for Security Research and Development | pentest crawl recon exploit | ![]() ![]() ![]() ![]() | |
| Proxy | EvilProxy | A ruby http/https proxy to do EVIL things. | mitmproxy | ![]() ![]() ![]() ![]() | |
| Recon | Hunt3r | Made your bugbounty subdomains reconnaissance easier with Hunt3r the web application reconnaissance framework | ![]() ![]() ![]() ![]() | ||
| Recon | intrigue-core | Discover Your Attack Surface | ![]() ![]() ![]() ![]() | ||
| Scanner | XSpear | Powerfull XSS Scanning and Parameter analysis tool&gem | xss | ![]() ![]() ![]() ![]() | |
| Scanner | arachni | Web Application Security Scanner Framework | ![]() ![]() ![]() ![]() | ||
| Scanner | wpscan | WPScan is a free, for non-commercial use, black box WordPress Vulnerability Scanner written for security professionals and blog maintainers to test the security of their WordPress websites. | ![]() ![]() ![]() ![]() | ||
| Scanner | DeadFinder | Find dead-links (broken links) | broken-link | ![]() ![]() ![]() ![]() | |
| Exploit | XXEinjector | Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods. | xxe | ![]() ![]() ![]() ![]() | |
| Exploit | beef | The Browser Exploitation Framework Project | xss | ![]() ![]() ![]() ![]() | |
| Utils | hbxss | Security test tool for Blind XSS | xss blind-xss | ![]() ![]() ![]() ![]() | |
| Utils | oxml_xxe | A tool for embedding XXE/XML exploits into different filetypes | ![]() ![]() ![]() ![]() | ||
| Env | pentest-env | Pentest environment deployer (kali linux + targets) using vagrant and chef. | pentest | ![]() ![]() ![]() ![]() | |
| Env | Glue | Application Security Automation | ![]() ![]() ![]() ![]() |



