Shell.md
February 15, 2026 ยท View on GitHub
Tools Made of Shell
| Type | Name | Description | Star | Tags | Badges |
|---|---|---|---|---|---|
| Army-Knife | axiom | A dynamic infrastructure toolkit for red teamers and bug bounty hunters! | infra | ![]() ![]() ![]() ![]() | |
| Recon | lazyrecon | This script is intended to automate your reconnaissance process in an organized fashion | ![]() ![]() ![]() ![]() | ||
| Recon | Sudomy | subdomain enumeration tool to collect subdomains and analyzing domains | subdomains | ![]() ![]() ![]() ![]() | |
| Recon | reconftw | reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities | ![]() ![]() ![]() ![]() | ||
| Recon | JSFScan.sh | Automation for javascript recon in bug bounty. | js-analysis | ![]() ![]() ![]() ![]() | |
| Recon | recon_profile | Recon profile (bash profile) for bugbounty | ![]() ![]() ![]() ![]() | ||
| Recon | megplus | Automated reconnaissance wrapper โ TomNomNom's meg on steroids. [DEPRECATED] | ![]() ![]() ![]() ![]() | ||
| Recon | BugBountyScanner | A Bash script and Docker image for Bug Bounty reconnaissance. | ![]() ![]() ![]() ![]() | ||
| Fuzzer | SSRFire | An automated SSRF finder. Just give the domain name and your server and chill | ssrf | ![]() ![]() ![]() | |
| Fuzzer | crlfuzz | A fast tool to scan CRLF vulnerability written in Go | crlf | ![]() ![]() ![]() ![]() | |
| Fuzzer | BruteX | Automatically brute force all services running on a target. | ![]() ![]() ![]() ![]() | ||
| Scanner | web_cache_poison | web cache poison - Top 1 web hacking technique of 2019 | cache-vuln | ![]() ![]() ![]() ![]() | |
| Scanner | testssl.sh | Testing TLS/SSL encryption anywhere on any port | ssl | ![]() ![]() ![]() ![]() | |
| Scanner | findom-xss | A fast DOM based XSS vulnerability scanner with simplicity. | xss | ![]() ![]() ![]() ![]() | |
| Exploit | Sn1per | Automated pentest framework for offensive security experts | ![]() ![]() ![]() ![]() | ||
| Utils | pwncat | pwncat - netcat on steroids with Firewall, IDS/IPS evasion, bind and reverse shell, self-injecting shell and port forwarding magic - and its fully scriptable with Python (PSE) | ![]() ![]() ![]() ![]() | ||
| Utils | Findsploit | Find exploits in local and online databases instantly | exploit | ![]() ![]() ![]() ![]() | |
| Utils | ob_hacky_slack | Hacky Slack - a bash script that sends beautiful messages to Slack | notify | ![]() ![]() ![]() ![]() | |
| Utils | bountyplz | Automated security reporting from markdown templates (HackerOne and Bugcrowd are currently the platforms supported) | report | ![]() ![]() ![]() ![]() |



