A customizable vulnerability scanner focused on web applications.
Features:
Plugin-based scanning engine
Fuzzing support
CVE detection
Flexible rule system
Lightweight alternative to heavier scanners.
๐ https://t.co/KVJX15OEuX
#WebSecurity#BugBounty#Scanner#CyberSecurity #RedTeam
A race condition testing framework for web applications.
Designed to exploit timing flaws in:
Payments
Coupon systems
OTP validation
Account actions
Inventory logic
Race conditions are massively underestimated.
๐ https://t.co/dphG2xg0Rz
#RaceCondition#WebHacking#BugBounty #CyberSecurity #RedTeam
A lesser-known SQL injection framework focused on detection accuracy and clean exploitation workflows.
Supports:
Boolean-based SQLi
Time-based SQLi
Error-based SQLi
DB fingerprinting
An interesting alternative to SQLMap.
๐ https://t.co/BtKmji4cAA
#SQLi#WebHacking #CyberSecurity #BugBounty #RedTeam
A recon tool that mines URLs and parameters from web archives.
Useful for discovering:
Hidden GET parameters
Old API endpoints
Debug functionality
Potential XSS/SSRF/IDOR attack surfaces
Great for deep web recon.
๐ https://t.co/dA09UMWzEq
#Recon#BugBounty#WebSecurity #CyberSecurity #RedTeam
An API discovery tool built to hunt hidden routes, endpoints, and forgotten API functionality.
Great for:
REST API enumeration
Shadow API discovery
Wordlist-based endpoint fuzzing
Large-scale recon
Very effective against modern SaaS targets.
๐ https://t.co/SCn7I8Z9sb
#API #WebSecurity #BugBounty #Recon #CyberSecurity
A niche tool designed to automate SSRF discovery and validation across web applications.
Helps identify:
Cloud metadata exposure
Internal service access
Blind SSRF behaviors
Dangerous integrations
SSRF remains one of the most impactful web vulnerabilities.
๐ https://t.co/IinvGn4HzG
#SSRF #WebHacking #BugBounty #RedTeam #CloudSecurity
A PowerShell tool that can enumerate and download all files accessible to a SharePoint account using an existing access token.
No password cracking.
No privilege escalation.
Just abusing already granted access.
Misconfigured Entra ID permissions + stolen OAuth tokens = massive data exposure risk.
๐ https://t.co/zRvXht9WQd
#CyberSecurity #RedTeam #BlueTeam #SharePoint #Microsoft365 #Infosec #PowerShell #ThreatDetection