Advanced Bug Hunting Toolkit & Reconnaissance Platform
Discover subdomains using recursive enumeration
Find domains and subdomains quickly
Find subdomains via certificate transparency logs
Always combine outputs before probing
Filter alive subdomains with httpx
Advanced crawling with multiple sources
Fetch URLs from multiple archives
Extract URLs with parameters
Find exposed sensitive files
Discover S3 buckets
Detect exposed git repos
Checks for information disclosure vulnerabilities using a scanner
Searches for AWS S3 buckets associated with the target
Searches for exposed API keys and tokens in JavaScript files
Comprehensive XSS hunting
Advanced XSS vulnerability scanner
Find stored XSS in forms
Detects potential DOM-based XSS vulnerabilities
Find LFI vulnerable parameters
Fuzz for LFI vulnerabilities
Test path traversal payloads
Check CORS policy of a website
Fast CORS misconfiguration scanner
Scan for CORS misconfigurations
Comprehensive WordPress vulnerability scan
Identify WordPress themes and vulnerabilities
Enumerate WordPress users and plugins
Download & Install Script: These tools are included in the install-all-tools.sh script