13 repositorios
Tools for identifying web technologies, frameworks, and configurations.
Explore 13 awesome GitHub repositories matching part of an awesome list · Technology Fingerprinting. Refine with filters or upvote what's useful.
httpx is a suite of tools and libraries for HTTP reconnaissance, infrastructure discovery, and DNS resolution. It functions as a command line toolkit for extracting metadata and status codes from HTTP targets and CIDR ranges, as well as a Go library for integrating these probing capabilities into custom programs. The project distinguishes itself through specialized infrastructure profiling, using TLS fingerprinting to extract JARM hashes and certificate details. It identifies underlying components such as CDN usage, Autonomous System Numbers, and CNAMEs to map web server software and infrastr
Fast HTTP toolkit for reliable probing and analysis.
WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.
Identifies and fingerprints Web Application Firewalls.
WhatWeb is a web application fingerprinting tool that identifies the technology stack powering a website by scanning HTTP responses and page content. It matches responses against a library of over 1800 signatures to detect CMS platforms, JavaScript libraries, web servers, embedded devices, and third-party addons, while also extracting technical metadata such as software versions, user accounts, and module names. The tool operates through a plugin-based detection framework that supports both passive and aggressive scanning modes. Passive plugins analyze existing HTTP headers and page content w
Uses multiple tests per technology, such as checking favicons and file paths, to identify hidden platforms.
Retire.js es un escáner de vulnerabilidades y analizador de seguridad de dependencias para JavaScript. Identifica librerías de JavaScript obsoletas o inseguras con fallos de seguridad conocidos dentro de aplicaciones web y proyectos locales. La herramienta funciona como una utilidad de auditoría de seguridad web que puede utilizarse durante pruebas de penetración para detectar scripts vulnerables en sitios web en vivo. Admite la generación de listas de materiales de software (SBOM) utilizando el formato CycloneDX para documentar las dependencias del proyecto. El sistema utiliza detección de librerías basada en firmas y coincidencia de patrones para mapear las versiones identificadas contra una base de datos de seguridad basada en JSON. Las capacidades de escaneo incluyen el uso de navegadores headless para analizar scripts cargados por aplicaciones en ejecución.
Detects vulnerable JavaScript libraries.
This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part
Identifies web servers and application frameworks to understand the technical environment of the target.
Port of Wappalyzer (uncovers technologies used on websites) to automate mass scanning.
Automated mass-scanning port of Wappalyzer.
Fast and configurable TLS grabber focused on TLS based data collection.
Configurable TLS data collection and analysis tool.
A utility to detect various technology for a given IP address.
Identifies technology associated with IP and DNS addresses.
graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint.
Fingerprints GraphQL server engines.
Standalone utility for service discovery on open ports.
This little tool is to calculate a MurmurHash value of a favicon to hunt phishing websites on the Shodan platform.
Calculates favicon hashes to find similar websites.
BuiltWith API client
Client for the BuiltWith technology lookup API.