awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to ekultek/whatwaf

Projects sharing features with WhatWaf

30 open-source projects similar to ekultek/whatwaf, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • gyoisamurai/gyoithongyoisamurai avatar

    gyoisamurai/GyoiThon

    822View on GitHub↗

    GyoiThon is a growing penetration test tool using Machine Learning.

    Python
    View on GitHub↗822
  • enablesecurity/wafw00fEnableSecurity avatar

    EnableSecurity/wafw00f

    6,414View on GitHub↗

    WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

    Python
    View on GitHub↗6,414
  • urbanadventurer/whatweburbanadventurer avatar

    urbanadventurer/WhatWeb

    6,424View on GitHub↗

    WhatWeb is a web application fingerprinting tool that identifies the technology stack powering a website by scanning HTTP responses and page content. It matches responses against a library of over 1800 signatures to detect CMS platforms, JavaScript libraries, web servers, embedded devices, and third-party addons, while also extracting technical metadata such as software versions, user accounts, and module names. The tool operates through a plugin-based detection framework that supports both passive and aggressive scanning modes. Passive plugins analyze existing HTTP headers and page content w

    Rubyapplication-securityappsechacking
    View on GitHub↗6,424
  • scipag/vulscanscipag avatar

    scipag/vulscan

    3,761View on GitHub↗

    Vulscan is a network service auditor and vulnerability scanner that utilizes the Nmap Scripting Engine to identify security flaws. It functions as a version-based flaw detector, matching detected software banners against an offline vulnerability database to identify potential security risks without requiring a constant internet connection. The tool provides mechanisms for refining identification accuracy, including an interactive mode for manual version overriding and configurable matching logic to filter results. It manages security data through a system for loading local datasets and synchr

    Lua
    View on GitHub↗3,761

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • yogeshojha/rengineyogeshojha avatar

    yogeshojha/rengine

    8,472View on GitHub↗

    Rengine is an automated reconnaissance framework and vulnerability management platform designed for attack surface monitoring. It functions as a centralized hub for discovering subdomains and open ports, gathering open-source intelligence, and tracking security flaws across target networks. The system integrates large language models to analyze reconnaissance data and generate vulnerability descriptions and insights. It distinguishes itself through a plugin-based tool integration that wraps external security scanning binaries and a target mapping system that tracks changes to assets over time

    HTMLbug-bountybugbountyhacking
    View on GitHub↗8,472
  • w-digital-scanner/w13scanw-digital-scanner avatar

    w-digital-scanner/w13scan

    1,945View on GitHub↗

    W13scan is an automated vulnerability assessment tool designed to identify security flaws in web applications through a modular plugin architecture. It functions as a scanning engine that executes specialized security logic against web endpoints to detect injection flaws, information leaks, and configuration errors. The platform distinguishes itself by combining active probing with passive traffic analysis and out-of-band detection. It utilizes a callback-based service to verify blind vulnerabilities that do not provide immediate feedback, and it operates as a proxy to intercept and inspect l

    Smartypassive-vulnerability-scannersecurity-tools
    View on GitHub↗1,945
  • v2-dev/awesome-social-engineeringv2-dev avatar

    v2-dev/awesome-social-engineering

    4,029View on GitHub↗

    This project is a curated collection of frameworks, libraries, and toolsets designed for social engineering and public data gathering. It aggregates specialized software and educational materials used to perform human-centric attacks during professional security engagements. The directory provides resources for gathering and visualizing open source intelligence to identify sensitive information leaks. It also includes a collection of methods and software for executing phishing campaigns to harvest credentials and session cookies. The repository further covers educational materials focused on

    View on GitHub↗4,029
  • kathanp19/howtohuntKathanP19 avatar

    KathanP19/HowToHunt

    7,146View on GitHub↗

    HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It provides a research methodology for organizing security testing procedures and validating application behaviors against known vulnerability patterns. The project features a curated library of security flaws and reconnaissance techniques. It organizes security testing into modular playbooks, checklists, and categorical vulnerability mappings to align specific exploitation techniques with target weaknesses. The repository covers a systematic sequence of information gathering task

    bugbountybugbountytipsbughunting-methodology
    View on GitHub↗7,146
  • sensepost/gowitnesssensepost avatar

    sensepost/gowitness

    4,174View on GitHub↗

    Gowitness is a system for rendering web interfaces at scale to capture visual snapshots, HTTP metadata, and network scan results. It functions as a headless browser screenshot tool and a web surface mapper used to identify and visually document the attack surface of network ranges and URL lists. The tool includes a screenshot gallery server that provides a web-based interface for browsing, filtering, and managing a database of captures. It specifically serves as an Nmap target visualizer, parsing network scan results to automatically capture screenshots of discovered web services. Capabiliti

    Gochromechrome-headlessfingerprint
    View on GitHub↗4,174
  • b1gcat/darkeyeB

    b1gcat/DarkEye

    0View on GitHub↗
    View on GitHub↗0
  • boy-hack/w8fuckcdnboy-hack avatar

    boy-hack/w8fuckcdn

    784View on GitHub↗

    Get website IP address by scanning the entire net 通过扫描全网绕过CDN获取网站IP地址

    Python
    View on GitHub↗784
  • boy-hack/w11scanboy-hack avatar

    boy-hack/w11scan

    472View on GitHub↗

    w11scan是一款分布式的WEB指纹识别系统(包括CMS识别、js框架、组件容器、代码语言、WAF等等),管理员可以在WEB端新增/修改指纹,建立批量的扫描任务,并且支持多种搜索语法。

    CSS
    View on GitHub↗472
  • chichou/grab.jschichou avatar

    chichou/grab.js

    50View on GitHub↗

    simple TCP banner grabbing with node.js

    Shell
    View on GitHub↗50
  • christruncer/eyewitnessChrisTruncer avatar

    ChrisTruncer/EyeWitness

    60View on GitHub↗

    EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.

    View on GitHub↗60
  • ascribe/image-matchascribe avatar

    ascribe/image-match

    2,975View on GitHub↗

    🎇 Quickly search over billions of images

    Python
    View on GitHub↗2,975
  • 1n3/sn1per1N3 avatar

    1N3/Sn1per

    10,049View on GitHub↗

    Sn1per is a vulnerability management platform and penetration testing orchestrator designed to automate reconnaissance, vulnerability scanning, and exploit verification. It functions as a dockerized security toolkit that coordinates multiple tools into a unified automated pipeline to identify security flaws across network and web assets. The platform features an attack surface manager for discovering internet-facing assets through OSINT, DNS enumeration, and certificate transparency. It distinguishes itself with an AI-powered security analyzer that uses large language models to summarize scan

    Shellattack-surfaceattack-surface-managementattacksurface
    View on GitHub↗10,049
  • boy-hack/gwhatwebboy-hack avatar

    boy-hack/gwhatweb

    213View on GitHub↗

    CMS识别 python gevent实现

    Python
    View on GitHub↗213
  • deibit/cansinadeibit avatar

    deibit/cansina

    899View on GitHub↗

    Web Content Discovery Tool

    Pythonpentestingpythonsecurity-audit
    View on GitHub↗899
  • danmcinerney/fast-reconDanMcInerney avatar

    DanMcInerney/fast-recon

    166View on GitHub↗

    Does some google dorks against a domain

    Python
    View on GitHub↗166
  • blackye/webdirdigblackye avatar

    blackye/webdirdig

    129View on GitHub↗

    webdirdig web敏感目录\信息泄漏扫描脚本

    Python
    View on GitHub↗129
  • dionach/cmsmapDionach avatar

    Dionach/CMSmap

    1,166View on GitHub↗

    CMSmap is a python open source CMS scanner that automates the process of detecting security flaws of the most popular CMSs.

    Python
    View on GitHub↗1,166
  • droope/droopescandroope avatar

    droope/droopescan

    1,432View on GitHub↗

    A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstripe.

    HTML
    View on GitHub↗1,432
  • dzonerzy/gowaptdzonerzy avatar

    dzonerzy/goWAPT

    347View on GitHub↗

    GOWAPT is the younger brother of wfuzz a swiss army knife of WAPT, it allow pentester to perform huge activity with no stress at all, just configure it and it's just a matter of clicks.

    Go
    View on GitHub↗347
  • ekultek/whatbreachEkultek avatar

    Ekultek/WhatBreach

    1,598View on GitHub↗

    OSINT tool to find breached emails, databases, pastes, and relevant information

    Pythonbreachbreachesdomains
    View on GitHub↗1,598
  • aipengjie/sensitivefilescanaipengjie avatar

    aipengjie/sensitivefilescan

    183View on GitHub↗

    this tools can be searched web leak files

    Python
    View on GitHub↗183
  • federicodotta/java-deserialization-scannerfedericodotta avatar

    federicodotta/Java-Deserialization-Scanner

    802View on GitHub↗

    All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities

    Java
    View on GitHub↗802
  • fnk0c/cangibrinafnk0c avatar

    fnk0c/cangibrina

    239View on GitHub↗

    ` / | () | () | | / | ' \ / | | ' \| '| | ' \ / | | || (| | | | | (| | | |) | | | | | | | (| | \\,|| ||\, ||./|| ||| ||\,| |/ Beta - v0.8.7 Dashboard Finder ``

    Python
    View on GitHub↗239
  • furduhlutur/yarFurduhlutur avatar

    Furduhlutur/yar

    241View on GitHub↗

    Yar is a tool for plunderin' organizations, users and/or repositories.

    Go
    View on GitHub↗241
  • ggusoft/inforfinderggusoft avatar

    ggusoft/inforfinder

    68View on GitHub↗

    Inforfinder is a tool made to collect information of any domain pointing at a server (ip,domain,range,file).

    Python
    View on GitHub↗68
  • d3vilbug/hackbard3vilbug avatar

    d3vilbug/HackBar

    1,627View on GitHub↗

    HackBar plugin for Burpsuite

    Java
    View on GitHub↗1,627