How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.
Dalfox is an automated web application security tool specifically designed for discovering and verifying cross-site scripting vulnerabilities. It functions as an XSS vulnerability scanner that analyzes HTTP parameters and DOM structures to identify reflected, stored, and blind injection points. The project distinguishes itself by providing a Model Context Protocol server and a REST API, allowing artificial intelligence agents and remote interfaces to trigger and manage security scans programmatically. It utilizes a payload mutation engine and fingerprinting strategies to execute WAF evasion t
This project is an open-source intelligence reconnaissance framework and recursive attack surface mapper. It functions as a containerized security scanner designed to map public-facing infrastructure, perform subdomain enumeration, and automate the gathering of open-source intelligence. The system employs a recursive discovery engine to iteratively explore target infrastructure, utilizing a plugin-based module architecture to extend scanning capabilities. It integrates third-party APIs for data enrichment and applies YARA rules across discovered assets to identify specific vulnerability patte
GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations
This tool for brute discover GET and POST parameters.
The main features of bo0om/parampampam are: Fuzzing Tools, Parameter Discovery.
Open-source alternatives to bo0om/parampampam include: hahwul/dalfox — Dalfox is an automated web application security tool specifically designed for discovering and verifying cross-site… blacklanternsecurity/bbot — This project is an open-source intelligence reconnaissance framework and recursive attack surface mapper. It functions… assetnote/batchql — GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations. assetnote/kiterunner — Contextual Content Discovery Tool. brendan-rius/c-jwt-cracker — JWT brute force cracker written in C. 1n3/brutex.