30 open-source projects similar to evilsocket/ditto, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.
Striker is an offensive information and vulnerability scanner.
jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit deserialization flaws to achieve remote code execution on target servers. It functions as a suite of tools for delivering payloads and executing system commands on vulnerable remote applications. The project includes a reverse shell orchestrator to establish and maintain persistent remote command connections from exploited targets back to a listener. It also provides post-exploitation automation for managing remote access and updating software on compromised systems. The fra
MyIP is a network diagnostics toolbox designed for analyzing public IP addresses, geolocation, and network connectivity performance. It provides utilities for identifying IPv4 and IPv6 addresses and analyzing their associated organization, ASN, and geographic details. The project features specialized privacy and security tools, including a network leak tester to detect DNS and WebRTC leaks used to verify VPN or proxy configurations. It also includes a browser fingerprint analyzer that generates unique client identifiers to audit how device attributes are used for online tracking. The platfor
RouterSploit is an embedded device exploitation framework and vulnerability scanner designed to identify and exploit security flaws in networked embedded hardware and firmware. It provides a centralized toolkit for scanning for known weaknesses and common misconfigurations to gain unauthorized system access. The framework includes an architecture-specific payload generator to create custom binary payloads tailored to the target hardware. It also features an automated brute force tool that uses dictionary-based credential guessing to bypass authentication on hardware devices. The tool covers
OSINT-SPY is an open-source reconnaissance framework designed for gathering intelligence on digital infrastructure and tracking financial activity across distributed ledgers. It functions as a centralized orchestrator that queries multiple third-party services and public databases to aggregate security data points into a unified format. The system utilizes a modular, plugin-based architecture that allows for independent data gathering tasks, ranging from domain and IP address reconnaissance to the analysis of remote files for malicious signatures. It supports specialized investigations into c
Mosint is an email OSINT framework and intelligence tool designed to gather data and identify digital footprints associated with email addresses. It functions as a suite of automated utilities for email validation, breach scanning, and social account discovery. The tool maps digital identities by linking email addresses to social media profiles and identifying related identities to expand the scope of investigations. It includes a breach scanner that checks email addresses against known database leaks and password dumps to detect compromised accounts. The framework also covers network intell
Blinks is a powerful Burp Suite extension that automates active scanning with Burp Suite Pro and enhances its functionality. With the integration of webhooks, this tool sends real-time updates whenever a new issue is identified, directly to your preferred endpoint. No more waiting for final reports – you get instant, actionable insights! 🛠️
HTTP Request Smuggling Detection Tool
Trivy is a comprehensive security scanner designed to identify vulnerabilities and misconfigurations across container images, filesystems, and infrastructure as code files. It functions as a software composition analysis tool and an infrastructure security scanner, providing automated checks for CI/CD pipelines and cloud environments to ensure the integrity of the software supply chain. The tool distinguishes itself through a modular, plugin-based architecture that allows for the independent inspection of diverse targets. It utilizes a declarative policy engine to evaluate configurations agai
Arachni is a dynamic application security testing vulnerability scanner and web application security tool. It functions as a distributed web audit framework that performs active and passive audits to identify security flaws such as SQL injection and cross-site scripting. The project features a JavaScript-aware web crawler that executes scripts and monitors DOM changes to analyze modern dynamic web applications. It utilizes server platform fingerprinting to target compatible security payloads and provides a grid-based system to distribute scanning workloads across multiple nodes. The tool cov
A cross-platform python based utility for information gathering and penetration testing automation!
A root exploit for CVE-2022-0847 (Dirty Pipe)
Burp Suite extension to passively scan for applications revealing server error messages
Burp Suite plugin identifies insertion points for GWT (Google Web Toolkit) requests
Burp extension to passively scan for applications revealing software version numbers
WRecon, is a tool for the recognition of vulnerabilities and blackbox information for wordpress.
This is an exploit for the CVE-2021-3156 sudo vulnerability (dubbed Baron Samedit by Qualys).
w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing