awesome-repositories.com
Blog
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to federicodotta/java-deserialization-scanner

Open-source alternatives to Java Deserialization Scanner

30 open-source projects similar to federicodotta/java-deserialization-scanner, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Java Deserialization Scanner alternative.

  • dionach/cmsmapDionach avatar

    Dionach/CMSmap

    1,166View on GitHub↗

    CMSmap is a python open source CMS scanner that automates the process of detecting security flaws of the most popular CMSs.

    Python
    View on GitHub↗1,166
  • bishopfox/gadgetprobeBishopFox avatar

    BishopFox/GadgetProbe

    616View on GitHub↗

    Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.

    Java
    View on GitHub↗616
  • arachni/arachniArachni avatar

    Arachni/arachni

    4,000View on GitHub↗

    Arachni is a dynamic application security testing vulnerability scanner and web application security tool. It functions as a distributed web audit framework that performs active and passive audits to identify security flaws such as SQL injection and cross-site scripting. The project features a JavaScript-aware web crawler that executes scripts and monitors DOM changes to analyze modern dynamic web applications. It utilizes server platform fingerprinting to target compatible security payloads and provides a grid-based system to distribute scanning workloads across multiple nodes. The tool cov

    Rubyanalysisarachniaudit
    View on GitHub↗4,000
  • h3xstream/burp-retire-jsh3xstream avatar

    h3xstream/burp-retire-js

    213View on GitHub↗

    Burp/ZAP/Maven extension that integrate Retire.js repository to find vulnerable Javascript libraries.

    JavaScript
    View on GitHub↗213

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • portswigger/backslash-powered-scannerPortSwigger avatar

    PortSwigger/backslash-powered-scanner

    712View on GitHub↗

    Finds unknown classes of injection vulnerabilities

    Java
    View on GitHub↗712
  • portswigger/httpoxy-scannerPortSwigger avatar

    PortSwigger/httpoxy-scanner

    95View on GitHub↗

    A Burp Suite extension that checks for the HTTPoxy vulnerability.

    Java
    View on GitHub↗95
  • linkedin/sometimelinkedin avatar

    linkedin/sometime

    60View on GitHub↗

    A BurpSuite plugin to detect Same Origin Method Execution vulnerabilities

    Java
    View on GitHub↗60
  • voulnet/desharializeV

    Voulnet/desharialize

    0View on GitHub↗
    View on GitHub↗0
  • projectdiscovery/nucleiprojectdiscovery avatar

    projectdiscovery/nuclei

    29,189View on GitHub↗

    Nuclei is a modular security scanning framework designed for automated vulnerability detection and infrastructure reconnaissance. It functions as a template-driven engine that executes security checks across diverse network protocols, allowing users to define custom detection logic to identify vulnerabilities, misconfigurations, and exposed assets. The platform distinguishes itself through its highly extensible architecture, which supports distributed scanning, headless browser automation for dynamic web content, and out-of-band interaction monitoring to detect blind vulnerabilities. It integ

    Goattack-surfacecve-scannerdast
    View on GitHub↗29,189
  • trufflesecurity/trufflehogtrufflesecurity avatar

    trufflesecurity/trufflehog

    24,630View on GitHub↗

    Trufflehog is a security tool designed to continuously monitor code repositories and cloud environments to detect, verify, and remediate exposed sensitive credentials and API keys. It functions as a comprehensive secret scanning engine that integrates directly into deployment pipelines and version control systems to intercept sensitive data before it is committed or pushed. By utilizing read-only operations and volatile memory processing, the system ensures that discovered credentials are never stored persistently, maintaining strict data privacy throughout the scanning lifecycle. The platfor

    Gocredentialsdevsecopsdynamic-analysis
    View on GitHub↗24,630
  • vulnerscom/burp-vulners-scannervulnersCom avatar

    vulnersCom/burp-vulners-scanner

    897View on GitHub↗

    Vulnerability scanner based on vulners.com search API

    Java
    View on GitHub↗897
  • wpscanteam/wpscanwpscanteam avatar

    wpscanteam/wpscan

    9,636View on GitHub↗

    WPScan is a security analysis utility and vulnerability scanner designed specifically for auditing WordPress installations and other content management systems. It functions as a web application security tool that identifies misconfigurations, outdated software, and security holes in core installations, plugins, and themes. The tool employs black-box scanning techniques to perform site component enumeration, identifying users, themes, and plugins by matching known file paths and response signatures. It matches these detected components against a database of known security flaws to analyze the

    Ruby
    View on GitHub↗9,636
  • s0md3v/xsstrikes0md3v avatar

    s0md3v/XSStrike

    14,752View on GitHub↗

    XSStrike is an automated security scanning engine designed for web application discovery, input

    Pythonwaf-detectionxssxss-bruteforce
    View on GitHub↗14,752
  • sullo/niktosullo avatar

    sullo/nikto

    10,104View on GitHub↗

    Nikto is an open-source HTTP security auditing tool and web server vulnerability scanner. It functions as a reconnaissance engine designed to identify insecure server options, outdated software, and common vulnerabilities by analyzing HTTP responses. The project differentiates itself through capabilities for intrusion detection evasion and web server fingerprinting. It uses request-level encoding and timing spacers to bypass security filters and employs signature-based identification to determine specific server software versions and misconfigurations. The scanner covers broad capability are

    Perl
    View on GitHub↗10,104
  • w-digital-scanner/w13scanw-digital-scanner avatar

    w-digital-scanner/w13scan

    1,945View on GitHub↗

    W13scan is an automated vulnerability assessment tool designed to identify security flaws in web applications through a modular plugin architecture. It functions as a scanning engine that executes specialized security logic against web endpoints to detect injection flaws, information leaks, and configuration errors. The platform distinguishes itself by combining active probing with passive traffic analysis and out-of-band detection. It utilizes a callback-based service to verify blind vulnerabilities that do not provide immediate feedback, and it operates as a proxy to intercept and inspect l

    Smartypassive-vulnerability-scannersecurity-tools
    View on GitHub↗1,945
  • reverse-shell/routersploitreverse-shell avatar

    reverse-shell/routersploit

    13,151View on GitHub↗

    RouterSploit is an embedded device exploitation framework and vulnerability scanner designed to identify and exploit security flaws in networked embedded hardware and firmware. It provides a centralized toolkit for scanning for known weaknesses and common misconfigurations to gain unauthorized system access. The framework includes an architecture-specific payload generator to create custom binary payloads tailored to the target hardware. It also features an automated brute force tool that uses dictionary-based credential guessing to bypass authentication on hardware devices. The tool covers

    Python
    View on GitHub↗13,151
  • joaomatosf/jexbossjoaomatosf avatar

    joaomatosf/jexboss

    2,512View on GitHub↗

    jexboss is a Java deserialization exploit framework and network vulnerability scanner designed to identify and exploit deserialization flaws to achieve remote code execution on target servers. It functions as a suite of tools for delivering payloads and executing system commands on vulnerable remote applications. The project includes a reverse shell orchestrator to establish and maintain persistent remote command connections from exploited targets back to a listener. It also provides post-exploitation automation for managing remote access and updating software on compromised systems. The fra

    Pythondeserializationexploitexploiting-vulnerabilities
    View on GitHub↗2,512
  • byt3bl33d3r/crackmapexecbyt3bl33d3r avatar

    byt3bl33d3r/CrackMapExec

    9,144View on GitHub↗

    CrackMapExec is a network penetration testing framework and automated security scanner designed to assess security postures across large IP ranges. It functions as a multi-protocol security scanner and network protocol auditor used to identify vulnerabilities and misconfigurations. The tool provides capabilities for Active Directory auditing to enumerate users and permissions, as well as post-exploitation enumeration to gather system metadata and discover lateral movement paths. It includes a framework for credential spraying and harvesting across various network services. The system utilize

    Python
    View on GitHub↗9,144
  • anshumanpattnaik/http-request-smugglinganshumanpattnaik avatar

    anshumanpattnaik/http-request-smuggling

    539View on GitHub↗

    HTTP Request Smuggling Detection Tool

    Python
    View on GitHub↗539
  • andresriancho/w3afandresriancho avatar

    andresriancho/w3af

    4,850View on GitHub↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    Pythonappseccross-site-scriptingscanner
    View on GitHub↗4,850
  • 1337g/cve-2017-102711

    1337g/CVE-2017-10271

    0View on GitHub↗
    View on GitHub↗0
  • alexcowperthwaite/passkeyscanneralexcowperthwaite avatar

    alexcowperthwaite/PasskeyScanner

    3View on GitHub↗
    Java
    View on GitHub↗3
  • augustd/burp-suite-gwt-scanaugustd avatar

    augustd/burp-suite-gwt-scan

    13View on GitHub↗

    Burp Suite plugin identifies insertion points for GWT (Google Web Toolkit) requests

    Java
    View on GitHub↗13
  • augustd/burp-suite-error-message-checksaugustd avatar

    augustd/burp-suite-error-message-checks

    65View on GitHub↗

    Burp Suite extension to passively scan for applications revealing server error messages

    Java
    View on GitHub↗65
  • augustd/burp-suite-software-version-checksaugustd avatar

    augustd/burp-suite-software-version-checks

    33View on GitHub↗

    Burp extension to passively scan for applications revealing software version numbers

    Java
    View on GitHub↗33
  • auth0/repo-supervisorauth0 avatar

    auth0/repo-supervisor

    653View on GitHub↗

    Scan your code for security misconfiguration, search for passwords and secrets. :mag:

    JavaScript
    View on GitHub↗653
  • baidu/openraspbaidu avatar

    baidu/openrasp

    2,964View on GitHub↗

    🔥Open source RASP solution

    C++
    View on GitHub↗2,964
  • bb00/zer0dumpB

    bb00/zer0dump

    0View on GitHub↗
    View on GitHub↗0
  • bbaranoff/cve-2022-0847B

    bbaranoff/CVE-2022-0847

    0View on GitHub↗
    View on GitHub↗0
  • albinowax/activescanplusplusalbinowax avatar

    albinowax/ActiveScanPlusPlus

    661View on GitHub↗

    ActiveScan++ Burp Suite Plugin

    Java
    View on GitHub↗661