awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to nekmo/dirhunt

Open-source alternatives to Dirhunt

30 open-source projects similar to nekmo/dirhunt, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Dirhunt alternative.

  • xmendez/wfuzzxmendez avatar

    xmendez/wfuzz

    6,519View on GitHub↗

    Wfuzz is a web application fuzzing framework that automates the injection of payloads into HTTP requests to discover hidden resources, parameters, and vulnerabilities. It functions as a content discovery scanner, a brute-force tool for credential guessing, and a plugin-based vulnerability scanner, all within a single modular system. The tool distinguishes itself through its plugin-based extensibility, allowing custom Python modules to add new payload sources, output printers, or scanning logic without modifying core code. It supports concurrent request dispatch using thread-based parallelism

    Python
    View on GitHub↗6,519
  • yogeshojha/rengineyogeshojha avatar

    yogeshojha/rengine

    8,472View on GitHub↗

    Rengine is an automated reconnaissance framework and vulnerability management platform designed for attack surface monitoring. It functions as a centralized hub for discovering subdomains and open ports, gathering open-source intelligence, and tracking security flaws across target networks. The system integrates large language models to analyze reconnaissance data and generate vulnerability descriptions and insights. It distinguishes itself through a plugin-based tool integration that wraps external security scanning binaries and a target mapping system that tracks changes to assets over time

    HTMLbug-bountybugbountyhacking
    View on GitHub↗8,472
  • sensepost/gowitnesssensepost avatar

    sensepost/gowitness

    4,174View on GitHub↗

    Gowitness is a system for rendering web interfaces at scale to capture visual snapshots, HTTP metadata, and network scan results. It functions as a headless browser screenshot tool and a web surface mapper used to identify and visually document the attack surface of network ranges and URL lists. The tool includes a screenshot gallery server that provides a web-based interface for browsing, filtering, and managing a database of captures. It specifically serves as an Nmap target visualizer, parsing network scan results to automatically capture screenshots of discovered web services. Capabiliti

    Gochromechrome-headlessfingerprint
    View on GitHub↗4,174

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • kathanp19/howtohuntKathanP19 avatar

    KathanP19/HowToHunt

    7,146View on GitHub↗

    HowToHunt is a bug bounty hunting knowledge base and a structured guide for web application penetration testing. It provides a research methodology for organizing security testing procedures and validating application behaviors against known vulnerability patterns. The project features a curated library of security flaws and reconnaissance techniques. It organizes security testing into modular playbooks, checklists, and categorical vulnerability mappings to align specific exploitation techniques with target weaknesses. The repository covers a systematic sequence of information gathering task

    bugbountybugbountytipsbughunting-methodology
    View on GitHub↗7,146
  • aleff-github/wayparamaleff-github avatar

    aleff-github/wayparam

    6View on GitHub↗

    Fetch and normalize parameterized URLs from the Wayback CDX API (OSINT, inspired by ParamSpider).

    Python
    View on GitHub↗6
  • b1gcat/darkeyeB

    b1gcat/DarkEye

    0View on GitHub↗
    View on GitHub↗0
  • 1n3/blackwidow1N3 avatar

    1N3/BlackWidow

    1,804View on GitHub↗
    Pythonactiveapplicationautomated
    View on GitHub↗1,804
  • boy-hack/gwhatwebboy-hack avatar

    boy-hack/gwhatweb

    213View on GitHub↗

    CMS识别 python gevent实现

    Python
    View on GitHub↗213
  • aipengjie/sensitivefilescanaipengjie avatar

    aipengjie/sensitivefilescan

    183View on GitHub↗

    this tools can be searched web leak files

    Python
    View on GitHub↗183
  • boy-hack/w11scanboy-hack avatar

    boy-hack/w11scan

    472View on GitHub↗

    w11scan是一款分布式的WEB指纹识别系统(包括CMS识别、js框架、组件容器、代码语言、WAF等等),管理员可以在WEB端新增/修改指纹,建立批量的扫描任务,并且支持多种搜索语法。

    CSS
    View on GitHub↗472
  • boy-hack/w8fuckcdnboy-hack avatar

    boy-hack/w8fuckcdn

    784View on GitHub↗

    Get website IP address by scanning the entire net 通过扫描全网绕过CDN获取网站IP地址

    Python
    View on GitHub↗784
  • chichou/grab.jschichou avatar

    chichou/grab.js

    50View on GitHub↗

    simple TCP banner grabbing with node.js

    Shell
    View on GitHub↗50
  • cillian-collins/dirscraperCillian-Collins avatar

    Cillian-Collins/dirscraper

    226View on GitHub↗

    OSINT scanning tool which discovers and maps directories found in javascript files hosted on a website.

    Python
    View on GitHub↗226
  • cloudtracer/pasktocloudtracer avatar

    cloudtracer/paskto

    150View on GitHub↗

    Paskto will passively scan the web using the Common Crawl internet index either by downloading the indexes on request or parsing data from your local system. URLs are then processed through Nikto and known URL lists to identify interesting content. Hash signatures are also used to identify known…

    JavaScript
    View on GitHub↗150
  • dzonerzy/gowaptdzonerzy avatar

    dzonerzy/goWAPT

    347View on GitHub↗

    GOWAPT is the younger brother of wfuzz a swiss army knife of WAPT, it allow pentester to perform huge activity with no stress at all, just configure it and it's just a matter of clicks.

    Go
    View on GitHub↗347
  • bo0om/fuzz.txtBo0oM avatar

    Bo0oM/fuzz.txt

    3,312View on GitHub↗

    Potentially dangerous files

    View on GitHub↗3,312
  • deibit/cansinadeibit avatar

    deibit/cansina

    899View on GitHub↗

    Web Content Discovery Tool

    Pythonpentestingpythonsecurity-audit
    View on GitHub↗899
  • ekultek/whatwafEkultek avatar

    Ekultek/WhatWaf

    2,901View on GitHub↗

    Detect and bypass web application firewalls and protection systems

    Python
    View on GitHub↗2,901
  • enablesecurity/wafw00fEnableSecurity avatar

    EnableSecurity/wafw00f

    6,414View on GitHub↗

    WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

    Python
    View on GitHub↗6,414
  • epinna/tplmapepinna avatar

    epinna/tplmap

    4,169View on GitHub↗

    tplmap is a security tool designed for the detection and exploitation of server-side template injection vulnerabilities. It functions as an automated scanner to identify vulnerable template engine contexts and provides a framework for achieving remote code execution. The tool focuses on translating high-level requests into engine-specific syntax to execute operating system commands and bypass application sandboxes. It further enables remote file system access, allowing users to read, write, and transfer files between a local machine and a target server. Additional capabilities include the ab

    Python
    View on GitHub↗4,169
  • fnk0c/cangibrinafnk0c avatar

    fnk0c/cangibrina

    239View on GitHub↗

    ` / | () | () | | / | ' \ / | | ' \| '| | ' \ / | | || (| | | | | (| | | |) | | | | | | | (| | \\,|| ||\, ||./|| ||| ||\,| |/ Beta - v0.8.7 Dashboard Finder ``

    Python
    View on GitHub↗239
  • fuzzdb-project/fuzzdbfuzzdb-project avatar

    fuzzdb-project/fuzzdb

    8,819View on GitHub↗

    fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a fuzzing payload dictionary, a resource discovery wordlist, and a fault injection dataset containing corrupted Unicode, null bytes, and escape codes to trigger application crashes and logic errors. The project includes a security filter bypass list featuring polyglots and encoded strings to evade web application firewalls and input validation filters. It also provides a comprehensive web application penetration testing dataset specifically for identifying flaws such as cross-s

    PHP
    View on GitHub↗8,819
  • ggusoft/inforfinderggusoft avatar

    ggusoft/inforfinder

    68View on GitHub↗

    Inforfinder is a tool made to collect information of any domain pointing at a server (ip,domain,range,file).

    Python
    View on GitHub↗68
  • google/domatogoogle avatar

    google/domato

    1,784View on GitHub↗

    DOM fuzzer

    Python
    View on GitHub↗1,784
  • gosecure/dtd-finderGoSecure avatar

    GoSecure/dtd-finder

    661View on GitHub↗

    List DTDs and generate XXE payloads using those local DTDs.

    Kotlin
    View on GitHub↗661
  • h4ckforjob/dirmapH4ckForJob avatar

    H4ckForJob/dirmap

    3,366View on GitHub↗

    @Author: xxlin @Date: 2019-04-11 20:34:14 @LastEditors: ttttmr @LastEditTime: 2019-06-03 23:49:33 -->

    Python
    View on GitHub↗3,366
  • hack-all-the-things/charsetinspecthack-all-the-things avatar

    hack-all-the-things/charsetinspect

    28View on GitHub↗

    A script that inspects multi-byte character sets looking for characters with specific user-defined properties

    Python
    View on GitHub↗28
  • jekyc/wigjekyc avatar

    jekyc/wig

    552View on GitHub↗

    wig is a web application information gathering tool, which can identify numerous Content Management Systems and other administrative applications.

    Python
    View on GitHub↗552
  • commixproject/commixcommixproject avatar

    commixproject/commix

    5,757View on GitHub↗

    Commix is an automated tool for detecting and exploiting OS command injection vulnerabilities in web applications. It probes user-supplied input vectors with heuristic test payloads, analyzes response differences to identify injection points, and then automates the execution of arbitrary operating system commands on the target server. The tool distinguishes itself through a multi-layer filter bypass engine that evaluates input constraints independently per filter type and composes tailored evasion strategies into a single payload. A modular payload tamper pipeline transforms raw injection str

    Python
    View on GitHub↗5,757
  • blackye/webdirdigblackye avatar

    blackye/webdirdig

    129View on GitHub↗

    webdirdig web敏感目录\信息泄漏扫描脚本

    Python
    View on GitHub↗129