Open source
Tools I use on real targets
Small command-line tools for pentests and bug bounty, written in Go, Python or Bash. The source, install steps and issue trackers are public.
unwaf
Discover the real origin IP behind a WAF/CDN using passive techniques.Descubre la IP de origen real detrás de un WAF/CDN usando técnicas pasivas.
resolvalid
A fast, concurrent DNS server validator written in Go.Un validador de servidores DNS rápido y concurrente escrito en Go.
exifray
Find the documents a domain publishes and turn their metadata into recon.Encuentra los documentos que publica un dominio y convierte sus metadatos en recon.
Built because I needed them
Each tool removes a repetitive step from reconnaissance or validation. The pentest service is where those utilities sit inside a complete testing method.