White-box web app testing, source code review, custom exploit chains.
Official PageStatic analysis for finding security patterns
pip3 install semgrepsemgrep --config p/php-security src/Git repository extraction tools
git clone https://github.com/internetwache/GitTools./gitdumper.sh http://target/.git/ /output; ./extractor.sh /output /extractedPHP gadget chain generator (like ysoserial for PHP)
git clone https://github.com/ambionics/phpggc./phpggc -l; ./phpggc Laravel/RCE1 system idJava deserialization exploit gadget generator
Download jar from releasesjava -jar ysoserial.jar CommonsCollections1 "id" > payload.serJWT testing and attacking tool
git clone https://github.com/ticarpi/jwt_tool && pip3 install -r requirements.txtpython3 jwt_tool.py <token> -X aAdvanced web proxy with scanner
Download from portswigger.netActive scan, Intruder, custom extensions