ARSENAL DE FERRAMENTAS
Colecao de 32 ferramentas de seguranca ofensiva desenvolvidas para bug bounty e pentest. Recon, scanners, cloud security, secrets hunting e muito mais.
DESTAQUES
MonRust3
Flagship — full-stack recon platform with real-time UI
Acesso via treinamento
CloudFinder
Multi-cloud + 100+ secret types + JS vuln engine
Acesso via treinamento
mcpBurp
MCP server — Burp Suite controlled by Claude
Acesso via treinamento
CATEGORIAS
Recon Platforms
Flagship products with UI - SaaS & DashboardsMonRust3
Flagship — full-stack recon platform with real-time UI
MonRust 2.0
Predecessor — tmux-driven monitor with parallel orchestration
BLOB Hunter
Multi-org Git secrets SaaS (FastAPI + React)
GitHub Intelligence
GitHub MRI account intel dashboard
PostRecon
Web UI + MCP for Postman public scanning
LovableExpl
Supabase JWT validator + DB explorer with web UI
FirebaseEx
Firebase enumerator (Web UI + CLI + REST API)
EnumRust
Real-time security scanner with web dashboard
Web Vulnerability Scanners
Point at a target, get findingsBLH-Hunter
Broken link hijacking across 23+ platforms
ORSCAN
Open redirect scanner — crawl + hidden params + 30+ payloads
Cache Storm
Web cache poisoning at scale (11 techniques, CDN-aware)
ActuatoRust
Spring Boot Actuator scanner with heap dump validation
NagliRecon
All-in-one recon + 40K vuln patterns from WooYun
EnumInfra
CTF / pentest infra enum (18+ tools, AD coverage)
Cloud & Storage
AWS / GCP / Azure / R2 bucketsCloudFinder
Multi-cloud + 100+ secret types + JS vuln engine
S3Scan
8-cloud bucket scanner with Lambda fan-out
MongoDBCRAWL
Open MongoDB scanner with auto-dump
Secrets & Tokens
JS / Git / Postman / GTM secret huntingJSHunter
Deep JS analysis + Cognito exploitation chain
IACrawl
132 patterns across 52+ AI/cloud services + exploit engine
CrawAlgolia
Specialist Algolia key hunter with index siege
crawlGTM
GTM container OSINT + reverse lookup (7 sources)
PostEvil
Postman public-library credential hunter
JS Realtime
Chrome extension passively captures JS secrets
JS Realtime Server
Companion server — 40+ secret patterns + token validation
JWT Token Hunter
Browser extension that finds JWTs (Supabase / Vercel)
Identity Providers
Cognito / Supabase / Firebase / JWTCrawlCognito
AWS Cognito 8-step auto-exploitation chain
JSHunter
Cognito module — 330+ AWS permission tests
LovableExpl
Supabase JWT → full DB dump
FirebaseEx
Firestore + RTDB enumeration
Supply Chain
Dependency confusion across ecosystemsDependencyRust
Manifest scan + dorks + PoC payloads (9 ecosystems)
Confussed
Auto-publish PoC packages with OOB callbacks
Distributed / AI
Lambda fan-out + LLM-driven enginesLemma
Multi-Lambda recon suite (40+ tools on AWS)
mcpBurp
MCP server — Burp Suite controlled by Claude
Browser & Fuzzing
Extensions, MCP servers, PostmanJWT Token Hunter
Chrome extension for JWT detection
JS Realtime
Chrome extension that streams JS to analyzer
FFUF Master
Bug-bounty-grade FFUF wrapper with 5 modes
QUER ACESSO AS FERRAMENTAS?
Todas as ferramentas sao privadas e disponiveis exclusivamente para alunos do treinamento. Entre em contato para saber mais.