404checker
Headless check for URLs that return 200 but render not-found.
loading
Every tool you can run in a Trickest workflow, 309 in total. Each page covers what the tool does, its real inputs and outputs, the skills it belongs to, and a runnable example.
A tool is one step. A workflow is a graph of them: the output of one node becomes the input of the next, and every node keeps its results for you to read after the run. Start from a tool when you know the command you want. Start from a workflow when you know the answer you want.
309 items
Headless check for URLs that return 200 but render not-found.
BHUSA Arsenal TLS/SSH crypto inventory with post-quantum readiness signals and CBOM-shaped output.
Async DNS brute force for subdomains that passive sources miss.
Reflection triage for parameter URLs during recon.
Import, export, and upsert workflow data against an Airtable base.
Pattern-based subdomain wordlist generator from known names.
Multi-source subdomain discovery; hand names to httpx.
OWASP Amass intel: map an organization's root domains and ranges.
OWASP Amass enumeration that emits structured JSON.
Find related domains via shared Google Analytics IDs.
Append lines to a file only if they are not already there.
Decode Android APK files into smali sources and resources.
Extract URLs and endpoints from Android APK files.
Visual inspection of websites across many hosts.
Map an organization's network ranges from ASN data.
Check a file's values against conditions and exit with a matching code.
Find domains and subdomains potentially related to a given domain.
Authenticated Route53 hosted-zone inventory.
List and flag sensitive keys across many S3 buckets.
AST-based security checks for Python source.
Merge the target's DNS servers with public resolvers into one pool.
Extract file or folder lines by START_LINE,END_LINE batch range.
Extract a START,END batch from file lines or folder files.
Modular OSINT recon that chains modules from a seed target.
CLI client for the BeVigil OSINT API, keyed by domain or app package.
Checks live URLs for backup files and exposed version-control paths.
Fingerprint the software version of a remote F5 BIG-IP management interface.
Scan software bills of materials for known-vulnerable dependencies.
Find broken links, missing images, and other dead HTML references.
A focused Go script that probes 403 Forbidden responses for known bypasses.
Crawl a domain list and scan responses for endpoints, secrets, tokens, and juicy files.
Discover the origin host behind a reverse proxy, useful when a cloud WAF hides the backend.
Extract URLs for a specific target from commoncrawl.org indexes.
Detect CDN, WAF, and cloud technology for a given IP or hostname.
Organize community Nuclei templates from across the ecosystem in one place.
Scrape domain names from SSL certificates of arbitrary hosts.
Pull a domain's subdomains from the crt.sh certificate transparency database.
Spider a URL and return a wordlist for password crackers.
Go client for ProjectDiscovery Chaos DB subdomain lookups.
Signature scanner for exposed files, folders, and services on web roots.
Module-driven extractor for Wayback Machine page history.
Regex-clean a wordlist before the slow stage reads it.
Multi-cloud public name enumeration for AWS, Azure, and GCP.
List assets from multiple cloud providers in one inventory.
Spider pages and scrape linked cloud resource strings.
CMS detection and version fingerprinting.
Automates OS command injection detection and exploitation.
Crack weak signing secrets on stateless session cookies.
Find Cross-Origin Resource Sharing misconfigurations on a URL list.
Browser-driven crawler that harvests requests for downstream scanners.
Directory and file brute forcing across many hosts.
Find HTTP response splitting in parameterized URLs.
Go-based CRLF injection scanner for URLs and URL lists.
Passive LinkedIn employee enumeration through search engine results.
Discover related domains from Content-Security-Policy headers.
Username enumeration against OpenSSH via CVE-2018-15473.
Version-based detection of Citrix builds exposed to CVE-2023-3519.
Parameter mining and XSS testing with headless verification.
Static review of Ruby source for security issues, CVEs, and OWASP risks.
Expand one CIDR into one IP per line.
Expand many CIDR ranges from one file.
Diff this run against a Trickest storage baseline.
Web path scanner.
Permute known subdomains, then resolve what lives.
Passive DNS records from DNSDumpster.
Passive DNSDumpster host lookup by domain.
Wordlist and mined-word subdomain permutation.
Subdomain takeover scanner with cloud-zone intake.
Active multi-technique DNS enumeration for assessments.
Generate lookalike domains and flag registered typosquats.
Validate public DNS resolvers against trusted baselines.
Keep only IPv4 resolvers that match baseline answers.
Multi-purpose DNS toolkit for resolution, record queries, and wordlist brute force.
Execute a custom shell script inside one or more Docker images.
Regex hunt for exposed API keys with exploitation hints.
Automate GitHub and GitLab dorking from a target list.
Filter or extract domains from URLs by subdomain level.
Tiny SQLi check for GET and POST parameters on one URL.
Tiny XSS check for GET and POST parameters on one URL.
Entropy and rules scan for hardcoded keys and passwords in large file trees.
Deduplicate a wordlist without sorting so probability order stays intact.
Git ripper that reconstructs repos even when directory browsing is off.
Persist attack-surface files in Elasticsearch and query them later.
List public repositories for each GitHub username you already have.
Node.js TCP connect scanner for a single IP or CIDR.
evilscan wrapped to TCP-scan a whole targets file.
Run a JavaScript file between workflow stages.
Upload a file or folder to Azure Blob with a SAS token.
Label website screenshots so interesting hosts surface first.
Crawl pages, harvest potential parameters, write a custom wordlist.
Hash favicons across a URL list and match them against a fingerprint dictionary.
Look up the real IP of a host from its favicon via Shodan.
Automate Local/Remote File Inclusion and directory traversal checks.
Recursive content discovery with smart defaults and rich response filters.
A fast web fuzzer written in Go.
Host-header fuzzing packaged for vhost discovery.
Filter file or folder lines by a fixed string.
Locate public CVE proof-of-concept repositories on GitHub.
Multi-cloud dangling DNS detection via zone-to-inventory diff, not wordlists.
Flag potential DOM-based XSS across a URL list.
Passive subdomain enumeration with optional resolve and HTTP checks.
Service fingerprinting for open host:port pairs.
Parallel ICMP echo sweeps for CIDR ranges and host files.
Domain-derived backup-file URL fuzzer.
Passive known-URL fetch from public web archives.
Maintained gau fork for passive archive URL collection.
Merge five scanner JSON streams into one host-keyed YAML report.
Pull named files from Trickest file storage into a workflow.
Pull acquired companies for a parent domain from SecurityTrails.
Resolve one ASN to the IP prefixes it announces.
Deprecated. Downloaded Trickest workflow node outputs by id.
Extract JavaScript file URLs from a page or URL list.
Named JSON patterns over grep for recon URL triage.
GitHub Archive URLs in, unique repository and user CSVs out.
GraphQL enrichment and dedupe for archive repo and user CSVs.
Filter scraped GitHub archive CSVs by star, fork, and watcher floors.
Parse GitHub Archive logs into deduplicated repository and user CSVs.
Report which GitHub repositories use Log4J, and which files reference it.
Hunt public GitHub code for leaked credential files.
Find endpoints for a domain in public GitHub code.
Find subdomains for a domain in public GitHub code.
Recover source from sites that leaked their .git directory.
Detect hardcoded secrets in git repos and plain directories.
Download exposed .git directories when listing is disabled.
Download an exposed .git and rebuild the working tree in one pass.
Reconstruct commits from a dumped .git folder.
Flag hosts that serve a publicly accessible .git directory.
Wordlist-driven subdomain permutations from known hosts.
Directory and file brute force against a live web target.
DNS subdomain brute force with wildcard handling.
Single-URL extractor for endpoints in HTML and embedded scripts.
Repeatable Google dorking through a Custom Search Engine.
Go AST security scanner for credentials, crypto, and injection.
Go web crawler for links, forms, and JS endpoints.
DNS wordlists through subdomain permutations.
Headless Chrome screenshots for web target triage.
Screenshot URLs and store capture metadata in SQLite.
Screenshot web services discovered in an nmap XML scan.
Make JSON greppable.
Email OSINT against breach services and local dumps.
HTTP status codes for a URL list. Nothing else.
Go crawler for URLs, forms, and JavaScript locations.
Bulk reverse DNS lookups from an IP list.
CLI client for SecurityTrails subdomain, WHOIS, and DNS modes.
Batch host header injection checks against a URL list.
OSINT mapping from IP addresses to virtual hostnames.
Timing-based CL.TE and TE.CL desync detection for a URL or URL list.
A human-friendly CLI HTTP client for APIs and servers.
Probe a domain list for working HTTP and HTTPS servers.
A fast and multi-purpose HTTP toolkit that runs multiple probers with reliable, high-throughput results.
Probe hosts with httpx and save a screenshot of each page.
Capture web host screenshots with httpx and export them as a zip.
Parallel network login cracker for SSH, FTP, HTTP forms, and related services.
Email OSINT from public sources, with optional breach checks.
Official IPinfo CLI for IP geolocation and ASN lookups.
Signature-driven web application scanner.
Batch deobfuscate JavaScript folders into readable source.
Passive subdomain lookup against the jldc.me Anubis API.
OWASP Joomla vulnerability scanner for CMS flaws and misconfigurations.
Extract URLs, paths, and secrets from JavaScript with a syntax tree.
Convert JSON into an HTML table for readable reports.
Decode, forge, crack, and tamper JWTs for auth checks.
A fast crawling and spidering framework.
Schema-aware API route discovery for modern apps.
Triage reflected special characters on parameterized URLs.
Scan GitHub orgs and URL responses for leaked secrets.
Discover endpoints and parameters inside JavaScript files.
Remote scanner for Log4Shell RCE, CVE-2021-44228.
Username search that collects accounts and profile data into one dossier.
Expand, aggregate, and slice CIDR ranges into host lists.
Sweep a host list for publicly accessible .git directories.
LinkFinder over a file of JavaScript URLs, with -r filter and -c cookies.
DNS existence check for a pre-compiled S3 bucket wordlist.
Asynchronous SYN port scanner for wide IP ranges; bound runs with --rate and --excludefile.
Asynchronous masscan port sweep with structured JSON output.
DNS stub resolver for large domain lists.
Recursive HTTP directory and file fuzzer.
Fetch many paths across many hosts while staying polite per host.
Cartesian join of two wordlists for fuzzing candidates.
URL path lists from a wordlist for content discovery.
Subdomain candidates from a wordlist for DNS resolution.
CVE-2025-14847 MongoDB memory disclosure scanner.
A fast and reliable port scanner that enumerates open ports for hosts.
Authenticated network assessment across SMB, LDAP, WinRM, and more.
Simple IP or CIDR sweep for open ports.
Bundled web server checks for dangerous files and outdated software.
Deprecated host-list wrapper for nikto. Prefer the nikto node.
Bypass 403/40X restrictions through smart request manipulation.
Rule-based secret scanning across text and full Git history.
MongoDB-focused NoSQL injection scanner and injector.
Publish tool output to chat and alerting providers.
Passive Shodan enrichment for IP lists: ports and known CVEs.
Raw-socket SYN scanner for internet-wide port discovery, with optional banners and scripts.
YAML template scanner for live hosts; scope runs with tags and severity.
Nuclei vulnerability scan with Markdown export for readable findings.
Subdomain recon with passive sources, optional brute force, and alive filtering.
SNMP community-string scanner for host lists.
OpenAI chat responses from a file and a prompt.
Async open-redirect fuzzer for parameterized URLs.
Python open-redirect and CRLF fuzzer for URLs and URL lists.
Passive archive miner for parameterized URLs on a domain.
OSINT paste-site search for credentials and brand terms.
Modular multi-protocol credential brute forcer with response filtering.
Password wordlist attacks against phpMyAdmin login forms.
Lightweight TCP port scanner for massdns-resolved hosts.
Prepend one string to each line in a file or folder.
Print every IP in a range or CIDR, one per line.
Portable shell expansion of IP ranges into host lists.
CSS selectors over HTML, the jq counterpart for markup.
A fast domain resolver and subdomain bruteforcing tool that filters out wildcards and poisoned entries.
Write workflow results into Trickest file storage.
Rule-driven wordlist builder for brute-force pipelines.
Find a domain's public files via search engines and extract their metadata.
Replace every query-string value across a URL list.
Confirm the RSC and Next.js RCE CVEs on a URL or host list.
Entropy-based secret scan across a Git repository's commit history.
Detects JavaScript and Node library versions with published vulnerabilities.
Regex ruleset scanner for directories and GitHub repositories; matches saved as JSON.
Port discovery that lists open ports for downstream service detection.
RustScan over a target file, with optional scripting on each open-port hit.
Normalize mixed S3 bucket references into one address format.
Checks candidate S3 buckets for open permissions and can dump readable contents.
Routes port checks through public websites so probes do not leave your host.
Sweeps a URL list with module-based checks across multiple HTTP methods.
Offline CLI search across the local Exploit-DB archive of exploits and shellcodes.
Crawler that collects second-order subdomain references for takeover review.
Regex scan of JavaScript for API keys, tokens, JWTs, and similar client-side secrets.
Scroll SecurityTrails with an embedded query and api-key.
Passive SecurityTrails subdomain list for one root domain.
Static analysis with rules that look like the code they match.
Username checks across social networks with optional CSV export.
Bulk-export Shodan banner matches as json.gz.
Search and inspect internet-facing hosts through the Shodan CLI.
Enumerate IIS 8.3 short filenames to recover hidden paths.
massdns wrapper for active subdomain brute force and resolution with wildcard filtering.
HTTP request smuggling and desync tester for a single endpoint.
Find files on web servers that should not be public.
Crawl pages for broken social links that can be hijacked.
Check whether emails and usernames are available, taken, or invalid.
Reconstruct JavaScript source trees from Sourcemap files.
Automated OSINT modules for attack surface mapping.
Detect and exploit SQL injection on authorized web targets.
SSH password brute-forcing from a host, user, and wordlist.
Python SSL/TLS scanner for protocols, certs, and named weaknesses.
SSRF and CRLF fuzzer for parameterized URL lists.
Workflow utility that writes a string to a file artifact.
DNS subdomain brute force routed through open resolvers.
Mine JavaScript and GitHub for subdomains, cloud URLs, and secrets.
A subdomain discovery tool that finds valid subdomains using passive online sources.
Concurrent subdomain takeover checks against dangling CNAMEs.
OSINT subdomain enumeration across search engines, with optional SubBrute.
Subdomain takeover checks driven by can-i-take-over-xyz response fingerprints.
Subdomain enumeration with optional probing, takeover checks, and HTML reports.
Append one string to each line in a folder of files.
Audit endpoints declared in exposed Swagger and OpenAPI specs.
Passive OSINT for emails, names, and subdomains on a domain.
Detect dangling DNS records and optionally claim them.
TLS grabber for certificates, SANs, and JARM or JA3 fingerprints.
Detect and exploit server-side template injection on live parameters.
Start a Trickest workflow run from the command line.
Download outputs from finished Trickest workflow runs.
Trivy CVE scanning for container images stored in Amazon ECR.
Trivy against container images for CVEs, secrets, and misconfigs.
Hunt leaked credentials and verify which still work.
Opinionated web audit for headers, ports, and TLS.
Opinionated twa web audits, one pass over a domain list.
Passive host discovery across multiple search-engine indexes.
Extract chosen URL parts from stdin into clean line lists.
Inverse file filter: keep files that lack a given string.
Deduplicate URLs by path and query-string shape.
Passive URL collection from public discovery sources.
Search archives of URLs exposed via shortener services.
Virtual host scanner with Host-header sweeps and catch-all detection.
Passive subdomain gathering from certificate logs, DNS aggregators, and archives.
Fingerprint the WAF in front of a site before active scanning.
Black-box crawler and fuzzer for web app injection classes.
Identify CMS, frameworks, analytics, and servers on a website.
Black-box web app crawler and parameter fuzzer.
Passive historic robots.txt path enumeration from Wayback.
Multi-archive URL harvest with optional response download.
Go Wappalyzer port for bulk technology fingerprinting.
Browser-driven screenshots for visual host triage.
Non-interactive downloader for HTTP, HTTPS, FTP, and FTPS transfers.
Fingerprint web application firewalls and test tamper bypasses.
Plugin-based fingerprinting for CMS, servers, libraries, and devices.
Confirm target-org owns the ranges in a whois-file.
Forward WHOIS for a hostname through RIPE.net.
Pivot one registrant detail into registered domains.
WitnessMe grab mode for links and XPath field extraction.
WitnessMe screenshot mode for visual web inventory.
WordPress scanner for plugins, themes, users, and known vulns.
WPScan across a file of WordPress URLs.
Hidden parameter discovery by response comparison.
Host header injection and CORS checks on URL lists.
Endpoints and parameters from crawls and saved traffic.
Parameter XSS analysis with optional blind callbacks.
Passive subdomain discovery from curated OSINT sources.
Extract one URL component per run.
Passive known-URL discovery from archive feeds.
OWASP ZAP against an API contract, not a crawlable site.
Ordered ZAP jobs from one YAML plan.
Full OWASP ZAP active scan against a target URL.
CLI DNS lookup for bulk name lists.
zgrab2 HTTP module for structured banner grabs.
Parsed zgrab2 HTTP output: title, status, content length.
Active JARM TLS fingerprinting via zgrab2.
Multi-protocol zgrab2 grabs driven by one config file.
TLS handshake and certificate grabs for host lists.
Stateless single-packet scanner for large port surveys.
Get a personalized demo
A 30-minute walkthrough. We map the platform to your stack and answer pricing and deployment questions for your environment.