* [Reconner v4.0.0](https://github.com/rootdr-backup/Reconner) – Self-hosted attack-surface intelligence and verification-first DAST with integrated web and network recon, continuous monitoring, and evidence capture for authorized bug bounty targets. * [Blitz Strike v1.0.0](https://github.com/shinthink/blitzstrike) – A structured penetration-testing methodology that maps reconnaissance, source-to-sink analysis, and live validation into a universal MCP server with deterministic guardrails and scoped results. * [Xalgorix v4.6.118](https://github.com/xalgorix/xalgorix) – Autonomous AI pentesting platform that runs an end-to-end methodology and uses independent re-exploitation to verify and prove vulnerabilities. * [crt.sh v3.0.4](https://github.com/az7rb/crt.sh) – Fast, parallel subdomain enumeration tool that queries seven independent Certificate Transparency log sources simultaneously using a single Go binary. * [Antares v0.6.0](https://github.com/enowdev/antares) – Self-hosted AI pentest agent and assistant providing an authorized security testing workspace with files, shell, real browser control, memory, and retrieval-augmented reports. * [Payloader v2.0.1](https://github.com/3516634930/Payloader) – Cross-platform payload quick-reference app for penetration testing, with React and Electron UI supporting encoding, WAF variants, and JWT and hashing formats. * [jshunter v0.8](https://github.com/cc1a2b/JShunter) – Command-line tool for analyzing JavaScript files and extracting API endpoints and sensitive data.