{"repo":"FlinnZee/webstrike-framework","free":true,"listed":false,"github":"https://github.com/FlinnZee/webstrike-framework","clone":"git clone https://github.com/FlinnZee/webstrike-framework.git","description":"WebStrike — automated web-pentesting framework that orchestrates Kali tools (subfinder, httpx, katana, ffuf, nuclei, sqlmap, dalfox) into one phased recon→exploit→report pipeline.","language":"Python","stars":24,"topics":["automation","bug-bounty","kali-linux","offensive-security","penetration-testing","pentesting","security-tools","web-security"],"license":"MIT","category":"security-tools","readme_excerpt":"WebStrike — Automated Web Pentesting Framework Created by NiMAA. A modular orchestration engine that conducts best-in-class Kali tools through a phase-based pipeline. WebStrike does not reinvent scanners — it chains them, passes the output of one as the input to the next, dedupes, and reports. Why an orchestrator (and not \"yet another scanner\") The hard part of web pentesting isn't running a tool — it's deciding what to run next based on what you just found, and reporting it cleanly. WebStrike owns that workflow. Each tool stays the best at its job; WebStrike is the conductor. Design A phase pipeline . Modules declare which phase they belong to; phases run in order, modules inside a phase run concurrently . Output flows through a shared Context — subdomains found in recon become probe targets, live URLs become crawl/scan targets, and so on. Phase Module Tool Intrusive What it does ----------- -------------------- ------------ :---------: --------------------------------------- recon crtsh curl no Passive subdomain enum (crt.sh CT) recon subfinder subfinder no Passive subdomain enum recon dnsx-resolve dnsx no Keep only resolvable subdomains probe http-probe whatweb no Liveness + tech fingerprint crawl katana-crawl katana yes Active crawl for endpoints crawl screenshot gowitness no Screenshot live hosts (visual triage) content content-discovery ffuf yes Directory / file brute force vulnscan nuclei-scan nuclei yes Template-driven vuln scanning webtest sqli-scan sqlmap yes SQL in","default_branch":null,"files":null,"tree":[],"storefront":"/r/FlinnZee","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/FlinnZee/webstrike-framework/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}