Scant3rScanT3r - Web Security Scanner
DiodataTools, data, and contact lists relevant to The disclose.io Project.
HawkeyeHawkeye filesystem analysis tool
Awesome BbhtA bash script that will automatically install a list of bug hunting tools that I find interesting for recon, exploitation, etc. (minus burp) For Ubuntu/Debain.
Di.we.hRepositório com conteúdo sobre web hacking em português
AxiomThe dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf, masscan, nuclei, meg and many more!
BbrAn open source tool to aid in command line driven generation of bug bounty reports based on user provided templates.
HuntrVulnerability Database | huntr.dev
PidrilaPython Interactive Deepweb-oriented Rapid Intelligent Link Analyzer
GoaltdnsA permutation generation tool written in golang
Awesome HackingA collection of various awesome lists for hackers, pentesters and security researchers
SubtakeAutomatic finder for subdomains vulnerable to takeover. Written in Go, based on @haccer's subjack.
KeyeKeye is a reconnaissance tool that was written in Python with SQLite3 integrated. After adding a single URL, or a list of URLs, it will make a request to these URLs and try to detect changes based on their response's body length.
Ecommerce Website Security ChecklistList of considerations for commerce site auditing and security teams. This is summary of action points and areas that need to be built into the Techinical Specific Document, or will be checked in the Security testing phases.
SubjackSubdomain Takeover tool written in Go
Clickjacking TesterA python script designed to check if the website if vulnerable of clickjacking and create a poc
SpellbookMicro-framework for rapid development of reusable security tools
SsrfmapSimple Server Side Request Forgery services enumeration tool.
BurpbountyBurp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules through a very intuitive graphical interface.
SubdomainizerA tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.
Sn0intSemi-automatic OSINT framework and package manager
SublertSublert is a security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains deployed by specific organizations and issued TLS/SSL certificate.
SwiftnessxA cross-platform note-taking & target-tracking app for penetration testers.
DiodbOpen-source vulnerability disclosure and bug bounty program database.
SuboverA Powerful Subdomain Takeover Tool
Git HoundReconnaissance tool for GitHub code search. Finds exposed API keys using pattern matching, commit history searching, and a unique result scoring system.
Security ToolsCollection of small security tools, mostly in Bash and Python. CTFs, Bug Bounty and other stuff.
SubfinderSubfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing.
Black Hat RustApplied offensive security with Rust - Early access - https://academy.kerkour.com/black-hat-rust?coupon=GITHUB
Offensive DockerOffensive Docker is an image with the more used offensive tools to create an environment easily and quickly to launch assessment to the targets.
InjuredandroidA vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.
VajraVajra is a highly customizable target and scope based automated web hacking framework to automate boring recon tasks and same scans for multiple target during web applications penetration testing.
Dumpall一款信息泄漏利用工具,适用于.git/.svn源代码泄漏和.DS_Store泄漏
RenginereNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with…
sub404A python tool to check subdomain takeover vulnerability
swiss-bugbounty-programsList of bug bounty and coordinated vulnerability disclosure programs of companies/organisations in Switzerland
frida setupOne-click installer for Frida and Burp certs for SSL Pinning bypass
reconmapVulnerability assessment and penetration testing automation and reporting platform for teams.
NightingaleIt's a Docker Environment for pentesting which having all the required tool for VAPT.
Bucket-FlawsBucket Flaws ( S3 Bucket Mass Scanner ): A Simple Lightweight Script to Check for Common S3 Bucket Misconfigurations
SQLi-Query-TamperingSQLi Query Tampering extends and adds custom Payload Generator/Processor in Burp Suite's Intruder. This extension gives you the flexibility of manual testing with many powerful evasion techniques.
diotermsOpen-source vulnerability disclosure policy templates.