Cc.pyExtracting URLs of a specific target based on the results of "commoncrawl.org"
AutoreconSimple shell script for automated domain recognition with some tools
BugbountyscannerA Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use.
IntruderpayloadsA collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.
SitedorksSearch Google/Bing/Ecosia/DuckDuckGo/Yandex/Yahoo for a search term with a default set of websites, bug bounty programs or a custom collection.
DnsprobeDNSProb is a tool built on top of retryabledns that allows you to perform multiple dns queries of your choice with a list of user supplied resolvers.
Contact.shAn OSINT tool to find contacts in order to report security vulnerabilities.
Can I Take Over Xyz"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
PdlistA passive subdomain finder
WstgThe Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
Qsfuzzqsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.
Mad MetasploitMetasploit custom modules, plugins, resource script and.. awesome metasploit collection
SlicerA tool to automate the boring process of APK recon
BasecrackDecode All Bases - Base Scheme Decoder
HowtohuntTutorials and Things to Do while Hunting Vulnerability.
Awesome BbhtA bash script that will automatically install a list of bug hunting tools that I find interesting for recon, exploitation, etc. (minus burp) For Ubuntu/Debain.
GetjsA tool to fastly get all javascript sources/files
3klconAutomation Recon tool which works with Large & Medium scopes. It performs more than 20 tasks and gets back all the results in separated files.
KnaryA simple HTTP(S) and DNS Canary bot with Slack/Discord/MS Teams & Pushover support
GarudAn automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
CrithitTakes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to cross-check vulnerabilities over multiple hosts.
XrcrossXRCross is a Reconstruction, Scanner, and a tool for penetration / BugBounty testing. This tool was built to test (XSS|SSRF|CORS|SSTI|IDOR|RCE|LFI|SQLI) vulnerabilities
Jwt Hack🔩 jwt-hack is tool for hacking / security testing to JWT. Supported for En/decoding JWT, Generate payload for JWT attack and very fast cracking(dict/brutefoce)
TuktukTool for catching and logging different types of requests.
Url TrackerChange monitoring app that checks the content of web pages in different periods.
Tools TbhmTools of "The Bug Hunters Methodology V2 by @jhaddix"
MobilehackersweaponsMobile Hacker's Weapons / A collection of cool tools used by Mobile hackers. Happy hacking , Happy bug-hunting
BbreconPython library and CLI for the Bug Bounty Recon API
AsnlookupLeverage ASN to look up IP addresses (IPv4 & IPv6) owned by a specific organization for reconnaissance purposes, then run port scanning on it.
MinesweeperA Burpsuite plugin (BApp) to aid in the detection of scripts being loaded from over 23000 malicious cryptocurrency mining domains (cryptojacking).
RescopeRescope is a tool geared towards pentesters and bugbounty researchers, that aims to make life easier when defining scopes for Burp Suite and OWASP ZAP.
Di.we.hRepositório com conteúdo sobre web hacking em português
Awesome Bugbounty WriteupsA curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference
ApkleaksScanning APK file for URIs, endpoints & secrets.
Proof Of ConceptsA little collection of fun and creative proof of concepts to demonstrate the potential impact of a security vulnerability.
BbrAn open source tool to aid in command line driven generation of bug bounty reports based on user provided templates.
AutosetupAuto setup is a bash script compatible with Debian based distributions to install and setup necessary programs.
QuiverQuiver is the tool to manage all of your tools for bug bounty hunting and penetration testing.
NosqlmapAutomated NoSQL database enumeration and web application exploitation tool.
ReconnessReconNess is a platform to allow continuous recon (CR) where you can set up a pipeline of #recon tools (Agents) and trigger it base on schedule or events.
Awesome Mobile SecurityAn effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.
AsnipASN target organization IP range attack surface mapping for reconnaissance, fast and lightweight
SwiftnessA note-taking macOS app for penetration-testers.
0l4bsCross-site scripting labs for web application security enthusiasts