cf-checkCloudFlare Checker written in Go
quick-recon.pyDo some quick reconnaissance on a domain-based web-application
ORtesterOpen Redirect scanner - (out of date)
gitls🖇 Enumerate git repository URL from list of URL / User / Org. Friendly to pipeline
SecurityExplainedSecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create informational content in multiple formats and share with the community to enable knowledge creation and learning.
jsleaka Go code to detect leaks in JS files via regex patterns
YAPSYet Another PHP Shell - The most complete PHP reverse shell
AndroidSecNotesAn actively maintained, Self curated notes related to android application security for security professionals, bugbounty hunters, pentesters, reverse engineer, and redteamers.
PentestingMisc. Public Reports of Penetration Testing and Security Audits.
authz0🔑 Authz0 is an automated authorization test tool. Unauthorized access can be identified based on URLs and Roles & Credentials.
leaky-pathsA collection of special paths linked to major web CVEs, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.
targetsA collection of over 5.1 million sub-domains and assets belonging to public bug bounty programs, compiled into a repo, for performing bulk operations.
EagleMultithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities
aneweranewer appends lines from stdin to a file if they don't already exist in the file. This is a rust version of https://github.com/tomnomnom/anew
frida setupOne-click installer for Frida and Burp certs for SSL Pinning bypass
fresh.pyAn efficient multi-threaded DNS resolver validator
nuubiNuubi Tools (Information-ghatering|Scanner|Recon.)
T1tl3A simple python script which can check HTTP status of branch of URLs/Subdomains and grab URLs/Subdomain title
HolyTipsA Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.
osmedeus-workflowCommunity Workflow for the Osmedeus Engine that describes basic reconnaissance methodology for you to build your own
ldapconsoleThe ldapconsole script allows you to perform custom LDAP requests to a Windows domain.
ksubdomainSubdomain enumeration tool, asynchronous dns packets, use pcap to scan 1600,000 subdomains in 1 second
hack-pet🐰 Managing command snippets for hackers/bug bounty hunters. with pet.
PayloadsPayload Arsenal for Pentration Tester and Bug Bounty Hunters
hinjectHost Header Injection Checker
VulWebajuVulWebaju is a platform that automates setting up your pen-testing environment for learning purposes.
daily-commonspeak2commonspeak2 subdomains wordlist generated daily **DEPRECATED** The author(s) of commonspeak2 maintain an official repo with more lists. Please use it instead: https://github.com/assetnote/wordlists
SubWalkerSimultaneously execute various subdomain enumeration tools and aggregate results.
webapp-wordlistsThis repository contains wordlists for each versions of common web applications and content management systems (CMS). Each version contains a wordlist of all the files directories for this version.
recceDomain availbility checker
OffensiveCloudDistributionLeverage the ability of Terraform and AWS or GCP to distribute large security scans across numerous cloud instances.
vapivAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.
Reconky-Automated Bash ScriptReconky is an great Content Discovery bash script for bug bounty hunters which automate lot of task and organized in the well mannered form which help them to look forward.
requests-ip-rotatorA Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.
ldap2jsonThe ldap2json script allows you to extract the whole LDAP content of a Windows domain into a JSON file.
spellbookFramework for rapid development and reusable of security tools
BugHunterIDPara pencari bug / celah kemanan bisa bergabung.
nozakiHTTP fuzzer engine security oriented
PinaakA vulnerability fuzzing tool written in bash, it contains the most commonly used tools to perform vulnerability scan
SubcertSubcert is an subdomain enumeration tool, that finds all the subdomains from certificate transparency logs.
NightingaleIt's a Docker Environment for pentesting which having all the required tool for VAPT.
centCommunity edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place
PassivehunterSubdomain discovery using the power of 'The Rapid7 Project Sonar datasets'
DeadDNSDNS hijacking via dead records automation tool
CommandGenInterfaceSimple vueJS based command generator which I developed in order to learn vueJS a little bit more.
Virtual-HostModified Nuclei Templates Version to FUZZ Host Header