SubjackSubdomain Takeover tool written in Go
Stars: ✭ 1,194 (-57.48%)
magicReconMagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this saving the results obtained in an organized way in directories and with various formats.
Stars: ✭ 478 (-82.98%)
PentestingMisc. Public Reports of Penetration Testing and Security Audits.
Stars: ✭ 24 (-99.15%)
GetaltnameExtract subdomains from SSL certificates in HTTPS sites.
Stars: ✭ 320 (-88.6%)
BxssbXSS is a utility which can be used by bug hunters and organizations to identify Blind Cross-Site Scripting.
Stars: ✭ 331 (-88.21%)
ksubdomainSubdomain enumeration tool, asynchronous dns packets, use pcap to scan 1600,000 subdomains in 1 second
Stars: ✭ 320 (-88.6%)
DomainkerBugBounty Tool
Stars: ✭ 40 (-98.58%)
Go DorkThe fastest dork scanner written in Go.
Stars: ✭ 274 (-90.24%)
SonarsearchA MongoDB importer and API for Project Sonars DNS datasets
Stars: ✭ 297 (-89.42%)
Qsfuzzqsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.
Stars: ✭ 201 (-92.84%)
Bug Bounty ResponsesA collection of response templates for invalid bug bounty reports.
Stars: ✭ 46 (-98.36%)
JaelesThe Swiss Army knife for automated Web Application Testing
Stars: ✭ 1,073 (-61.79%)
SubcertSubcert is an subdomain enumeration tool, that finds all the subdomains from certificate transparency logs.
Stars: ✭ 58 (-97.93%)
CrithitTakes a single wordlist item and tests it one by one over a large collection of websites before moving onto the next. Create signatures to cross-check vulnerabilities over multiple hosts.
Stars: ✭ 182 (-93.52%)
osmedeus-workflowCommunity Workflow for the Osmedeus Engine that describes basic reconnaissance methodology for you to build your own
Stars: ✭ 26 (-99.07%)
BasecrackDecode All Bases - Base Scheme Decoder
Stars: ✭ 196 (-93.02%)
OsmedeusFully automated offensive security framework for reconnaissance and vulnerability scanning
Stars: ✭ 3,391 (+20.76%)
HettyHetty is an HTTP toolkit for security research.
Stars: ✭ 3,596 (+28.06%)
aquatoneA Tool for Domain Flyovers
Stars: ✭ 43 (-98.47%)
Assessment MindsetSecurity Mindmap that could be useful for the infosec community when doing pentest, bug bounty or red-team assessments.
Stars: ✭ 608 (-78.35%)
Legal Bug Bounty#legalbugbounty project — creating safe harbors on bug bounty programs and vulnerability disclosure programs. Authored by Amit Elazari.
Stars: ✭ 42 (-98.5%)
DirsearchWeb path scanner
Stars: ✭ 7,246 (+158.05%)
S3scannerScan for open AWS S3 buckets and dump the contents
Stars: ✭ 1,319 (-53.03%)
Gf SecretsSecret and/ credential patterns used for gf.
Stars: ✭ 96 (-96.58%)
Defaultcreds Cheat SheetOne place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password 🛡️
Stars: ✭ 1,949 (-30.59%)
AstraAstra is a tool to find URLs and secrets inside a webpage/files
Stars: ✭ 187 (-93.34%)
Sub-DrillA very (very) FAST and simple subdomain finder based on online & free services. Without any configuration requirements.
Stars: ✭ 70 (-97.51%)
gwdomainssub domain wild card filtering tool
Stars: ✭ 38 (-98.65%)
goverviewgoverview - Get an overview of the list of URLs
Stars: ✭ 93 (-96.69%)
PastebinMarkdownXSSXSS in pastebin.com and reddit.com via unsanitized markdown output
Stars: ✭ 84 (-97.01%)
T1tl3A simple python script which can check HTTP status of branch of URLs/Subdomains and grab URLs/Subdomain title
Stars: ✭ 14 (-99.5%)
targetsA collection of over 5.1 million sub-domains and assets belonging to public bug bounty programs, compiled into a repo, for performing bulk operations.
Stars: ✭ 85 (-96.97%)
MegplusAutomated reconnaissance wrapper — TomNomNom's meg on steroids. [DEPRECATED]
Stars: ✭ 268 (-90.46%)
CloudbruteAwesome cloud enumerator
Stars: ✭ 268 (-90.46%)
H2csmugglerHTTP Request Smuggling over HTTP/2 Cleartext (h2c)
Stars: ✭ 292 (-89.6%)
sub404A python tool to check subdomain takeover vulnerability
Stars: ✭ 205 (-92.7%)
Bugbounty CheatsheetA list of interesting payloads, tips and tricks for bug bounty hunters.
Stars: ✭ 3,644 (+29.77%)
OneforallOneForAll是一款功能强大的子域收集工具
Stars: ✭ 4,202 (+49.64%)
doraFind exposed API keys based on RegEx and get exploitation methods for some of keys that are found
Stars: ✭ 229 (-91.84%)
Learn365This repo is about @harshbothra_ 365 days of learning Tweet & Mindmap collection
Stars: ✭ 525 (-81.3%)
Security ToolsCollection of small security tools, mostly in Bash and Python. CTFs, Bug Bounty and other stuff.
Stars: ✭ 509 (-81.87%)
SuboverA Powerful Subdomain Takeover Tool
Stars: ✭ 607 (-78.38%)
Dictionary Of PentestingDictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。
Stars: ✭ 492 (-82.48%)
ReconftwreconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
Stars: ✭ 974 (-65.31%)
DomainedMulti Tool Subdomain Enumeration
Stars: ✭ 688 (-75.5%)
MetabigorIntelligence tool but without API key
Stars: ✭ 424 (-84.9%)
AcamarA Python3 based single-file subdomain enumerator
Stars: ✭ 89 (-96.83%)
SubtakeAutomatic finder for subdomains vulnerable to takeover. Written in Go, based on @haccer's subjack.
Stars: ✭ 104 (-96.3%)
ResourcesA Storehouse of resources related to Bug Bounty Hunting collected from different sources. Latest guides, tools, methodology, platforms tips, and tricks curated by us.
Stars: ✭ 62 (-97.79%)
Proof Of ConceptsA little collection of fun and creative proof of concepts to demonstrate the potential impact of a security vulnerability.
Stars: ✭ 148 (-94.73%)
SuperLibraryInformation Security Library
Stars: ✭ 60 (-97.86%)
urldedupePass in a list of URLs with query strings, get back a unique list of URLs and query string combinations
Stars: ✭ 208 (-92.59%)
BugbountyguideBug Bounty Guide is a launchpad for bug bounty programs and bug bounty hunters.
Stars: ✭ 338 (-87.96%)
Rfd CheckerRFD Checker - security CLI tool to test Reflected File Download issues
Stars: ✭ 56 (-98.01%)
AutosetupAuto setup is a bash script compatible with Debian based distributions to install and setup necessary programs.
Stars: ✭ 140 (-95.01%)