Lists (1)
Sort Name ascending (A-Z)
Stars
a simple discovery script that uses popular tools like subfinder, amass, puredns, alterx, massdns and others
Extract URLs, paths, secrets, and other interesting bits from JavaScript
The FLARE team's open-source tool to identify capabilities in executable files.
A fuzzer for finding anomalies and analyzing how servers respond to different HTTP headers
403/401 Bypass Methods + Bash Automation + Your Support ;)
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
i will upload more templates here to share with the comunity.
Collaborative Incident Response platform
Python script that sends CVE-2021-44228 log4j payload requests to url list
NucleiFuzzer is a Powerful Automation tool for detecting XSS, SQLi, SSRF, Open-Redirect, etc.. Vulnerabilities in Web Applications
These are the labs for my Intro class. Yes, this is public. Yes, this is intentional.
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
All about bug bounty (bypasses, payloads, and etc)
Tips and Tutorials for Bug Bounty and also Penetration Tests.
Stunner is a tool to test and exploit STUN, TURN and TURN over TCP servers.
Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.
Payload Arsenal for Pentration Tester and Bug Bounty Hunters
QuadraInspect is an Android framework that integrates AndroPass, APKUtil, and MobFS, providing a powerful tool for analyzing the security of Android applications.
CMSmap is a python open source CMS scanner that automates the process of detecting security flaws of the most popular CMSs.
This repo contains scripts i used while bug bounty.
F5 BIG-IP Scanner scans for servers on shodan and checks to see if they are vulnerable.