Skip to content
View UmarNasir0002's full-sized avatar

Block or report UmarNasir0002

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

LazyHunter is an automated reconnaissance tool designed for bug hunters, leveraging Shodan's InternetDB and CVEDB APIs

Python 139 18 Updated Feb 23, 2025
Python 379 72 Updated Mar 3, 2025

🎯 Open Redirect Payload List

567 199 Updated Jul 18, 2024

Misconfig Mapper is a fast tool to help you uncover security misconfigurations on popular third-party services used by your company and/or bug bounty targets!

Go 662 51 Updated Mar 7, 2025

Content discovery wordlists generated using BigQuery

Shell 565 72 Updated Apr 26, 2020

In-depth attack surface mapping and asset discovery

Go 12,567 1,943 Updated Mar 7, 2025

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 63,717 15,086 Updated Mar 7, 2025

CeWL is a Custom Word List Generator

Ruby 2,143 278 Updated Oct 28, 2024

Self-hosted bug bounty programs that are "scammy" or unethical

118 14 Updated Jan 30, 2025

Shell 98 31 Updated Sep 21, 2024

40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...

Go 1,681 289 Updated Jul 3, 2023

🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List

6,775 1,755 Updated Jul 18, 2024

httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.

Go 8,179 876 Updated Mar 3, 2025

Content-Type Research

601 63 Updated Feb 8, 2024

XSS payloads for exploiting Markdown syntax

466 181 Updated Oct 12, 2024

SOC Interview Questions

1,112 166 Updated Sep 10, 2024

Not so awesome Web3 Security Reasearcher roadmap by tpiliposian

233 17 Updated Jan 15, 2025

Web path scanner

Python 12,625 2,352 Updated Feb 20, 2025

Fetch all the URLs that the Wayback Machine knows about for a domain

Go 3,752 492 Updated May 1, 2024

Scanning pastebin with yara rules

Python 1,082 226 Updated Jun 18, 2024

Find, verify, and analyze leaked credentials

Go 18,344 1,788 Updated Mar 7, 2025

Reconnaissance tool for GitHub organizations

Go 6,005 830 Updated Sep 20, 2022

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

5,345 1,080 Updated Aug 14, 2024

Find interesting Amazon S3 Buckets by watching certificate transparency logs.

Python 1,762 208 Updated Feb 28, 2025
Ruby 553 128 Updated Feb 1, 2024

EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.

Python 5,200 862 Updated Oct 22, 2024

A security tool for grabbing screenshots of many web hosts

Python 316 50 Updated Jul 17, 2017

Generates permutations, alterations and mutations of subdomains and then resolves them

Python 2,387 451 Updated Jan 9, 2025

Leverages publicly available datasets from Google BigQuery to generate content discovery and subdomain wordlists

Go 714 104 Updated Feb 12, 2023
Next