Stars
- All languages
- Assembly
- AutoIt
- Batchfile
- C
- C#
- C++
- CSS
- Clojure
- CodeQL
- Crystal
- Dockerfile
- GLSL
- Go
- HTML
- Hack
- Java
- JavaScript
- Jupyter Notebook
- Kotlin
- LLVM
- MDX
- Markdown
- Nim
- OCaml
- Objective-C
- PHP
- Pascal
- Perl
- PostScript
- PowerShell
- Python
- Ruby
- Rust
- SCSS
- Scala
- Shell
- Smali
- Smarty
- Solidity
- Swift
- TSQL
- TypeScript
- VBA
- VBScript
- Visual Basic
- Visual Basic .NET
- YARA
Prevents you from committing secrets and credentials into git repositories
OSS-Fuzz - continuous fuzzing for open source software.
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
Testing TLS/SSL encryption anywhere on any port
apk.sh makes reverse engineering Android apps easier, automating some repetitive tasks like pulling, decoding, rebuilding and patching an APK.
Various tips & tricks
SSH-Snake is a self-propagating, self-replicating, file-less script that automates the post-exploitation task of SSH private key and host discovery.
A simple script just made for self use for bypassing 403
This is a script by which you can install Ubuntu in your termux application without a rooted device
Educational, CTF-styled labs for individuals interested in Memory Forensics
grep rough audit - source code auditing tool
NucleiFuzzer is a robust automation tool that efficiently detects web application vulnerabilities, including XSS, SQLi, SSRF, and Open Redirects, leveraging advanced scanning and URL enumeration te…
403/401 Bypass Methods + Bash Automation + Your Support ;)
GooFuzz is a tool to perform fuzzing with an OSINT approach, managing to enumerate directories, files, subdomains or parameters without leaving evidence on the target's server and by means of advan…
Secure Shell Bruteforcer — A faster & simpler way to bruteforce SSH server
An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects
A Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use.
A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.
Automatically install some web hacking/bug bounty tools.
Tool for especially scanning nearby devices and execute a given command on its own system while the target device comes in range.
Demonized Shell is an Advanced Tool for persistence in linux.
k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.
Arsenal is a Simple shell script (Bash) used to install tools and requirements for Bug Bounty
PolarDNS is a specialized authoritative DNS server suitable for penetration testing and vulnerability research.
Password Hunter in Active Directory