Starred repositories
RSMangler will take a wordlist and perform various manipulations on it similar to those done by John the Ripper with a few extras.
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
A cheat sheet that contains advanced queries for SQL Injection of all types.
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…
Fetch all the URLs that the Wayback Machine knows about for a domain
One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password 🛡️
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
A collection of custom security tools for quick needs.
A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference
A comprehensive curated list of available Bug Bounty & Disclosure Programs and Write-ups.
🐶 A curated list of Web Security materials and resources.
A repository with my notable code snippets for Offensive Security's PEN-300 (OSEP) course.
Automatic SQL injection and database takeover tool
A collection of various awesome lists for hackers, pentesters and security researchers. With repository stars⭐ and forks🍴
Simple animated GIF screen recorder with an easy to use interface
A list of interesting payloads, tips and tricks for bug bounty hunters.
A collection of hacking tools, resources and references to practice ethical hacking.
A curated list of blockchain security Capture the Flag (CTF) competitions
An XSS exploitation command-line interface and payload generator.
A tool for converting SysWhispers3 syscalls for use with Nim projects
All about bug bounty (bypasses, payloads, and etc)