Stars
One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password 🛡️
The all-in-one browser extension for offensive security professionals 🛠
File upload vulnerability scanner and exploitation tool.
This is the data that powers the PortSwigger URL validation bypass cheat sheet.
Advanced Time-based Blind SQL Injection fuzzer for HTTP Headers
🔍 Search anyone's digital footprint across 300+ websites
A tool for adding new lines to files, skipping duplicates
Open Source Intelligence Interface for Deep Web Scraping
Hawker is an OSINT investigative tool designed to assist law enforcement and cybersecurity professionals in gathering and analyzing open-source intelligence efficiently. (BIG UPDATE)
The CVE Binary Tool helps you determine if your system includes known vulnerabilities. You can scan binaries for over 350 common, vulnerable components (openssl, libpng, libxml2, expat and others),…
StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.
OSS-Fuzz - continuous fuzzing for open source software.
A Burp Suite extension to add OpenAI (GPT) on Burp and help you with your Bug Bounty recon to discover endpoints, params, URLs, subdomains and more!
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...
Linux enumeration tool for pentesting and CTFs with verbosity levels
ConPtyShell - Fully Interactive Reverse Shell for Windows
📱 objection - runtime mobile exploration
A static analyzer for Java, C, C++, and Objective-C
A simple zero-config tool to make locally trusted development certificates with any names you'd like.
TerminatorZ is a highly sophisticated and efficient web security tool that scans for top potential vulnerabilities with known CVEs in your web applications.
Exploit for the vulnerability CVE-2024-43044 in Jenkins
40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...