Stars
Takeit is an advanced tool for detecting subdomain takeovers.
The recursive internet scanner for hackers. 🧡
real time face swap and one-click video deepfake with only a single image
Guided Differential Fuzzing for HTTP Request Parsing Discrepancies
Unsecure time-based secret exploitation and Sandwich attack implementation Resources
A wordlist framework to fullfill your kinks with your wordlists. For security researchers, bug bounty and hackers.
jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice
Differential fuzzing REPL for HTTP implementations.
A multiprotocol credentials bruteforcer / password sprayer and enumerator. 🥷
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.
🔍 gowitness - a golang, web screenshot utility using Chrome Headless
Pass in a list of URLs with query strings, get back a unique list of URLs and query string combinations
Small and highly portable detection tests based on MITRE's ATT&CK.
REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications
Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
Grammar-based HTTP/2 fuzzer with mutation ability
The SpecterOps project management and reporting engine
Windows binaries for Hadoop versions (built from the git commit ID used for the ASF relase)
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
Python and Powershell internal penetration testing framework
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).
Gather and update all available and newest CVEs with their PoC.
Grammar-based HTTP/1 fuzzer with mutation ability