Stars
The recursive internet scanner for hackers. π§‘
A wordlist framework to fullfill your kinks with your wordlists. For security researchers, bug bounty and hackers.
A multiprotocol credentials bruteforcer / password sprayer and enumerator. π₯·
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf, masscan, nuclei, meg and many more!
Gives you one-liners that aids in penetration testing operations, privilege escalation and more
Fetch many paths for many hosts - without killing the hosts
The OWASP Secure Headers Project
A collection of custom security tools for quick needs.
secretz, minimizing the large attack surface of Travis CI
Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that domain. Handy for bugbounty hunters.
CVE-2019-5418 - File Content Disclosure on Ruby on Rails
Automatic SSRF fuzzer and exploitation tool
π Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.
A tool to capture all the git secrets by leveraging multiple open source git searching tools
Simple wrapper for meg that sieves through meg's output for you.
Incredibly fast crawler designed for OSINT.
Fetch all the URLs that the Wayback Machine knows about for a domain
OWASP Joomla Vulnerability Scanner Project https://www.secologist.com/
Perform advanced MiTM attacks on websites with ease π
StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.
"Can I take over XYZ?" β a list of services and how to claim (sub)domains with dangling DNS records.