Highlights
Lists (3)
Sort Name ascending (A-Z)
Stars
Feature-packed native macOS screenshot & recording tool: annotate, auto-redact PII, record GIFs, OCR + translate, scroll capture, beautify, and more. No Electron, no subscription.
An extension to find callback endpoints in the background while searching the Web
GitHub Action to alert on security patches before the CVE drops.
Clawdbot/Moltbot/OpenClaw One-click RCE PoC 🦞 (CVE-2026-25253)
A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.
Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.
Abuse trust-boundaries to bypass firewalls and network controls
jxscout superpowers JavaScript analysis for security researchers
Database Subsetting and Relational Data Browsing Tool.
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
Extract URLs, paths, secrets, and other interesting bits from JavaScript
Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable SSRF candidates.
Deserialization payload generator for a variety of .NET formatters
Demo of the URLClassLoader JAR-swapping showing the ability to replace and exploit an already loaded JAR with inner classes
A proposed standard that allows websites to define security policies.
Driller: augmenting AFL with symbolic execution!
A wordlist generator tool, that allows you to supply a set of words, giving you the possibility to craft multiple variations from the given words, creating a unique and ideal wordlist to use regard…