Stars
A curated collection of fun and creative examples generated with Nano Banana & Nano Banana Pro🍌, Gemini-2.5-flash-image based model. We also release Nano-consistent-150K openly to support the commu…
Content-Security-Policy (CSP) Bypass Techniques
attacksurge / ax
Forked from pry0cc/axiomThe Distributed Scanning Framework for Everybody! Control Your Infrastructure, Scale Your Scanning-On Your Terms. Easily distribute arbitrary binaries and scripts using any of our nine supported cl…
A plugin for Burp Suite Pro that uses the GraphQL schema to begin Active Scanning the entire endpoint.
Provides public bug bounty programs in-scope data that offer rewards and monitors public bug bounty programs assets.
The only GraphQL wordlist you'll ever need. Operations, field names, type names... Collected on more than 60k distinct GraphQL schemas.
Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.
Protection against Model Serialization Attacks
Opensource assets and vulnerability scanning tool
Easily train a good VC model with voice data <= 10 mins!
リアルタイムボイスチェンジャー Realtime Voice Changer
Asset inventory of over 800 public bug bounty programs.
This is a Burp Suite extension that allows users to easily add web addresses to the Burp Suite scope.
chenxwh / bark
Forked from suno-ai/bark🔊 Text-Prompted Generative Audio Model
bulk outbound calls with automatic Whisper transcription via Telnyx
AutoRaise (and focus) a window when hovering over it with the mouse
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous …
fuzzuli is a url fuzzing tool that aims to find critical backup files by creating a dynamic wordlist based on the domain.
Run your own GPTChat Telegram bot, with a single command!
A next-generation crawling and spidering framework.
A curated list of various bug bounty tools
An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
Subdomain enumeration tool, asynchronous dns packets, use pcap to scan 1600,000 subdomains in 1 second
PortSwigger / aes-killer
Forked from Ebryx/AES-KillerBurp Plugin to decrypt AES encrypted traffic on the fly
Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal, GhostArchive & Intelligence X!
A bash script that will automatically install Bug Hunting tools used for recon
Nuclei plugin for BurpSuite