Highlights
- Pro
Lists (1)
Sort Name ascending (A-Z)
Starred repositories
A complete bug bounty workspace for HackerOne researchers. Includes scope enforcement, automated recon/vuln pipeline (400+ tools), report templates, CVE/CWE watchlists, and a local VM practice lab.…
RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.
A local knowledge base for bug bounty hunters. Paste a writeup URL or raw text → Claude extracts a structured technique card → you search, filter, and review it later when you're hunting.
A simple HAR-based JavaScript recon automation kit for organizing JS files, endpoints, secrets, and gf-filtered attack surface during bug bounty hunting.
This is a lightweight manual recon and app-mapping checklist I use to avoid skipping obvious attack surfaces, roles, workflows, IDs, and bug classes during the first pass of a target.
Bug bounty methodology, checklists, and hunting notes.
CLAUDE.md configs and skills I use for bug bounty hunting with Claude Code
Hundreds of models & providers. One command to find what runs on your hardware.
Debian packaging skill with comprehensive policy, debhelper, and language-specific knowledge for Ruby, Python, Rust, and Go. I mostly use this for personal, private packages not OSS Debian packages…
Burp Suite extension that automatically flags non-standard HTTP headers in proxy traffic, helping you spot custom application headers that may reveal internal infrastructure, debug endpoints, or at…
Este repo documenta e gera um catálogo de técnicas de ofuscação de URL baseadas no componente userinfo da authority (o trecho antes do @),
An evolving recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh
Autonomous AI agents for bug bounty hunting, 18 parallel hunters, built-in validator, zero setup.
OWASP Web Recon & Directory Discovery Platform
Tips and Tutorials for Bug Bounty and also Penetration Tests.
Lightweight OSINT reconnaissance tool with web UI for bug bounty hunters and pentesters
Ambiente de pentest assistido por IA integrando Claude Code + Caido MCP + 792 Skills + 35 Subagentes especializados. Do reconhecimento ao relatório em minutos, com persistência de findings por clie…
Hermes cron job that monitors GitHub for new bounties matching Atlas Nexus capabilities and alerts via Telegram.
Xfce Customization Guide (moved from my old repo) https://github.com/diws1/xfce-rice
Transparent anonymization proxy for AI-assisted pentesting. Strips IPs, credentials, hostnames and PII before they reach any LLM (Claude, OpenAI, OpenRouter). Local Ollama + regex detection. Per-en…
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works w…
SSkills (Slop Skills) is a public collection of specialist skills for security agents and human reviewers. Each skill packages structured domain knowledge, sources, examples, safety gates, and vali…