Stars
AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.
A comprehensive collection of various techniques and methods for bypassing Two-Factor Authentication (2FA) security mechanisms.
Top disclosed reports from HackerOne
Curated list of project-based tutorials
A community-powered collection of all known bug bounty platforms, vulnerability disclosure platforms, and crowdsourced security platforms currently active on the Internet.
Wordlist for content(directory) bruteforce discovering with Burp or dirsearch
A Modern Framework for Bug Bounty Hunting
This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
Nuclei Templates Collection
The only GraphQL wordlist you'll ever need. Operations, field names, type names... Collected on more than 60k distinct GraphQL schemas.
Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.
Enhanced fork with logging, OpenAPI 3.0 and Python 3 for security monitoring workshops
A collection of snippets of codes and commands to make your life easier!
nahamsec / SecLists
Forked from danielmiessler/SecListsSecLists is the security tester's companion. It is a collection of multiple types of lists used during security assessments. List types include usernames, passwords, URLs, sensitive data grep strin…