Stars
Your subdomains are free for the taking - no API key, no mistaking! 🕺
Stay on the beat with SubHound - receive notifications for new subdomains on Telegram and Discord! 🐶🎵
Fleex makes it easy to create multiple VPS on cloud providers and use them to distribute workloads.
Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!
grapX will iterate through the URLs and grep the endpoints with all possible extensions.
A Powerful Sensor Tool to discover login panels, and POST Form SQLi Scanning
This tool downloads, installs, and configures a shiny new copy of Chromium.
PwnFox is a Firefox/Burp extension that provide usefull tools for your security audit.
A fast, simple, recursive content discovery tool written in Rust.
Code security scanning tool (SAST) to discover, filter and prioritize security and privacy risks.
Demystifying Exploitable Bugs in Smart Contracts
Vulnerability Scan with Nuclei
Nmap NSE scripts to check against log4shell or LogJam vulnerabilities (CVE-2021-44228)
All About Dependency Confusion Attack, (Detecting, Finding, Mitigating)
A Bind9 server for pentesters to use for Out-of-Band vulnerabilities
Check AWS S3 instances for read/write/delete access
For basic researches, top 25 vulnerability parameters that can be used in automation tools or manual recon. 🛡️⚔️🧙
A repository that includes all the important wordlists used while bug hunting.
A fast DOM based XSS vulnerability scanner with simplicity.
An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
Mobile Hacker's Weapons / A collection of cool tools used by Mobile hackers. Happy hacking , Happy bug-hunting
"Can I take over DNS?" — a list of DNS providers and how to claim vulnerable domains.