Stars
API Security Project aims to present unique attack & defense methods in API Security field
A Huge Learning Resources with Labs For Offensive Security Players
Course content, lab setup instructions and documentation of our very popular Breaking and Pwning Apps and Servers on AWS and Azure hands on training!
Kubernetes Security - Best Practice Guide
Network security testing for Kubernetes DevSecOps workflows
Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark
Work with Windows containers and LCOW on Mac/Linux/Windows
A tool to dump a git repository from a website
Easily turn single threaded command line applications into a fast, multi-threaded application with CIDR and glob support.
Automated All-in-One OS Command Injection Exploitation Tool
🎯 Fast CORS misconfiguration vulnerabilities scanner
Automatic SSRF fuzzer and exploitation tool
Reconnaissance tool for GitHub organizations
WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.
Generates permutations, alterations and mutations of subdomains and then resolves them
A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys
In-depth attack surface mapping and asset discovery
Find domains and subdomains related to a given domain
The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, …
Fast passive subdomain enumeration tool.
Fast subdomains enumeration tool for penetration testers
Takeover script extracts CNAME record of all subdomains at once. TakeOver saves researcher time and increase the chance of finding subdomain takeover vulnerability.