Skip to content
View muhammadfaizan92's full-sized avatar

Block or report muhammadfaizan92

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

🕵️‍♂️ All-in-one OSINT tool for analysing any website

TypeScript 26,816 2,152 Updated Aug 3, 2025

Easy to use open source fast database for search | Good alternative to Elasticsearch now | Drop-in replacement for E in the ELK stack

C++ 11,392 619 Updated Nov 6, 2025

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Java 8,575 1,844 Updated Mar 31, 2024

Collection of methodology and test case for various web vulnerabilities.

6,783 1,862 Updated Jun 25, 2025

Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...

Go 5,897 707 Updated Jul 12, 2024

A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference

Python 5,394 1,103 Updated Aug 6, 2023

Top disclosed reports from HackerOne

Python 4,972 900 Updated Oct 12, 2025

Email OSINT & Password breach hunting tool, locally or using premium services. Supports chasing down related email

Python 4,711 561 Updated Aug 15, 2023

Server-Side Template Injection and Code Injection Detection and Exploitation Tool

Python 4,063 688 Updated Apr 21, 2024

A curated list of amazingly awesome Burp Extensions

3,305 630 Updated Feb 15, 2025

This repository contain a lot of web and api vulnerability checklist , a lot of vulnerability ideas and tips from twitter

3,131 715 Updated Feb 10, 2024

A collection of awesome one-liner scripts especially for bug bounty tips.

2,955 609 Updated Jul 29, 2024

Mind-Maps of Several Things

2,602 548 Updated Jun 29, 2023

List of Github repositories and articles with list of dorks for different search engines

2,441 362 Updated Apr 11, 2025

Reverse proxies cheatsheet

Python 1,854 217 Updated Nov 4, 2023

Collection of some common wordlists such as RDP password, user name list, ssh password wordlist for brute force. IP Cameras Default Passwords.

1,681 1,095 Updated Aug 14, 2022

A comprehensive guide for web application penetration testing and bug bounty hunting, covering methodologies, tools, and resources for identifying and exploiting vulnerabilities.

1,653 267 Updated Sep 11, 2025

403/401 Bypass Methods + Bash Automation + Your Support ;)

Shell 1,541 288 Updated Jun 6, 2022

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Python 1,342 133 Updated Jul 14, 2025

An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for vulnerabilities.

Shell 1,262 209 Updated Jul 18, 2024

Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

Go 1,210 167 Updated Oct 17, 2025

An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability

922 119 Updated Dec 31, 2021

1337 Wordlists for Bug Bounty Hunting

904 176 Updated Sep 6, 2025

The most exhaustive list of reliable DNS resolvers.

889 98 Updated Nov 6, 2025

These are my checklists which I use during my hunting.

HTML 781 98 Updated Nov 30, 2023

crawls the website and finds broken social media links that can be hijacked

Go 751 75 Updated Jan 23, 2025

A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.

JavaScript 715 73 Updated Oct 28, 2025

Bug Bounty Tricks and useful payloads and bypasses for Web Application Security.

693 129 Updated Nov 1, 2025

Scrape domain names from SSL certificates of arbitrary hosts

Go 686 91 Updated Mar 31, 2024
Next