Lists (2)
Sort Name ascending (A-Z)
Stars
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
An example C program which contains vulnerable code for common types of vulnerabilities. It can be used to show fuzzing concepts.
Building a full featured ecommerce api with nodejs, express and mongodb, that contains full CRUD operations, pagination, JWT authentication, RBAC Authorization, shopping cart, coupons, payment gate…
An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws
Tips on how to write exploit scripts (faster!)
0xEmbo / PyCript
Forked from Anof-cyber/PyCriptBurp Suite extension for bypassing client-side encryption for pentesting and bug bounty
Privilege Escalation Enumeration Script for Windows
A wordlist of API documentation endpoint used for fuzzing web application APIs.
A CLI tool to convert your codebase into a single LLM prompt with source tree, prompt templating, and token counting.
Penetration Testing AI Assistant based on open source LLMs.
This tool generates gopher link for exploiting SSRF and gaining RCE in various servers
Common Security Interview Questions with Answers
Free IDA Pro Binary Auditing Training Material for University Lectures - from http://binary-auditing.com . Contains decrypted/unzipped files along with original zip archive and site's index.html
Repository for download all version of @hpAndro1337 (Android AppSec) application.
Ricerca che mostra come scrivere regole per SemGrep per cercare SQL Injection nei plugin di Wordpress che usano action AJAX
Slurps down every stable version of every plugin in the WordPress plugin directory.
A static code analysis for WordPress (and PHP)
A vulnerable Android application that shows simple examples of vulnerabilities in a ctf style.
Honeyscanner: A vulnerability analyzer for honeypots
A FREE pragmatic DevOps learning to kickstart your DevOps career and knowledge in the Cloud Native era following the Agile MVP style! ⭐ (2026 plans for DevOps, Cloud, Platform, SRE, SWE)
In this repo, I have included the tools that i used for my everyday penetration tests, if you have just installed kali and lost your tools, this is the right repo for you :)
automate the procedure of 403 response code bypass
Take a list of domains and probe for working HTTP and HTTPS servers
SubEvil is an advanced open source intelligence framework (OSINT) for grouping subdomains.
this tool take a list of subdomains and give you the ip for each
OSINT Tool for Finding Passwords of Compromised Email Addresses