Stars
A comprehensive curated list of available Bug Bounty & Disclosure Programs and Write-ups.
XSS spider - 66/66 wavsep XSS detected
The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.
vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.
Metlo is an open-source API security platform.
A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.
A fast tool to scan CRLF vulnerability written in Go
A cheat sheet that contains advanced queries for SQL Injection of all types.
GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.
SSRF Proxy facilitates tunneling HTTP communications through servers vulnerable to Server-Side Request Forgery.
A multi-platform bug bounty toolkit that can be installed on Debian/Ubuntu or set up with Docker.
A Golang blocking rate limit implementation
A next-generation crawling and spidering framework.
Raw HTTP client in Go for complete request control and customization.
Fast passive subdomain enumeration tool.
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the …
WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.
A collection of Awesome Frida Scripts for MAPT
🔒 A compiled checklist of 300+ tips for protecting digital security and privacy in 2026
🔒 A curated checklist of 300+ tips for protecting digital security and privacy in 2020
LuNiZz / Resources-for-Beginner-Bug-Bounty-Hunters
Forked from nahamsec/Resources-for-Beginner-Bug-Bounty-HuntersA list of resources for those interested in getting started in bug bounties
This repository contains a curated list of resources I suggest on LinkedIn and Twitter.📝🌝
This repository will contain many mindmaps for cyber security technologies, methodologies, courses, and certifications in a tree structure to give brief details about them
Tools and Techniques for Red Team / Penetration Testing