Highlights
- Pro
Starred repositories
A list of SaaS, PaaS and IaaS offerings that have free tiers of interest to devops and infradev
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
The Patterns of Scalable, Reliable, and Performant Large-Scale Systems
A curated list of awesome warez and piracy links
🐶 A curated list of Web Security materials and resources.
The recursive internet scanner for hackers. 🧡
📡 PoC auto collect from GitHub.
Collection of Cyber Threat Intelligence sources from the deep and dark web
Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.
An enterprise friendly way of detecting and preventing secrets in code.
This repo contains a list of the 10,000 most common English words in order of frequency, as determined by n-gram frequency analysis of the Google's Trillion Word Corpus.
An step by step fuzzing tutorial. A GitHub Security Lab initiative
pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching
Maintained collection of OSINT related resources. (All Free & Actionable)
A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me
Repositório criado com intuito de reunir informações, fontes(websites/portais) e tricks de OSINT dentro do contexto Brasil.
Awesome list of step by step techniques to achieve Remote Code Execution on various apps!
A Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.
A Python library to utilize AWS API Gateway's large IP pool as a proxy to generate pseudo-infinite IPs for web scraping and brute forcing.
A pentest reporting tool written in Python. Free yourself from Microsoft Word.
Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
🚫 Advanced tool for security researchers to bypass 403/40X restrictions through smart techniques and adaptive request manipulation. Fast. Precise. Effective.
A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.