Stars
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
A repository with 3 tools for pwn'ing websites with .git repositories available
Git All the Payloads! A collection of web attack payloads.
Asset inventory of over 800 public bug bounty programs.
An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for vulnerabilities.
Self contained htaccess shells and attacks
Automation for javascript recon in bug bounty.
An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
ReconPi - A lightweight recon tool that performs extensive scanning with the latest tools.
Awesome Bug bounty builder Project
Reconnaissance Real IP address for Cloudflare Bypass
Multiprocessing(Parallel)Subdomain Detect Script
Crtsh Subdomain Enumeration | This bash script makes it easy to quickly save and parse the output from https://crt.sh website.
An automation tool to install the most popular tools for bug bounty or pentesting.
Wordlist for Hacking, Penetration Testing, Vulnerability Assessments and More
Project Morya is just a collection of bash scripts that runs iteratively to carry out various tools and recon process & store output in an organized way
Collaborative programming environment inside GitHub Actions – like Google Docs for hacking
KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Ports.
Basic Recon For Bug Bounty Hunter - "HuntTheBug" is Basic Scripts For Sub Domain Enumeration> Live Domain Enumeration > Sub Domain Hijack > URL + JavaScript Scan > Dir Brute Forcing > Open Port Che…
SubzzZ to find possible subdomains using passive recon. Tool also support Permutations, Mutations, Alterations.
My configs, tools and what not. For everytime that I blow up my vm....
This includes all the templates of nuclei collected from different sources
Scanner for Log4j RCE CVE-2021-44228