Starred repositories
Bug Bounty Tricks and useful payloads and bypasses for Web Application Security.
Scripts i create to help me with my daily dasks
A list of resources for those interested in getting started in bug bounties
GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep
Curating the best DevSecOps resources and tooling.
🛡️ Open-source and next-generation Web Application Firewall (WAF)
ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.
Detect and validate 500+ types of hardcoded secrets with advanced checks. Use it as a pre-commit hook, GitHub Action, or CLI for proactive secret detection and security.
Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...
An authoritative list of awesome devsecops tools with the help from community experiments and contributions.
i-sylar / DevSecOps
Forked from hahwul/DevSecOps🔱 Collection and Roadmap for everyone who wants DevSecOps. Hope your DevOps are more safe 😎
vAPI is Vulnerable Adversely Programmed Interface which is Self-Hostable API that mimics OWASP API Top 10 scenarios through Exercises.
A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.
A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.
🐶 A curated list of Web Security materials and resources.
🍓📡🍍Monitor illegal wireless network activities. (Fake Access Points), (WiFi Threats: KARMA Attacks, WiFi Pineapple, Similar SSID, OPN Network Density etc.)
An easy to grep dump of the NVD database showing only; CVE-ID, CVSS Risk Score, and Summary.
SSL Fingerprint Tool written in Go for the CLI and package use.
this tool take a list of subdomains and give you the ip for each
Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wis…
All about bug bounty (bypasses, payloads, and etc)
Content discovery wordlists generated using BigQuery
ScanT3r - Module based Bug Bounty Automation Tool ( use Lotus instead github.com/bugBlocker/lotus )