Lists (32)
Sort Name ascending (A-Z)
403
Active Directory
AI-PENTEST
Android
Auto_VulnScanner
golangBugbounty_Automate
Burp Suite
C2
chatgpt
Cobalt Strike
DirScan
docker-cloud
EDR Bypass
file_upload
Flutter_Pinning
🔮 Future ideas
IDOR
IOS Pentest
JS-Bugbounty
Network-Pentest
OSEP
Red_Team
Report_Pentest
SAST
sec_checklist
SECURITY DOCUMENT
SQL
subdomain
VulnScan(Burp/ZAP/Jenkins)
windows privilege escalation
Wordlist_Fuzz
XSS
Stars
- All languages
- ASP.NET
- Ada
- Assembly
- Batchfile
- BitBake
- Boo
- C
- C#
- C++
- CSS
- Clojure
- Crystal
- Dart
- Dockerfile
- Elixir
- Go
- HCL
- HTML
- Hack
- Haskell
- Inno Setup
- Java
- JavaScript
- Jupyter Notebook
- Kotlin
- Lua
- Makefile
- Nim
- OCaml
- Objective-C
- Objective-C++
- PHP
- PLSQL
- Pascal
- Perl
- PowerShell
- Python
- Rich Text Format
- Ruby
- Rust
- SCSS
- Shell
- Svelte
- Swift
- TypeScript
- VBScript
- Vim Script
- Visual Basic .NET
- Vue
- XSLT
- YAML
- YARA
- Zig
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…
PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically.
All in one tool for Information Gathering, Vulnerability Scanning and Crawling. A must have tool for all penetration testers
Shopware 6 is an open commerce platform based on Symfony Framework and Vue and supported by a worldwide community and more than 3.100 community extensions
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
AWSGoat : A Damn Vulnerable AWS Infrastructure
A laboratory for learning secure web and mobile development in a practical manner.
AppSec Payloads Arsenal for Pentration Tester and Bug Bounty Hunters
PurpleLab is an efficient and readily deployable lab solution, providing a swift setup for cybersecurity professionals to test detection rules and undertake various security tasks, all accessible …
OpenSource Poc && Vulnerable-Target Storage Box.
Pentesting and Bug Bounty Notes, Cheetsheets and Guide for Ethical Hacker, Whitehat Pentesters and CTF Players.
Blackfire Player is a powerful Web Crawling, Web Testing, and Web Scraper application. It provides a nice DSL to crawl HTTP services, assert responses, and extract data from HTML/XML/JSON responses.
List of payloads and wordlists that are specifically crafted to identify and exploit vulnerabilities in target web applications.
Toolkit to detect and keep track on Blind XSS, XXE & SSRF
Cross-site scripting labs for web application security enthusiasts
Whitebox source code review cheatsheet (Based on AWAE syllabus)
少而精的常用字典,积累各种场景实现字典进化,只追求更简单更有效,不建议star,但建议pr。
Simple Bulk Scan Scheduler for Acunetix in PHP
The repo will contains code for web app exploiltation