Stars
MCP server that connects AI assistants to HackerOne for bug bounty hunting
A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.
Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents, and skills, and orchestrating security tool usage, we confi…
📱 objection - runtime mobile exploration
Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥
Orbis is an full spectrum automated external attack surface intelligent toolkit.
The only GraphQL wordlist you'll ever need. Operations, field names, type names... Collected on more than 60k distinct GraphQL schemas.
This app runs various webview tests to explore the attack surface and exploit techniques
A lightweight GPT model, trained to discover subdomains.
davidkevork / reverse-sourcemap
Forked from paazmaya/shuji🔭 Reverse engineering JavaScript and CSS sources from sourcemaps
Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox
💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp…
If you found this, you are among the truly lucky, to be given providence to my curated and often custom wordlists. Enjoy, buddy, you've earned it.
CSS injection requires an attacker to load a standalone CSS file to leak HTML tag attributes.
CeWLeR - Custom Word List generator Redefined. CeWL alternative in Python, based on the Scrapy framework.
A command line Curses based json viewer and tabulator
Bambdas collection for Burp Suite Professional and Community.
Secrets Ninja is an GUI tool for validating & investigating API keys discovered during pentesting & bug bounty hunting.
Autoswagger by Intruder - detect API auth weaknesses
Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!
fuzzuli is a url fuzzing tool that aims to find critical backup files by creating a dynamic wordlist based on the domain.
MapperPlus facilitates the extraction of source code from a collection of targets that have publicly exposed .js.map files.
Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.
Gospider - Fast web spider written in Go
Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing
TheHulk is a dynamic analysis tool designed to detect and exploit DOM Clobbering vulnerabilities.