Lists (13)
Sort Name ascending (A-Z)
Starred repositories
PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
Ultimate Solidity, Blockchain, and Smart Contract - Beginner to Expert Full Course | Python Edition
POC for netdata ndsudo vulnerability - CVE-2024-32019
PoC for CVE-2025-24893: XWiki' Remote Code Execution exploit for versions prior to 15.10.11, 16.4.1 and 16.5.0RC1.
SAF-MCP is a comprehensive security framework for documenting and mitigating threats in the AI Agent ecosystem.
A curated list of amazingly awesome Burp Extensions
The OWASP DevSecOps Guideline explains how we can implement a secure pipeline and use best practices and introduce tools that we can use in this matter. Also, the project is trying to help us promo…
Overflowme is a walkthrough to learn the basics of binary exploitation. Detailed instructions, stack diagrams and fully commented assembly source code are provided for each of the challenges. There…
Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports Azure DevOps, GitHub and GitLab.
gpoParser is a tool designed to extract and analyze configurations applied through Group Policy Objects (GPOs) in an Active Directory environment.
HopLa Burp Suite Extender plugin - Brings AI capabilities, autocompletion support, and a set of useful payloads to Burp Suite
OSS-Fuzz - continuous fuzzing for open source software.
This npm package reads the NuGet dependencies of a .NET project, and generates a dependencies tree object.
Autoswagger by Intruder - detect API auth weaknesses
Unofficial documentation for the great tool Param Miner
Script that automates the installation of the main tools used for web application penetration testing and Bug Bounty.
😎 A curated list of awesome GitHub Profile READMEs 📝
Script that performs a scan of a specific domain, using the following tools: Subfinder, assetfinder, amass and httpx. The result is merged into one file.
A curated list of various bug bounty tools
MassDNS wrapper written in go to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard filtering and easy input-output support.
Open Source Vulnerability Management Platform
Data pipelines for cloud config and security data. Build cloud asset inventory, CSPM, FinOps, and vulnerability management solutions. Extract from AWS, Azure, GCP, and 70+ cloud and SaaS sources.
Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
Open-Source Unified Vulnerability Management, DevSecOps & ASPM
A vulnerability scanner for container images and filesystems
CLI tool and library for generating a Software Bill of Materials from container images and filesystems