Stars
Checklists for Testing Security environment
SploitScan is a sophisticated cybersecurity utility designed to provide detailed information on vulnerabilities and associated exploits.
My Notes about Penetration Testing
Script to Automate installtion of Apps ,frida server and moving Burpsuite certificate to root folder
A curated list of amazingly awesome Burp Extensions
⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡
"Can I take over DNS?" — a list of DNS providers and how to claim vulnerable domains.
PeTeReport is an open-source application vulnerability reporting tool.
OWASP dep-scan is a next-generation security and risk audit tool based on known vulnerabilities, advisories, and license limitations for project dependencies. Both local repositories and container …
Easily and securely send things from one computer to another 🐊 📦
Bash script to Download all endpoints/CIDRS from host targets
A Burp Suite extension to extract datas from source code while browsing.
Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3
Atlassian Confluence CVE-2021-26084 one-liner mass checker
Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules thro…
Extract uncompiled, uncompressed SPA code from Webpack source maps.
Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wis…
The all-in-one browser extension for offensive security professionals 🛠
Crack Interface lockscreen, Metasploit and More Android/IOS Hacking
💀 Generate a bunch of malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh
Go scripts for checking API key / access token validity
Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥
A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.