007nicky's Stars
skylot/jadx
Dex to Java decompiler
EdOverflow/can-i-take-over-xyz
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
pry0cc/axiom
The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf, masscan, nuclei, meg and many more!
reddelexc/hackerone-reports
Top disclosed reports from HackerOne
internetwache/GitTools
A repository with 3 tools for pwn'ing websites with .git repositories available
arkadiyt/bounty-targets-data
This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports
six2dez/OneListForAll
Rockyou for web fuzzing
iddoeldor/frida-snippets
Hand-crafted Frida examples
ssl/ezXSS
ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.
B3nac/Android-Reports-and-Resources
A big list of Android Hackerone disclosed reports and other resources.
exentriquesolutions/nip.io
kkrypt0nn/wordlists
📜 A collection of wordlists for many different usages
jdonsec/AllThingsSSRF
This is a collection of writeups, cheatsheets, videos, books related to SSRF in one single location
projectdiscovery/public-bugbounty-programs
Community curated list of public bug bounty and responsible disclosure programs.
sw33tLie/bbscope
Scope gathering tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!
emadshanab/Nuclei-Templates-Collection
Nuclei Templates Collection
fyoorer/ShadowClone
Unleash the power of cloud
narfindustries/http-garden
Differential fuzzing REPL for HTTP implementations.
orwagodfather/WordList
oversecured/ovaa
Oversecured Vulnerable Android App
xnl-h4ck3r/XnlReveal
A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements and enable disabled elements.
eMVee-NL/MindMap
This is a collection of some of mine mindmaps abount pentesting created with Obsidian.
SAPT01/HBSQLI
Automated Tool for Testing Header Based Blind SQL Injection
0x999-x/jsluicepp
jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice
xnl-h4ck3r/knoxnl
This is a python wrapper around the amazing KNOXSS API by Brute Logic
putsi/privatecollaborator
A script for installing private Burp Collaborator with free Let's Encrypt SSL-certificate
teknogeek/get_schemas
Print out URL schemas from an Android app
externalist/presentations
Some presentations I did in the past
inesmartins/Android-App-Link-Verification-Tester
Checks if an Android application has successfully completed the "App Link Verification" process for Android App Links.
Kashkovsky/CVE-2021-40438
Apache forward request CVE