3rk1n's Stars
public-apis/public-apis
A collective list of free APIs
trimstray/the-book-of-secret-knowledge
A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.
flameshot-org/flameshot
Powerful yet simple to use screenshot software :desktop_computer: :camera_flash:
shieldfy/API-Security-Checklist
Checklist of the most important security countermeasures when designing, testing, and releasing your API
nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters
A list of resources for those interested in getting started in bug bounties
paralax/awesome-honeypots
an awesome list of honeypot resources
jofpin/trape
People tracker on the Internet: OSINT analysis and research tool by Jose Pino
yeahhub/Hacking-Security-Ebooks
Top 100 Hacking & Security E-Books (Free Download)
Tib3rius/AutoRecon
AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.
OlivierLaflamme/Cheatsheet-God
Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet
vulnersCom/nmap-vulners
NSE script based on Vulners.com API
dreddsa5dies/goHackTools
Hacker tools on Go (Golang)
redhuntlabs/Awesome-Asset-Discovery
List of Awesome Asset Discovery Resources
nahamsec/lazyrecon
This script is intended to automate your reconnaissance process in an organized fashion
Hackplayers/hackthebox-writeups
Writeups for HacktheBox 'boot2root' machines
parsiya/Hacking-with-Go
Golang for Security Professionals
hectorm/hblock
Improve your security and privacy by blocking ads, tracking and malware domains.
doyensec/inql
InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.
jdonsec/AllThingsSSRF
This is a collection of writeups, cheatsheets, videos, books related to SSRF in one single location
utkusen/socialhunter
crawls the website and finds broken social media links that can be hijacked
vitalysim/totalrecon
TotalRecon installs all the recon tools you need
whid-injector/whid-31337
WHID Elite is a GSM-enabled Open-Source Multi-Purpose Offensive Device that allows a threat actor to remotely inject keystrokes, bypass air-gapped systems, conduct mousejacking attacks, do acoustic surveillance, RF replay attacks and much more. In practice, is THE Wet Dream of any Security Consultant out there!
utkusen/reqstress
a benchmarking&stressing tool that can send raw HTTP requests