Aalapsec's Stars
hakluke/weaponised-XSS-payloads
XSS payloads designed to turn alert(1) into P1
chrislockard/api_wordlist
A wordlist of API names for web application assessments
AtharavRH/Hack_Pack_V1.0
danielmiessler/RobotsDisallowed
A curated list of the most common and most interesting robots.txt disallowed directories.
jonluca/Anubis
Subdomain enumeration and information gathering tool
Voorivex/pentest-guide
Penetration tests guide based on OWASP including test cases, resources and examples.
Liodeus/liodeus.github.io
x90skysn3k/brutespray
Bruteforcing from various scanner output - Automatically attempts default creds on found services.
GovTech-CSG/Autowasp
BurpSuite Extension: A one-stop pen testing checklist and logger tool
capture0x/XSS-LOADER
Xss Payload Generator ~ Xss Scanner ~ Xss Dork Finder
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
chvancooten/BugBountyScanner
A Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use.
elkokc/reflector
Burp plugin able to find reflected XSS on page in real-time while browsing on site
PortSwigger/backslash-powered-scanner
Finds unknown classes of injection vulnerabilities
dark-warlord14/JSScanner
You can read the writeup on this script here
Findomain/Findomain
The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, multiple API Keys for sources and much more.
lanjelot/patator
Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.
random-robbie/rb-recon
random-robbie/bruteforce-lists
Some files for bruteforcing certain things.
d3vilbug/HackBar
HackBar plugin for Burpsuite
reconness/reconness
ReconNess is a platform to allow continuous recon (CR) where you can set up a pipeline of #recon tools (Agents) and trigger it base on schedule or events.
Zarcolio/sitedorks
Search Google/Bing/Ecosia/DuckDuckGo/Yandex/Yahoo for a search term (dork) with a default set of websites, bug bounty programs or custom collection.
m8sec/subscraper
Subdomain and target enumeration tool built for offensive security testing
ghsec/webHunt
Web App bug hunting
m0nad/HellRaiser
Vulnerability scanner using Nmap for scanning and correlating found CPEs with CVEs.
skavngr/rapidscan
:new: The Multi-Tool Web Vulnerability Scanner.
venom26/recon
information gathering
Quitten/Autorize
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
A3h1nt/Subcert
Subcert is a subdomain enumeration tool, that finds all the subdomains from certificate transparency logs.
madhavtripathi05/encrypted_chat_app
Simple AES encrypted chat app which works on Android, iOS, Web, and macOS with WebSocket server.