Ayoub5474's Stars
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
RustScan/RustScan
🤖 The Modern Port Scanner 🤖
OJ/gobuster
Directory/File, DNS and VHost busting tool written in Go
secfigo/Awesome-Fuzzing
A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Development like root cause analysis.
streaak/keyhacks
Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.
bitsadmin/wesng
Windows Exploit Suggester - Next Generation
almandin/fuxploider
File upload vulnerability scanner and exploitation tool.
find-sec-bugs/find-sec-bugs
The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
gwen001/github-search
A collection of tools to perform searches on GitHub.
maK-/parameth
This tool can be used to brute discover GET and POST parameters
hahwul/jwt-hack
🔩 jwt-hack is tool for hacking / security testing to JWT. Supported for En/decoding JWT, Generate payload for JWT attack and very fast cracking(dict/brutefoce)
manoelt/50M_CTF_Writeup
$50 Million CTF from Hackerone - Writeup
M4DM0e/DirDar
DirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it
mgeeky/tomcatWarDeployer
Apache Tomcat auto WAR deployment & pwning penetration testing tool.
root4loot/rescope
Bugbounty scope tool
j3ers3/PassList
👍 Awesome password to hack
GainSec/GoldenNuggets-1
Burp Extension for easily creating Wordlists
mgeeky/expdevBadChars
Bad Characters highlighter for exploit development purposes supporting multiple input formats while comparing.
ambionics/symfony-exploits
Exploits targeting Symfony
kazet/wpgarlic
A proof-of-concept WordPress plugin fuzzer
Dheerajmadhukar/Lilly
Tool to find the real IP behind CDNs/WAFs like cloudflare using passive recon by retrieving the favicon hash. For the same hash value, all the possible IPs, PORTs and SSL/TLS Certs are searched to validate the target in-scope.
devanshbatham/ArchiveFuzz
Hunt down the secrets from the WebArchives for Fun and Profit
ethicalhackingplayground/linkJS
The404Hacking/b374k-mini
PHP Webshell with handy features.
nyxxxie/awesome-default-passwords
An organized collection of default passwords for various devices and services.
mgeeky/LISET
Light System Examination Toolkit (LISET) - logs & activity & configuration gathering utility that comes handy in fast Windows incident response (either forensic or malware oriented).
SpiderLabs/masher
multiple password 'asher using Python’s hashlib
Mad-robot/web-cve-tests
A simple framework for sending test payloads for known web CVEs.
HanseSecure/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Mad-robot/keyhacks
Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.