S0L1tud3's Stars
Josue87/gotator
Gotator is a tool to generate DNS wordlists through permutations.
xdevplatform/Twitter-API-v2-sample-code
Sample code for the Twitter API v2 endpoints
projectdiscovery/pdtm
ProjectDiscovery's Open Source Tool Manager
andresriancho/enumerate-iam
Enumerate the permissions associated with AWS credential set
cclabsInc/BlockChainExploitation
Scripts used in Blockchain Exploitation Blog
istvanbohm/nahamcon2023
xdebug/xdebug
Xdebug — Step Debugger and Debugging Aid for PHP
RandomRobbieBF/CVE-2023-32243
CVE-2023-32243 - Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation
dhmosfunk/CVE-2023-25690-POC
CVE 2023 25690 Proof of concept - mod_proxy vulnerable configuration on Apache HTTP Server versions 2.4.0 - 2.4.55 leads to HTTP Request Smuggling vulnerability.
RedSiege/EyeWitness
EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.
takshal/freq
This is go CLI tool for send fast Multiple get HTTP request.
sushiwushi/bug-bounty-dorks
List of Google Dorks for sites that have responsible disclosure program / bug bounty program
s0md3v/Photon
Incredibly fast crawler designed for OSINT.
0xPugal/Awesome-Dorks
Dorks for Bug Bounty Hunting
arainho/awesome-api-security
A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.
Karanxa/Bug-Bounty-Wordlists
A repository that includes all the important wordlists used while bug hunting.
dwisiswant0/go-dork
The fastest dork scanner written in Go.
musana/fuzzuli
fuzzuli is a url fuzzing tool that aims to find critical backup files by creating a dynamic wordlist based on the domain.
hisxo/gitGraber
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...
projectdiscovery/alterx
Fast and customizable subdomain wordlist generator using DSL
ayoubfathi/leaky-paths
A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to scan passively for high-quality endpoints and quick-wins.
projectdiscovery/nuclei-burp-plugin
Nuclei plugin for BurpSuite
s0md3v/uro
declutters url lists for crawling/pentesting
devploit/nomore403
Tool to bypass 403/40X response codes.
Dheerajmadhukar/4-ZERO-3
403/401 Bypass Methods + Bash Automation + Your Support ;)
denandz/sourcemapper
Extract JavaScript source trees from Sourcemap files
jonluca/Anubis
Subdomain enumeration and information gathering tool
maK-/parameth
This tool can be used to brute discover GET and POST parameters
the-xentropy/samlists
Free, libre, effective, and data-driven wordlists for all!
Sh1Yo/x8
Hidden parameters discovery suite