Sydwicked's Stars
Hack-with-Github/Awesome-Hacking
A collection of various awesome lists for hackers, pentesters and security researchers
MobSF/Mobile-Security-Framework-MobSF
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
CISOfy/lynis
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
threat9/routersploit
Exploitation Framework for Embedded Devices
OJ/gobuster
Directory/File, DNS and VHost busting tool written in Go
1N3/Sn1per
Attack Surface Management Platform
drwetter/testssl.sh
Testing TLS/SSL encryption anywhere on any port
lanjelot/patator
Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.
nabla-c0d3/sslyze
Fast and powerful SSL/TLS scanning library.
almandin/fuxploider
File upload vulnerability scanner and exploitation tool.
evyatarmeged/Raccoon
A high performance offensive security tool for reconnaissance and vulnerability scanning
21y4d/nmapAutomator
A script that you can run in the background!
Tuhinshubhra/CMSeeK
CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 180 other CMSs
x90skysn3k/brutespray
Bruteforcing from various scanner output - Automatically attempts default creds on found services.
Nekmo/dirhunt
Find web directories without bruteforce
strongdm/comply
Compliance automation framework, focused on SOC2
m4n3dw0lf/pythem
pentest framework
0xInfection/XSRFProbe
The Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.
the-robot/sqliv
massive SQL injection vulnerability scanner
laluka/bypass-url-parser
bypass-url-parser
WhitewidowScanner/whitewidow
SQL Vulnerability Scanner
Ekultek/Zeus-Scanner
Advanced reconnaissance utility
kurobeats/fimap
fimap is a little python tool which can find, prepare, audit, exploit and even google automatically for local and remote file inclusion bugs in webapps.
openstack-archive/syntribos
Python API security testing tool from OpenStack Security Group
devsecboy/DomainRecon
Based on URL and Organization Name, collect the IP Ranges, subdomains using various tools like Amass, subfinder, etc.. And check for uphost and Run Masscan to grap CNAME entries, take the screenshot of all the found subdomains using WebScreeShot and more...
hvqzao/liffy
Local File Inclusion Exploitation Tool (mirror)
Josue87/BoomER
Framework for exploiting local vulnerabilities
Hack-Hut/CrabStick
Automatic remote/local file inclusion vulnerability analysis and exploit tool
t3rabyt3-zz/R3vSh3ll3r
Reverse Shell Using JavaScript & XSS
Sam360/SAMGoldToolkit
'Software Asset Management' PowerShell library to extract software licensing relevant information from enterprise software systems