T-Tatsumaki's Stars
mantvydasb/RedTeaming-Tactics-and-Techniques
Red Teaming Tactics and Techniques
RhinoSecurityLabs/CVEs
A collection of proof-of-concept exploit scripts written by the team at Rhino Security Labs for various CVEs.
emadshanab/Content-Discovery-Web-Dir-Bruteforce-wordlists-Collection
razzorsec/AuditorsRoadmap
sehno/Bug-bounty
Ressources for bug bounty hunting
jhaddix/tbhm
The Bug Hunters Methodology
bugcrowd/bugcrowd_university
Open source education content for the researcher community
bugcrowd/HUNT
0xKayala/NucleiFuzzer
NucleiFuzzer is a Powerful Automation tool for detecting XSS, SQLi, SSRF, Open-Redirect, etc.. Vulnerabilities in Web Applications
AbstractEngine/pentest-muse-cli
prokunal/Study-Tracker
Monitor your study sessions, log your study hours, set goals, and watch your productivity progress.
KathanP19/HowToHunt
Collection of methodology and test case for various web vulnerabilities.
casterbyte/Above
Invisible network protocol sniffer
ihebski/A-Red-Teamer-diaries
RedTeam/Pentest notes and experiments tested on several infrastructures related to professional engagements.
0xDigimon/PenetrationTesting_Notes-
My Notes about Penetration Testing
projectdiscovery/nuclei-templates
Community curated list of templates for the nuclei engine to find security vulnerabilities.
niranjan94/OpenCTF
An Open Sourced CTF hosting platform written in php
sdslabs/playCTF
An Open Source CTF hosting platform
GZTimeWalker/GZCTF
The GZ::CTF project, an open source CTF platform.
Orange-Cyberdefense/arsenal
Arsenal is just a quick inventory and launcher for hacking programs
shieldfy/API-Security-Checklist
Checklist of the most important security countermeasures when designing, testing, and releasing your API
ysanatomic/io_uring_LPE-CVE-2023-2598
LPE PoC of a vulnerability in the io_uring subsystem of the Linux Kernel.
MuhammadKhizerJaved/Insecure-Firebase-Exploit
A simple Python Exploit to Write Data to Insecure/vulnerable firebase databases! Commonly found inside Mobile Apps. If the owner of the app have set the security rules as true for both "read" & "write" an attacker can probably dump database and write his own data to firebase db.
xsudoxx/OSCP
p0dalirius/ExtractBitlockerKeys
A system administration or post-exploitation script to automatically extract the bitlocker recovery keys from a domain.
kevin-mizu/domloggerpp
A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.
nxenon/grpc-pentest-suite
gRPC-Web Pentesting Suite + Burp Suite Extension
horizon3ai/CVE-2023-34051
VMware Aria Operations for Logs CVE-2023-34051
daffainfo/AllAboutBugBounty
All about bug bounty (bypasses, payloads, and etc)
swisskyrepo/DamnWebScanner
Another web vulnerabilities scanner, this extension works on Chrome and Opera