YuraveON's Stars
jobertabma/virtual-host-discovery
A script to enumerate virtual hosts on a server.
jobertabma/relative-url-extractor
A small tool that extracts relative URLs from a file.
ffuf/ffuf
Fast web fuzzer written in Go
capt-meelo/LazyRecon
An automated approach to performing recon for bug bounty hunting and penetration testing.
eslam3kl/3klCon
Automation Recon tool which works with Large & Medium scopes. It performs a lot of tasks and gets back all the results in separated files.
s0md3v/Arjun
HTTP parameter discovery suite.
devanshbatham/ParamSpider
Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing
hahwul/dalfox
🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
vincentcox/bypass-firewalls-by-DNS-history
Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that domain. Handy for bugbounty hunters.
gitleaks/gitleaks
Find secrets with Gitleaks 🔑
OWASP/CheatSheetSeries
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
techgaun/github-dorks
Find leaked secrets via github search
jhaddix/tbhm
The Bug Hunters Methodology
jaeles-project/jaeles
The Swiss Army knife for automated Web Application Testing
OWASP/wstg
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
qazbnm456/awesome-web-security
🐶 A curated list of Web Security materials and resources.
Hack-with-Github/Awesome-Hacking
A collection of various awesome lists for hackers, pentesters and security researchers
0xSobky/HackVault
A container repository for my public web hacks!
hahwul/XSS-Payload-without-Anything
XSS Payload without Anything.
bugcrowd/bugcrowd_university
Open source education content for the researcher community
kongsec/Vulnerabilities-Approach-Slides
PDF slides
TheCrysp/Hackbuntu
danielmiessler/SecLists
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
KathanP19/HowToHunt
Collection of methodology and test case for various web vulnerabilities.
FluxionNetwork/fluxion
Fluxion is a remake of linset by vk496 with enhanced functionality.
GTFOBins/GTFOBins.github.io
GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems
riramar/Web-Attack-Cheat-Sheet
Web Attack Cheat Sheet
pry0cc/axiom
The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf, masscan, nuclei, meg and many more!
codingo/VHostScan
A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.