YuraveON's Stars
sherlock-project/sherlock
Hunt down social media accounts by username across social networks
peass-ng/PEASS-ng
PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
humiaozuzu/awesome-flask
A curated list of awesome Flask resources and plugins
Gallopsled/pwntools
CTF framework and exploit development library
PowerShellMafia/PowerSploit
PowerSploit - A PowerShell Post-Exploitation Framework
infosecn1nja/Red-Teaming-Toolkit
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
sullo/nikto
Nikto web server scanner
BishopFox/sliver
Adversary Emulation Framework
google/tsunami-security-scanner
Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.
EmpireProject/Empire
Empire is a PowerShell and Python post-exploitation agent.
nomi-sec/PoC-in-GitHub
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
OWASP/Top10
Official OWASP Top 10 Document Repository
t3l3machus/Villain
Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them among connected sibling servers (Villain instances running on different machines).
epinna/tplmap
Server-Side Template Injection and Code Injection Detection and Exploitation Tool
opsdisk/pagodo
pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching
assetnote/kiterunner
Contextual Content Discovery Tool
calebstewart/pwncat
Fancy reverse and bind shell handler
jaeles-project/gospider
Gospider - Fast web spider written in Go
defparam/smuggler
Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3
mm0r1/exploits
Pwn stuff.
IvanGlinkin/Fast-Google-Dorks-Scan
The OSINT project, the main idea of which is to collect all the possible Google dorks search combinations and to find the information about the specific web-site: common admin panels, the widespread file types and path traversal. The 100% automated.
dwisiswant0/crlfuzz
A fast tool to scan CRLF vulnerability written in Go
kkrypt0nn/wordlists
📜 A collection of wordlists for many different usages
mushorg/conpot
ICS/SCADA honeypot
epsylon/xsser
Cross Site "Scripter" (aka XSSer) is an automatic -framework- to detect, exploit and report XSS vulnerabilities in web-based applications.
MindPatch/scant3r
ScanT3r - Module based Bug Bounty Automation Tool ( use Lotus instead github.com/bugBlocker/lotus )
iamthefrogy/FYI
My last 12 year's material collection on offensive & defensive security, GRC, risk management, technical security guidelines and much more.
wkei/jlpt-vocab-api
Open API for JLPT Vocabulary from N5 to N1
minamo7sen/burp-JS-Miner
This tool tries to find interesting stuff inside static files; mainly JavaScript and JSON files.
kursadalsan/fastbugbounty
Fast Bug Bounty Script