asnblock's Stars
danielmiessler/SecLists
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
shieldfy/API-Security-Checklist
Checklist of the most important security countermeasures when designing, testing, and releasing your API
vulhub/vulhub
Pre-Built Vulnerable Environments Based on Docker-Compose
TheKingOfDuck/fuzzDicts
Web Pentesting Fuzz 字典,一个就够了。
Ignitetechnologies/Mindmap
This repository will contain many mindmaps for cyber security technologies, methodologies, courses, and certifications in a tree structure to give brief details about them
Naituw/IPAPatch
Patch iOS Apps, The Easy Way, Without Jailbreak.
Mebus/cupp
Common User Passwords Profiler (CUPP)
Threekiii/Awesome-POC
一个漏洞POC知识库 目前数量 1000+
H4ckForJob/dirmap
An advanced web directory & file scanning tool that will be more powerful than DirBuster, Dirsearch, cansina, and Yu Jian.一个高级web目录、文件扫描工具,功能将会强于DirBuster、Dirsearch、cansina、御剑。
arainho/awesome-api-security
A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.
rtcatc/Packer-Fuzzer
Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.
flipkart-incubator/Astra
Automated Security Testing For REST API's
0xsyr0/Awesome-Cybersecurity-Handbooks
A huge chunk of my personal notes since I started playing CTFs and working as a Red Teamer.
wux1an/wxapkg
微信小程序反编译工具,.wxapkg 文件扫描 + 解密 + 解包工具
onhexgroup/Conferences
Conference presentation slides
ibaiw/2023Hvv
2023 HVV情报速递~
tenable/poc
Proof of Concepts
kgspider/crawler
K 哥爬虫代码分享,JS 逆向,爬虫进阶。关注公众号:K哥爬虫
akr3ch/BugBountyBooks
A collection of PDF/books about the modern web application security and bug bounty.
carlospolop/Auto_Wordlists
akto-api-security/akto
Proactive, Open source API security → API discovery, Testing in CI/CD, Test Library with 150+ Tests, Add custom tests, Sensitive data exposure
0x727/FingerprintHub
侦查守卫(ObserverWard)的指纹库
alphaSeclab/awesome-burp-suite
Awesome Burp Suite Resources. 400+ open source Burp plugins, 400+ posts and videos.
StarCrossPortal/scalpel
scalpel是一款命令行漏洞扫描工具,支持深度参数注入,拥有一个强大的数据解析和变异算法,可以将常见的数据格式(json, xml, form等)解析为树结构,然后根据poc中的规则,对树进行变异,包括对叶子节点和树结构 的变异。变异完成之后,将树结构还原为原始的数据格式。
izj007/wechat
微信收藏的文章
cujanovic/Open-Redirect-Payloads
Open Redirect Payloads
ayadim/Nuclei-bug-hunter
i will upload more templates here to share with the comunity.
akto-api-security/tests-library
Community generated list of API security tests to find OWASP top10, HackerOne top 10 vulnerabilities
SecPriv/cookiecrumbles
Cookie Crumbles: Breaking and Fixing Web Session Integrity
leecade/Web-Series
:books: 现代 Web 开发,现代 Web 开发导论 | 基础篇 | 进阶篇 | 架构优化篇 | React 篇 | Vue 篇