bbhunter's Stars
BishopFox/unredacter
Never ever ever use pixelation as a redaction technique
pry0cc/axiom
The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf, masscan, nuclei, meg and many more!
HolyBugx/HolyTips
A Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.
sehno/Bug-bounty
Ressources for bug bounty hunting
Cgboal/SonarSearch
A rapid API for the Project Sonar dataset
epi052/recon-pipeline
An automated target reconnaissance pipeline.
0x0FB0/pulsar
Network footprint scanner platform. Discover domains and run your custom checks periodically.
ngalongc/openapi_security_scanner
tasooshi/pentesting-cookbook
A set of recipes useful in pentesting and red teaming scenarios
nccgroup/go-pillage-registries
Pentester-focused Docker registry tool to enumerate and pull images
PwnFunction/Next.js-Flat-Prototype-Pollution
Prototype Pollution using `flat` with Next.js
riddhi-shree/knowledge-sharing
Hands-on content for Humla/Puliya sessions at null community
mattiasgrenfeldt/bachelors-thesis-http-request-smuggling
SmoZy92/Shodomain
Shodan subdomain finder
0xsapra/fuzzparam
chopicalqui/TurboDataMiner
The objective of this Burp Suite extension is the flexible and dynamic extraction, correlation, and structured presentation of information from the Burp Suite project as well as the flexible and dynamic on-the-fly modification of outgoing or incoming HTTP requests using Python scripts. Thus, Turbo Data Miner shall aid in gaining a better and faster understanding of the data collected by Burp Suite.
gwen001/bxss
Alternative to XSS Hunter for blind XSS.
thelikes/gwdomains
sub domain wild card filtering tool
tehryanx/sourcemapper
Reconstruct javascript from a sourcemap in bash
trufflesecurity/EmailGraffiti
Vandalize old emails. Like an NFT that's easy to prove ownership of.
gwen001/csp-analyzer
Analyze Content-Security-Policy header of a given URL.
Static-Flow/BurpSuiteAutoRepeaterNaming
This extension replaces the default repeater tab name with the URL path of the repeater request.
h3xstream/waf-workshop
gwen001/graphql-introspection-analyzer
Graphql introspection query analyzer.
gwen001/gitpillage
Extract data from a .git directory.
si9int/iprobe
Take a list of IP addresses and probe for working HTTP and HTTPS servers
digininja/cracked_flask
A very simple lab for cracking Flask session cookies
gwen001/shotTheWorld
PHP tool that takes screenshots of a given ips/ports combo list and then try to guess the service.
yapaxi/Schemas
YousefAmery/PostgreSQL-RCE-Extensions
A User Defined function written in C for PostgreSQL Extensions, can be compiled as DLL for RCE on windows machines.