eraymitrani's Stars
Hack-with-Github/Awesome-Hacking
A collection of various awesome lists for hackers, pentesters and security researchers
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
danielmiessler/SecLists
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
zaproxy/zaproxy
The ZAP by Checkmarx Core project
michenriksen/aquatone
A Tool for Domain Flyovers
EdOverflow/can-i-take-over-xyz
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
qazbnm456/awesome-cve-poc
✍️ A curated list of CVE PoCs.
arkadiyt/bounty-targets-data
This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports
cujanovic/SSRF-Testing
SSRF (Server Side Request Forgery) testing resources
0x00-0x00/ShellPop
Pop shells like a master.
adon90/pentest_compilation
Compilation of commands, tips and scripts that helped me throughout Vulnhub, Hackthebox, OSCP and real scenarios
codingo/VHostScan
A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.
arkadiyt/bounty-targets
This project crawls bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) hourly and dumps them into the bounty-targets-data repo
jordanpotti/CloudScraper
CloudScraper: Tool to enumerate targets in search of cloud resources. S3 Buckets, Azure Blobs, Digital Ocean Storage Space.
neex/gifoeb
exploit for ImageMagick's uninitialized memory disclosure in gif coder
bayotop/off-by-slash
Burp extension to detect alias traversal via NGINX misconfiguration at scale.
thejakeyboy/umich-eecs545-lectures
This repository contains the lecture materials for EECS 545, a graduate course in Machine Learning, at the University of Michigan, Ann Arbor.
yassineaboukir/CVE-2018-0296
Script to test for Cisco ASA path traversal vulnerability (CVE-2018-0296) and extract system information.
AlwaysBCoding/Episodes
Source Code from episodes of AlwaysBCoding screencasts
EdOverflow/bugbountywiki
The Bug Bounty Wiki
smiegles/mass3
nahamsec/SundayStreams
Data from my Sunday streams
MrTaherAmine/pentest-management
Simple webinterface combining different recon tools.
cemakd/Fruits-vs-Veggies