h888t's Stars
statelyai/xstate
Actor-based state management & orchestration for complex app logic.
duo-labs/cloudmapper
CloudMapper helps you analyze your Amazon Web Services (AWS) environments.
deepfence/SecretScanner
:unlock: :unlock: Find secrets and passwords in container images and file systems :unlock: :unlock:
christophetd/CloudFlair
🔎 Find origin servers of websites behind CloudFlare by using Internet-wide scan data from Censys.
cisagov/ScubaGear
Automation to assess the state of your M365 tenant against CISA's baselines
mandatoryprogrammer/xsshunter-express
An easy-to-setup version of XSS Hunter. Sets up in five minutes and requires no maintenance!
kost/dvcs-ripper
Rip web accessible (distributed) version control systems: SVN/GIT/HG...
mrh0wl/Cloudmare
Cloudflare, Sucuri, Incapsula real IP tracker.
codingo/VHostScan
A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.
BishopFox/eyeballer
Convolutional neural network for analyzing pentest screenshots
knavesec/CredMaster
Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling
ksharinarayanan/SSRFire
An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects
emadshanab/Nuclei-Templates-Collection
Nuclei Templates Collection
mxrch/GitFive
🐙 Track down GitHub users.
MattKeeley/Spoofy
Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.
t3l3machus/eviltree
A python3 remake of the classic "tree" command with the additional feature of searching for user provided keywords/regex in files, highlighting those that contain matches.
musana/mx-takeover
mx-takeover focuses DNS MX records and detects misconfigured MX records.
sw33tLie/sns
IIS shortname scanner written in Go
josehelps/git-wild-hunt
A tool to hunt for credentials in github wild AKA git*hunt
Audiobahn/CVE-2022-20699
Cisco Anyconnect VPN unauth RCE (rwx stack)
prodigysml/Dr.-Watson
Dr. Watson is a simple Burp Suite extension that helps find assets, keys, subdomains, IP addresses, and other useful information! It's your very own discovery side kick, the Dr. Watson to your Sherlock!
j3ssie/goverview
goverview - Get an overview of the list of URLs
0xAwali/Blind-SSRF
Nuclei Templates to reproduce Cracking the lens's Research
codenco-dev/nova-grid-system
Nova grid system for Laravel Nova
Th0h0/autopoisoner
Web cache poisoning vulnerability scanner.
numanturle/CVE-2022-1388
K23605346: BIG-IP iControl REST vulnerability CVE-2022-1388
nurse/traceroute53
A tool to investigate Route53, ELB, EC2 and Security Groups
cygenta/top10million
A repository of the 10 million live most popular websites
c0dejump/CredzCheckr
Testing default web credentials
dptsec/zipslip
Tool to create custom zip files with path traversal for certain bad unzip implementations