h888t's Stars
Budibase/budibase
Low code platform for building business apps and workflows in minutes. Supports PostgreSQL, MySQL, MariaDB, MSSQL, MongoDB, Rest API, Docker, K8s, and more 🚀
smicallef/spiderfoot
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
s0md3v/Photon
Incredibly fast crawler designed for OSINT.
nomi-sec/PoC-in-GitHub
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
EnableSecurity/wafw00f
WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.
khast3x/h8mail
Email OSINT & Password breach hunting tool, locally or using premium services. Supports chasing down related email
Arachni/arachni
Web Application Security Scanner Framework
DefectDojo/django-DefectDojo
DevSecOps, ASPM, Vulnerability Management. All on one platform.
swisskyrepo/SSRFmap
Automatic SSRF fuzzer and exploitation tool
sa7mon/S3Scanner
Scan for misconfigured S3 buckets across S3-compatible APIs!
1N3/BruteX
Automatically brute force all services running on a target.
swisskyrepo/GraphQLmap
GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)
michaeldyrynda/laravel-cascade-soft-deletes
Cascading deletes for Eloquent models that implement soft deletes
0xsha/CloudBrute
Awesome cloud enumerator
pwnesia/dnstake
DNSTake — A fast tool to check missing hosted DNS zones that can lead to subdomain takeover
byt3bl33d3r/WitnessMe
Web Inventory tool, takes screenshots of webpages using Pyppeteer (headless Chrome/Chromium) and provides some extra bells & whistles to make life easier.
allanlw/svg-cheatsheet
A cheatsheet for exploiting server-side SVG processors.
blark/aiodnsbrute
Python 3.5+ DNS asynchronous brute force utility
MindPointGroup/cloudfrunt
A tool for identifying misconfigured CloudFront domains
MarkoH17/Spray365
Spray365 makes spraying Microsoft accounts (Office 365 / Azure AD) easy through its customizable two-step password spraying approach. The built-in execution plan features options that attempt to bypass Azure Smart Lockout and insecure conditional access policies.
404labfr/laravel-auth-checker
Laravel Auth Checker allows you to log users authentication, devices authenticated from and lock intrusions.
bp0lr/dmut
A tool to perform permutations, mutations and alteration of subdomains in golang.
hahwul/deadfinder
🏴☠️ Find dead-links (broken links)
chandanbn/cvss
CVSS (Common Vulnerability Scoring System) Calculator CVSSv3.1
pry0cc/CredCatch
Find plaintext credentials from emails in bulk from password dumps, and generate emails on the fly.
mandatoryprogrammer/PERS
A passive scanning tool for finding expired domain vulnerabilities while you browse.
crashbrz/BET
Burp Enterprise Toolkit
rezen/zap-lambda
ZAP running in a lambda?!
pry0cc/ciscobruter
Brute-force Cisco SSL VPN
libook/cvss-3.1-calculator
Common Vulnerability Scoring System Version 3.1 Calculator