m0pam's Stars
projectdiscovery/katana
A next-generation crawling and spidering framework.
shmilylty/OneForAll
OneForAll是一款功能强大的子域收集工具
six2dez/reconftw
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
EdOverflow/can-i-take-over-xyz
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
arkadiyt/bounty-targets-data
This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports
devanshbatham/ParamSpider
Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing
obheda12/GitDorker
A Python program to scrape secrets from GitHub through usage of a large repository of dorks.
federicodotta/Brida
The new bridge between Burp Suite and Frida!
0xmaximus/Galaxy-Bugbounty-Checklist
Tips and Tutorials for Bug Bounty and also Penetration Tests.
QAX-A-Team/BrowserGhost
这是一个抓取浏览器密码的工具,后续会添加更多功能
jacopotediosi/GAppsMod
Tweak Google apps (e.g., Phone and Messages) to unlock hidden features (e.g., available only in some countries or on certain devices). Root is required.
sw33tLie/bbscope
Scope gathering tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!
indianajson/can-i-take-over-dns
"Can I take over DNS?" — a list of DNS providers and how to claim vulnerable domains.
drak3hft7/Cheat-Sheet---Active-Directory
This cheat sheet outlines common enumeration and attack methods for Windows Active Directory using PowerShell.
Brum3ns/firefly
Black box fuzzer for web applications
pwndoc-ng/pwndoc-ng
Pentest Report Generator
sw33tLie/sns
IIS shortname scanner written in Go
seeu-inspace/easyg
Here I gather all the resources about hacking that I find interesting
hackvertor/hackvertor
ssl/shortboost
Unicode characters that will translate a single character to multiple characters in domain names or TLD's
drak3hft7/Subscan4
Script that performs a scan of a specific domain, using the following tools: Subfinder, assetfinder, amass and httpx. The result is merged into one file.
felipecaon/wpsechelper
Seecurity helper tool to detect entry points of WordPress plugins
m0pam/crtsh-fetcher
Fetches domains from https://crt.sh/
Pushpamk/waybackparam
Find all the parameter from urls generated with waybackurls