muchmuchmuch's Stars
s0md3v/XSStrike
Most advanced XSS scanner.
RenwaX23/XSSTRON
Electron JS Browser To Find XSS Vulnerabilities Automatically
0xKayala/ParamSpider
Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing
dwisiswant0/awesome-oneliner-bugbounty
A collection of awesome one-liner scripts especially for bug bounty tips.
bugbountyforum/XSS-Radar
tomnomnom/qsreplace
Accept URLs on stdin, replace all query string values with a user-supplied value
r0075h3ll/Oralyzer
Open Redirection Analyzer
nytr0gen/deduplicate
Remove duplicate urls from input
1ndianl33t/Gf-Patterns
GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep
tomnomnom/waybackurls
Fetch all the URLs that the Wayback Machine knows about for a domain
sa7mon/S3Scanner
Scan for misconfigured S3 buckets across S3-compatible APIs!
projectdiscovery/nuclei-templates
Community curated list of templates for the nuclei engine to find security vulnerabilities.
RustScan/RustScan
🤖 The Modern Port Scanner 🤖
vysecurity/DomLink
A tool to link a domain with registered organisation names and emails, to other domains.
lc/gau
Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.
TakSec/chatgpt-prompts-bug-bounty
ChatGPT Prompts for Bug Bounty & Pentesting
sushiwushi/bug-bounty-dorks
List of Google Dorks for sites that have responsible disclosure program / bug bounty program
splunk/attack_range
A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk
epinna/tplmap
Server-Side Template Injection and Code Injection Detection and Exploitation Tool
jaeles-project/gospider
Gospider - Fast web spider written in Go
SigmaHQ/sigma
Main Sigma Rule Repository
projectdiscovery/alterx
Fast and customizable subdomain wordlist generator using DSL
projectdiscovery/naabu
A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentests
projectdiscovery/nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
projectdiscovery/dnsx
dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.
projectdiscovery/katana
A next-generation crawling and spidering framework.
nmap/nmap
Nmap - the Network Mapper. Github mirror of official SVN repository.
sqlmapproject/sqlmap
Automatic SQL injection and database takeover tool
danielmiessler/SecLists
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
Sh1Yo/x8
Hidden parameters discovery suite