nani1337's Stars
KissPeter/APIFuzzer
Fuzz test your application using your OpenAPI or Swagger API definition without coding
jgamblin/CPEData
NVD CPE Data
Hackmanit/Web-Cache-Vulnerability-Scanner
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).
arainho/awesome-api-security
A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.
BishopFox/iam-vulnerable
Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.
TencentARC/GFPGAN
GFPGAN aims at developing Practical Algorithms for Real-world Face Restoration.
microsoft/rest-api-fuzz-testing
REST API Fuzz Testing (RAFT): Source code for self-hosted service developed for Azure, including the API, orchestration engine, and default set of security tools (including MSR's RESTler), that enables developers to embed security tooling into their CI/CD workflows
rotemreiss/uddup
Urls de-duplication tool for better recon.
GrrrDog/weird_proxies
Reverse proxies cheatsheet
ajinabraham/aws_security_tools
Scripts and tools for AWS Pentest
linkedin/qark
Tool to look for several security related Android application vulnerabilities
NickstaDB/DeserLab
Java deserialization exploitation lab.
AloneMonkey/MonkeyDev
CaptainHook Tweak、Logos Tweak and Command-line Tool、Patch iOS Apps, Without Jailbreak.
michenriksen/aquatone
A Tool for Domain Flyovers
mitre/caldera
Automated Adversary Emulation Platform
hook-s3c/CVE-2018-11776-Python-PoC
Working Python test and PoC for CVE-2018-11776, includes Docker lab
yeyintminthuhtut/Awesome-Red-Teaming
List of Awesome Red Teaming Resources
redcanaryco/atomic-red-team
Small and highly portable detection tests based on MITRE's ATT&CK.
jaredthecoder/awesome-vehicle-security
🚗 A curated list of resources for learning about vehicle security and car hacking.
EdOverflow/can-i-take-over-xyz
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
x90skysn3k/brutespray
Bruteforcing from various scanner output - Automatically attempts default creds on found services.
projectdiscovery/subfinder
Fast passive subdomain enumeration tool.
ajinabraham/nodejsscan
nodejsscan is a static security code scanner for Node.js applications.
OWASP/NodeGoat
The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.
endgameinc/RTA
Cryptogenic/Exploit-Writeups
A collection where my current and future writeups for exploits/CTF will go
DidierStevens/DidierStevensSuite
Please no pull requests for this repository. Thanks!
attekett/Surku
Surku is a general-purpose mutation-based fuzzer.
gwen001/pentest-tools
A collection of custom security tools for quick needs.
s4n7h0/awesome-incident-response
A curated list of tools for incident response