navidof5's Stars
RevoltSecurities/Subdominator
SubDominator helps you discover subdomains associated with a target domain efficiently and with minimal impact for your Bug Bounty
CZ-NIC/knot-resolver
Knot Resolver - resolve DNS names like it's 2025
junegunn/fzf
:cherry_blossom: A command-line fuzzy finder
mgdm/htmlq
Like jq, but for HTML.
BishopFox/jsluice
Extract URLs, paths, secrets, and other interesting bits from JavaScript
Proviesec/google-dorks
Useful Google Dorks for WebSecurity and Bug Bounty
sw33tLie/sns
IIS shortname scanner written in Go
rix4uni/uforall
uforall is a fast url crawler this tool crawl all URLs number of different sources, alienvault,WayBackMachine,urlscan,commoncrawl
pikpikcu/nodesub
Nodesub is a command-line tool for finding subdomains in bug bounty programs
0xSolanaceae/proXXy
A super simple asynchronous multithreaded proxy scraper; scraping & checking ~500k HTTP, HTTPS, SOCKS4, & SOCKS5 proxies.
jhaddix/SubreconGPT
caido/caido
🚀 Caido releases, wiki and roadmap
trufflesecurity/trufflehog
Find, verify, and analyze leaked credentials
zricethezav/h1domains
HackerOne "in scope" domains
r0oth3x49/ghauri
An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws
kkrypt0nn/wordlists
📜 A collection of wordlists for many different usages
tennc/fuzzdb
Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
Medicean/SublimeXssEncode
Converts characters from one encoding to another using a transformation.
0xacb/recollapse
REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications
n0kovo/n0kovo_subdomains
An extremely effective subdomain enumeration wordlist of 3,000,000 lines, crafted by harvesting SSL certs from the entire IPv4 space.
3ndG4me/KaliLists
Repo of all the default wordlists included in Kali. Convienent if you're using something other than Kali.
xajkep/wordlists
Infosec Wordlists and more.
hakluke/hakip2host
hakip2host takes a list of IP addresses via stdin, then does a series of checks to return associated domain names.
gwen001/github-subdomains
Find subdomains on GitHub.
cyspad/Weaponize-Your-Burp
Weaponize Your Burp is a repository for automation your Bug Bounty Hunting mindset in Burp Suite
khanjanny/check-list
This checklist may help you to have a good methodology for bug bounty hunting When you have done a action, don't forget to check ;) Happy hunting !
Cgboal/DomainParser
A very high performance Domain Name parser package in Go.
saeidshirazi/Awesome-Smart-Contract-Security
A curated list of Smart Contract Security materials and resources For Researchers
owasp-amass/amass
In-depth attack surface mapping and asset discovery
resyncgg/ripgen
Rust-based high performance domain permutation generator.