sardella-dav's Stars
IlanKalendarov/PyHook
PyHook is an offensive API hooking tool written in python designed to catch various credentials within the API call.
GhostPack/Certify
Active Directory certificate abuse.
fijimunkii/bash-dev-tcp
collection of scripts using /dev/tcp
NotSoSecure/android_application_analyzer
The tool is used to analyze the content of the android application in local storage.
scspcommunity/Cyber-Sec-Resources
An organized list of resources including tools, blog-posts and how-to tutorials compiled and created by SCSP community members.
EdOverflow/can-i-take-over-xyz
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
danielmiessler/SecLists
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
blechschmidt/massdns
A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)
lc/gau
Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.
R0X4R/Garud
An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
GerbenJavado/LinkFinder
A python script that finds endpoints in JavaScript files
KathanP19/HowToHunt
Collection of methodology and test case for various web vulnerabilities.
chbrown/unmap
Unpack a JavaScript Source Map back into filesystem structure
ffuf/ffuf
Fast web fuzzer written in Go
maurosoria/dirsearch
Web path scanner
s0md3v/sqlmate
A friend of SQLmap which will do what you always expected from SQLmap.
find-sec-bugs/find-sec-bugs
The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
projectdiscovery/nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
0xSobky/HackVault
A container repository for my public web hacks!
vitalysim/Awesome-Hacking-Resources
A collection of hacking / penetration testing resources to make you better!
google/firing-range
ZephrFish/Wordlists
Various Payload wordlists
MobSF/Mobile-Security-Framework-MobSF
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
epinna/tplmap
Server-Side Template Injection and Code Injection Detection and Exploitation Tool
orangetw/Tiny-URL-Fuzzer
A tiny and cute URL fuzzer
swisskyrepo/SSRFmap
Automatic SSRF fuzzer and exploitation tool
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
0xInfection/XSRFProbe
The Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.