superdeen's Stars
GhostTroops/scan4all
Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...
fullhunt/log4j-scan
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
kleiton0x00/Advanced-SQL-Injection-Cheatsheet
A cheat sheet that contains advanced queries for SQL Injection of all types.
codingo/VHostScan
A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.
tadwhitaker/Security_Engineer_Interview_Questions
Every Security Engineer Interview Question From Glassdoor.com
fullhunt/spring4shell-scan
A fully automated, reliable, and accurate scanner for finding Spring4Shell and Spring Cloud RCE vulnerabilities
the-xentropy/samlists
Free, libre, effective, and data-driven wordlists for all!
Cybereason/siofra
Josue87/gotator
Gotator is a tool to generate DNS wordlists through permutations.
0xbigshaq/firepwn-tool
Firepwn is a tool made for testing the Security Rules of a firebase application.
neex/ffmpeg-avi-m3u-xbin
iustin24/chameleon
Escape-Technologies/awesome-graphql-security
A curated list of awesome GraphQL Security frameworks, libraries, software and resources
gsmith257-cyber/GraphCrawler
GraphQL automated security testing toolkit
resyncgg/ripgen
Rust-based high performance domain permutation generator.
Sh1Yo/request_smuggler
Http request smuggling vulnerability scanner
defparam/h1passets
List HackerOne private program assets
andresriancho/mongo-objectid-predict
Predict Mongo ObjectIds
tr3ss/gofetch
This could have been a bash one-liner but guess what. It's a small Go tool that lists the trending CVEs from cvetrends.com
w9w/bugbounty_changelogs
cujanovic/Virtual-host-wordlist
Virtual host wordlist
wdahlenburg/CVESearch
Query various sources for CVE proof-of-concepts
anantshri/html5_attack_and_secure
HTML5 Training material for Attack and Secure training sessions.
GoSecure/request-smuggling-workshop
k4k4r07/CertSubDumb
Basic Bash Script to scrape all subdomains from crtsh in a single run
w9w/chaos-hacks
inesmartins/Android-Activity-Tester
Enumerates all exported and non-exported activities, launches exported activities one by one using adb.
GohEeEn/insecure-flight-booking-app
A Spring-Boot based web application for booking flights (fake data) that may contains vulnerabilities. Course project for UCD COMP47660 Secure Software Engineering
arshadkazmi42/crawl4takeover
Crawler to crawl all the external links from a website
arshadkazmi42/gh-bucket-scanner
Scan S3 or Google Storage Bucket References in the user's public github repositories