superdeen's Stars
google/oss-fuzz
OSS-Fuzz - continuous fuzzing for open source software.
OWASP/Nettacker
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
knownsec/pocsuite3
pocsuite3 is an open-sourced remote vulnerability testing framework developed by the Knownsec 404 Team.
arainho/awesome-api-security
A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.
joaomatosf/jexboss
JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool
arthaud/git-dumper
A tool to dump a git repository from a website
Sh1Yo/x8
Hidden parameters discovery suite
1ndianl33t/Bug-Bounty-Roadmaps
Bug Bounty Roadmaps
utkusen/urlhunter
a recon tool that allows searching on URLs that are exposed via shortener services
s0md3v/uro
declutters url lists for crawling/pentesting
CodeIntelligenceTesting/jazzer
Coverage-guided, in-process fuzzing for the JVM
s0md3v/Silver
Mass scan IPs for vulnerable services
Tylous/ZipExec
A unique technique to execute binaries from a password protected zip
securing/DumpsterDiver
Tool to search secrets in various filetypes.
Hackmanit/Web-Cache-Vulnerability-Scanner
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).
allanlw/svg-cheatsheet
A cheatsheet for exploiting server-side SVG processors.
iamthefrogy/frogy
My subdomain enumeration script. It's unique in the way it is built upon.
s0md3v/ote
Generate Email, Register for anything, Get the OTP/Link
duc-nt/RCE-0-day-for-GhostScript-9.50
RCE 0-day for GhostScript 9.50 - Payload generator
harsh-bothra/SecurityExplained
SecurityExplained is a new series after the previous learning challenge series #Learn365. The aim of #SecurityExplained series is to create informational content in multiple formats and share with the community to enable knowledge creation and learning.
Paradoxis/Flask-Unsign
Command line tool to fetch, decode, brute-force and craft session cookies of a Flask application by guessing secret keys.
jas502n/Grafana-CVE-2021-43798
Grafana Unauthorized arbitrary file reading vulnerability
joswha/Secure-Coding-Handbook
Web Application Secure Coding Handbook resource.
akabe1/OAUTHScan
Burp Suite Extension useful to verify OAUTHv2 and OpenID security
neex/ghostinthepdf
szski/shapeshifter
GraphQL security testing tool
FlorianPicca/JWT-Key-Recovery
A tool that recovers the public key used to sign JWT tokens
ehsaanqazi/Mind-Maps
Explore a treasure trove of knowledge and insights through my repository, where every mind map is a journey into understanding and innovation
bugbountyhunters/Iris-JS
#JavascriptRecon #bugbounty
joswha/interviewpreparation
Road to OWNING SWE/SE interviews.