zesty's Stars
danielmiessler/SecLists
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.
laramies/theHarvester
E-mails, subdomains and names Harvester - OSINT
graphql-kit/graphql-voyager
🛰️ Represent any GraphQL API as an interactive graph
streaak/keyhacks
Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.
elceef/dnstwist
Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation
erebe/wstunnel
Tunnel all your traffic over Websocket or HTTP2 - Bypass firewalls/DPI - Static binary available
OWASP/Nettacker
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
wcventure/FuzzingPaper
Recent Fuzzing Paper
enjoiz/XXEinjector
Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.
rmcelreath/stat_rethinking_2024
t3l3machus/toxssin
An XSS exploitation command-line interface and payload generator.
RenwaX23/XSS-Payloads
List of XSS Vectors/Payloads
BuffaloWill/oxml_xxe
A tool for embedding XXE/XML exploits into different filetypes
vavkamil/awesome-vulnerable-apps
Awesome Vulnerable Applications
swanandx/lemmeknow
The fastest way to identify anything!
projectdiscovery/tlsx
Fast and configurable TLS grabber focused on TLS based data collection.
robiot/rustcat
Rustcat(rcat) - The modern Port listener and Reverse shell
Hari-prasaanth/Web-App-Pentest-Checklist
A OWASP Based Checklist With 500+ Test Cases
matusf/openapi-fuzzer
Black-box fuzzer that fuzzes APIs based on OpenAPI specification. Find bugs for free!
luisfontes19/xxexploiter
Tool to help exploit XXE vulnerabilities
nexB/vulnerablecode
A free and open vulnerabilities database and the packages they impact. And the tools to aggregate and correlate these vulnerabilities. Sponsored by NLnet https://nlnet.nl/project/vulnerabilitydatabase/ for https://www.aboutcode.org/ Chat at https://gitter.im/aboutcode-org/vulnerablecode Docs at https://vulnerablecode.readthedocs.org/
pwnwriter/haylxon
⚡ Blazing-fast tool to grab screenshots of your domain list right from terminal.
stealthsploit/OneRuleToRuleThemStill
A revamped and updated version of my original OneRuleToRuleThemAll hashcat rule
Escape-Technologies/graphql-wordlist
The only GraphQL wordlist you'll ever need. Operations, field names, type names... Collected on more than 60k distinct GraphQL schemas.
nikitastupin/param-miner-doc
Unofficial documentation for the great tool Param Miner
0xPugal/Awesome-Dorks
Dorks for Bug Bounty Hunting
r1cksec/corptrace
Automate Scoping, OSINT and Recon assessments.
vdespa/automation-with-postman-course
c3l3si4n/thankunext
Easily gather all routes related to a NextJs application through parsing of _buildManifest.js
victoni/elasticsearch2
Elastic(search²) is a small tool for discovering and analyzing Elasticsearch hosts for leaks and exposures from various search engines.