Skip to content
Change the repository type filter

All

    Repositories list

    • Gift

      Public
      10900Updated Dec 26, 2019Dec 26, 2019
    • A collection of various awesome lists for hackers, pentesters and security researchers
      Creative Commons Zero v1.0 Universal
      9.1k000Updated Dec 24, 2019Dec 24, 2019
    • BIG_XSS

      Public
      This repository is a collection of Awesome XSS Payloads in 1 txt file
      31200Updated Dec 23, 2019Dec 23, 2019
    • This repository was created and developed by Ammar Amer @cry__pto Only. Updates to this repository will continue to arrive until the number of links reaches 10000 links & 10000 pdf files .Learn Ethical Hacking and penetration testing .hundreds of ethical hacking & penetration testing & red team & cyber security & computer science resources.
      MIT License
      2.4k100Updated Dec 13, 2019Dec 13, 2019
    • GoogD0rker is a tool for firing off google dorks against a target domain, it is purely for OSINT against a specific target domain. READ the readme before messaging or tweeting me.
      Python
      The Unlicense
      96000Updated Nov 27, 2019Nov 27, 2019
    • ffuf

      Public
      Fast web fuzzer written in Go
      Go
      MIT License
      1.3k000Updated Nov 25, 2019Nov 25, 2019
    • Custom pentesting tools
      Python
      791000Updated Nov 25, 2019Nov 25, 2019
    • OneForAll

      Public
      OneForAll是一款功能强大的子域收集工具
      Python
      GNU General Public License v3.0
      1.3k000Updated Nov 25, 2019Nov 25, 2019
    • sub.sh

      Public
      Online Subdomain Detect Script
      Shell
      84000Updated Nov 25, 2019Nov 25, 2019
    • Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature
      996000Updated Nov 21, 2019Nov 21, 2019
    • meg

      Public
      Fetch many paths for many hosts - without killing the hosts
      Go
      MIT License
      269000Updated Nov 18, 2019Nov 18, 2019
    • keyhacks

      Public
      Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.
      1.1k000Updated Nov 15, 2019Nov 15, 2019
    • Asnlookup

      Public
      Leverage ASN to look up IP addresses (IPv4 & IPv6) owned by a specific organization for reconnaissance purposes, then run port scanning on it.
      Python
      43000Updated Nov 13, 2019Nov 13, 2019
    • A list of useful payloads and bypass for Web Application Security and Pentest/CTF
      Python
      MIT License
      15k000Updated Nov 11, 2019Nov 11, 2019
    • Generates lists of live hosts and URLs for targeting, automating the usage of MassDNS, Masscan and nmap to filter out unreachable hosts and gather service information
      Python
      66000Updated Nov 8, 2019Nov 8, 2019
    • massdns

      Public
      A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)
      C
      GNU General Public License v3.0
      472000Updated Nov 8, 2019Nov 8, 2019
    • sublert

      Public
      Sublert is a security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains deployed by specific organizations and issued TLS/SSL certificate.
      Python
      MIT License
      166000Updated Nov 8, 2019Nov 8, 2019
    • A list of interesting payloads, tips and tricks for bug bounty hunters.
      Creative Commons Attribution Share Alike 4.0 International
      1.6k000Updated Nov 6, 2019Nov 6, 2019
    • GitTools

      Public
      A repository with 3 tools for pwn'ing websites with .git repositories available
      Shell
      MIT License
      631000Updated Oct 23, 2019Oct 23, 2019
    • subjack

      Public
      Subdomain Takeover tool written in Go
      Go
      Apache License 2.0
      341000Updated Oct 22, 2019Oct 22, 2019
    • TheftFuzzer is a tool that fuzzes Cross-Origin Resource Sharing implementations for common misconfigurations.
      Python
      58000Updated Oct 17, 2019Oct 17, 2019
    • Wordlists

      Public
      Various Payload wordlists
      64000Updated Oct 7, 2019Oct 7, 2019
    • Python
      MIT License
      167000Updated Oct 3, 2019Oct 3, 2019
    • bass

      Public
      Bass grabs you those "extra resolvers" you are missing out on when performing Active DNS enumeration. Add anywhere from 100-6k resolvers to your "resolver.txt"
      Python
      GNU General Public License v3.0
      25000Updated Oct 1, 2019Oct 1, 2019
    • A collection of open source and commercial tools that aid in red team operations.
      GNU General Public License v3.0
      2.2k000Updated Sep 30, 2019Sep 30, 2019
    • 🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
      HTML
      MIT License
      1.7k000Updated Sep 23, 2019Sep 23, 2019
    • LazyRecon

      Public
      An automated approach to performing recon for bug bounty hunting and penetration testing.
      Shell
      MIT License
      102000Updated Sep 3, 2019Sep 3, 2019
    • Python
      3000Updated Aug 26, 2019Aug 26, 2019
    • A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.
      GNU General Public License v3.0
      9.8k100Updated Jul 10, 2019Jul 10, 2019
    • jenkinz

      Public
      jenkinz is a tool to retrieve every build for every job ever created and run on a given Jenkins instance.
      Go
      MIT License
      17000Updated Jul 10, 2019Jul 10, 2019