Stars
📡 PoC auto collect from GitHub.
A repository that includes all the important wordlists used while bug hunting.
Proof-of-concept codes created as part of security research done by Google Security Team.
A lightweight GPT model, trained to discover subdomains.
This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
60k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒
Intelligent fuzzing tool integrating LLM-driven wordlist selection, automated FUZZ mode detection, GPT-generated payloads, multi-threaded scanning, and advanced response filters modeled after ffuf.
Frogy 2.0 is an automated external reconnaissance and Attack Surface Management (ASM) toolkit
OSINT tools for Information gathering, Cybersecurity, Reverse searching, bugbounty, trust and safety, red team oprations and more.
A collection of several hundred online tools for OSINT
Weaponizing WaybackUrls for Recon, BugBounties , OSINT, Sensitive Endpoints and what not
A collection of PDF/books about the modern web application security and bug bounty.
A simple bash script for Web Cache Deception exploitation.
Awesome hacking is an awesome collection of hacking tools.
This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports
A curated list of Android Security materials and resources For Pentesters and Bug Hunters
A curated list of Smart Contract Security materials and resources For Researchers
cyberasset / asset-inventory
Forked from trickest/inventoryAsset inventory of over 800 public bug bounty programs.
Asset inventory of over 800 public bug bounty programs.
Scanning APK file for URIs, endpoints & secrets.
List of Google Dorks for sites that have responsible disclosure program / bug bounty program
Scripts I use during pentest engagements.
Fast passive subdomain enumeration tool.
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the …
List of Awesome Asset Discovery Resources
Automatically Launch Google Hacking Queries Against A Target Domain