-
vuln-bank Public
Forked from Commando-X/vuln-bankA deliberately vulnerable banking application designed for practicing secure code reviews and API security testing. Features common vulnerabilities found in real-world applications, making it an id…
Python MIT License UpdatedOct 5, 2025 -
google-dorks-bug-bounty Public
Forked from TakSec/google-dorks-bug-bountyA list of Google Dorks for Bug Bounty, Web Application Security, and Pentesting
MIT License UpdatedSep 29, 2025 -
DCOMUploadExec Public
Forked from deepinstinct/DCOMUploadExecDCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely
C++ UpdatedDec 13, 2024 -
gerobug Public
Forked from gerosecurity/gerobugThe First Open Source Bug Bounty Platform
HTML GNU Affero General Public License v3.0 UpdatedNov 21, 2024 -
-
APKEditor Public
Forked from REAndroid/APKEditorPowerful android apk editor - aapt/aapt2 independent
Java Apache License 2.0 UpdatedAug 2, 2024 -
android-unpinner Public
Forked from mitmproxy/android-unpinnerRemove Certificate Pinning from APKs
JavaScript UpdatedMay 23, 2024 -
-
google-dorks Public
Forked from Proviesec/google-dorksUseful Google Dorks for WebSecurity and Bug Bounty
UpdatedMar 30, 2024 -
sourcemapper Public
Forked from denandz/sourcemapperExtract JavaScript source trees from Sourcemap files
Go BSD 3-Clause "New" or "Revised" License UpdatedMar 22, 2024 -
vBank Public
Forked from vchan-in/fvbvBank is a vulnerable bank application that demonstrates how to exploit common REST and GraphQL API vulnerabilities, such as those listed in the OWASP API Security Top 10.
Vue MIT License UpdatedFeb 27, 2024 -
AD_Miner Public
Forked from AD-Security/AD_MinerAD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses
JavaScript GNU General Public License v3.0 UpdatedDec 8, 2023 -
sysreptor Public
Forked from Syslifters/sysreptorFully customisable, offensive security reporting solution designed for pentesters, red teamers and other security-related people alike.
Python Other UpdatedNov 30, 2023 -
uber-apk-signer Public
Forked from patrickfav/uber-apk-signerA cli tool that helps signing and zip aligning single or multiple Android application packages (APKs) with either debug or provided release certificates. It supports v1, v2 and v3 Android signing s…
Java Apache License 2.0 UpdatedOct 30, 2023 -
-
-
inventory Public
Forked from trickest/inventoryAsset inventory of over 800 public bug bounty programs.
Shell MIT License UpdatedOct 24, 2023 -
-
badsecrets Public
Forked from blacklanternsecurity/badsecretsA library for detecting known secrets across many web frameworks
Python GNU General Public License v3.0 UpdatedOct 12, 2023 -
-
EDRSandblast-GodFault Public
Forked from gabriellandau/EDRSandblast-GodFaultEDRSandblast-GodFault
C UpdatedAug 28, 2023 -
BypassAV Public
Forked from matro7sh/BypassAVThis map lists the essential techniques to bypass anti-virus and EDR
UpdatedAug 9, 2023 -
JS_Telegram_Chegg_Unlock Public
Forked from Sidhureddi/JS_Telegram_Chegg_UnlockChegg Unlocks - Deploy in Fly.io
JavaScript UpdatedJul 6, 2023 -
DavRelayUp Public
Forked from Dec0ne/DavRelayUpDavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced (the default settings).
C# UpdatedJun 5, 2023 -
RedTeam-Tools Public
Forked from A-poc/RedTeam-ToolsTools and Techniques for Red Team / Penetration Testing
UpdatedMay 30, 2023 -
awesome-bugbounty-tools Public
Forked from vavkamil/awesome-bugbounty-toolsA curated list of various bug bounty tools
Creative Commons Zero v1.0 Universal UpdatedMay 9, 2023 -
SWS-Recon-Tool Public
Forked from ShobhitMishra-bot/SWS-Recon-ToolSWS-Recon is a Python Tool designed to performed Reconnaissance on the given target website- Domain or SubDomain. SWS-Recon collects information such as Google Dork, DNS Information, Sub Domains, P…
Python MIT License UpdatedMar 16, 2023 -
Responder Public
Forked from lgandx/ResponderResponder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat…
Python GNU General Public License v3.0 UpdatedMar 15, 2023 -
Weblogic-CVE-2023-21839 Public
Forked from DXask88MA/Weblogic-CVE-2023-21839Java UpdatedFeb 21, 2023 -