Stars
Baseline rules files to improve the security of AI-generated code (Claude, Cursor, Copilot + more)
Find, verify, and analyze leaked credentials
A tool to inspect and attack version 1 GUIDs
Takeit is an advanced tool for detecting subdomain takeovers.
The recursive internet scanner for hackers. 🧡
real time face swap and one-click video deepfake with only a single image
Guided Differential Fuzzing for HTTP Request Parsing Discrepancies
Unsecure time-based secret exploitation and Sandwich attack implementation Resources
A wordlist framework to fullfill your kinks with your wordlists. For security researchers, bug bounty and hackers.
jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice
Differential testing framework for HTTP implementations
The fastest and more comprehensive multiprotocol credentials bruteforcer / password sprayer and enumerator. 🥷
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.
🔍 gowitness - a golang, web screenshot utility using Chrome Headless
Pass in a list of URLs with query strings, get back a unique list of URLs and query string combinations
Small and highly portable detection tests based on MITRE's ATT&CK.
The most exhaustive list of reliable DNS resolvers.
REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications
Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
Grammar-based HTTP/2 fuzzer with mutation ability
The SpecterOps project management and reporting engine
Windows binaries for Hadoop versions (built from the git commit ID used for the ASF relase)
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
Python and Powershell internal penetration testing framework
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).