Highlights
- Pro
Stars
Automation Recon tool which works with Large & Medium scopes. It performs a lot of tasks and gets back all the results in separated files.
Extract subdomains from SSL certificates in HTTPS sites.
Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application
Genshell: The atomatic copy-and-paste oneline reverse shell generator. Just add args!
golang library for accessing squashfs filesystems that utilizes squashfs-tools-ng
Curated resources help you prepare for the CNCF/Linux Foundation CKS 2021 "Kubernetes Certified Security Specialist" Certification exam. Please provide feedback or requests by raising issues, or ma…
Hunt for security weaknesses in Kubernetes clusters
Arsenal is just a quick inventory and launcher for hacking programs
Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting
Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.
Burp Extender plugin that generates a sitemap of a website using Wayback Machine
A Burp Suite Extension that try to find all sub-domain, similar-domain and related-domain of an organization automatically! 基于流量自动收集整个企业或组织的子域名、相似域名、相关域名的burp插件
Burp Suite extension to easily export sub domains
A curated list of amazingly awesome Burp Extensions
The source code of https://requestbin.net
Web browser forensics for Google Chrome/Chromium
List of ngrok/Cloudflare Tunnel alternatives and other tunneling software and services. Focus on self-hosting.
Fast passive subdomain enumeration tool.
📡 PoC auto collect from GitHub.
OpenSSF Scorecard - Security health metrics for Open Source
Zotero extension that combats link rot by archiving webpages and journal articles.