Stars
The ultimate single-file SSH tunnel manager. Full TUI, live dashboard, TLS obfuscation, Telegram bot, kill switch, and more. Zero dependencies.
Fast and customizable subdomain wordlist generator using DSL
Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox
Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist
A list of Google Dorks for Bug Bounty, Web Application Security, and Pentesting
The most exhaustive list of reliable DNS resolvers.
Web extension boilerplate files for web application testers.
A command line Curses based json viewer and tabulator
BackupFinder discovers backup files on web servers by generating intelligent patterns.
🤖 A CLI application that automatically prepares Android APK files for HTTPS inspection
Python APIs for web automation, testing, and bypassing bot-detection with ease.
Collection of rules for Static Application Security Testing (SAST) with Semgrep
burpsuite extension to analyze javascript files using semgrep
A comprehensive management panel for Hysteria2 proxy server with advanced features and user management capabilities.
Fast & user-friendly web change tracking tool.
Golang tool which helps dropping the irrelevant entries from your ffuf result file.
Browser extension that leverages TruffleHog and Native Messaging Hosts to scan web traffic in real-time for exposed secrets
jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive data, such as API endpoints and potential security v…
Agent S: an open agentic framework that uses computers like a human
基于chrome、firefox插件的被动式信息泄漏检测工具
Tool for fetching all the available waybackmachine snapshot urls
Useful "Match and Replace" burpsuite rules
Tunnel all your traffic over Websocket or HTTP2 - Bypass firewalls/DPI - Static binary available



