A cross-platform note-taking & target-tracking app for penetration testers.
-
Updated
Jan 17, 2023 - JavaScript
A bug bounty program is a deal offered by many websites, organizations and software developers by which individuals can receive recognition and compensation for reporting bugs, especially those pertaining to security exploits and vulnerabilities.
A cross-platform note-taking & target-tracking app for penetration testers.
Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With built-in command automation, output parsing, and AI‑assisted summaries, it delivers faster, more structured, and high‑quality security assessments.
Vajra is a highly customizable target and scope based automated web hacking framework to automate boring recon tasks and same scans for multiple target during web applications penetration testing.
Work in progress...
Work in progress...
SRCMS企业应急响应与缺陷管理系统
A Tool for Domain Flyovers
A deep look at some recon methodologies and web-application vulnerabilities of my interest where I will merge all my notes gathered from books, videos, articles and own experience with bug bounty hunting / web and network hacking
AspGoat is an intentionally vulnerable ASP.NET Core application for learning and practicing web application security.
One-click installer for Frida and Burp certs for SSL Pinning bypass
Fback is a tool that helps you create target-specific wordlists using a .json pattern.
ReconPro is a specialized Google dorking tool designed for cybersecurity professionals and bug bounty hunters.
COLI (Command Orchestration & Logic Interface) – A visual orchestration layer for EWE, built for bug bounty automation. Create and run CLI workflows visually, manage scopes, monitor scans in real-time, and chain tools like subfinder → httpx → nuclei in a single streamlined interface.
Phishing mobile application made in React Native for both Android and iOS devices.
High performance, distributed port scanner for mostly bugbounty. Fast by FastAPI.
A tool to notify you of the latest changes in bug bounty programs.
This search engine automates the discovery of sensitive information using customized dorks across GitHub, Google, and Shodan.
Chrome MV3 extension that auto-discovers JS endpoints and parameter keys from code and network traffic