This is your work, valued
pugdns. An experimental high-performance DNS query bruteforce tool built with AF_XDP for extremely fast and accurate bulk DNS lookups.
254webtrufflehog. Browser extension that leverages TruffleHog and Native Messaging Hosts to scan web traffic in real-time for exposed secrets
127quickcert. A better way of querying certificate transparency logs
89thankunext. Easily gather all routes related to a NextJs application through parsing of _buildManifest.js
68godeclutter. Declutters URLs in a fast and flexible way, for improving input for web hacking automations such as crawlers and vulnerability scans.
60crtdumper. crtdumper is a Go application designed to interact directly with Certificate Transparency (CT) logs servers and extract domain names from certificates. Perfect for security researchers and developers interested in massively extracting domain names from CT logs.
41subdomain_data. Results from analyzing data gathered from 1.6 billion subdomains
33styx. Styx is an cross-platform GUI interface for HackTheBox made in GoLang
31pugrecon. pugrecon is a bash script for automatic recon of common vulnerabilities, misconfigurations and files on domains.
26pwnkit. PoC for the CVE-2021-4034 vulnerability, affecting polkit < 0.120.
24r-u-flooded. 🦀 UDP-based DoS (Denial of Service) stress testing and Denial of Service tool made in Rust.
21subsift. experimental wildcard subdomain filtering prototype
14windows_sleep_techniques. A collections of methods to sleep on Windows using common and less-so-common techniques
14robson. Robson is a simple LKM rootkit that uses the Linux kernel's kprobes tracing feature as a hooking mechanism.
13revwhois. CLI tool for discovering related base domains using WhoisXMLAPI's reverse Whois endpoints
12cdn_nameservers. Non-exhaustive list of all nameservers belonging to commonly used CDNs
10gentleman. quick script for mixing wordlists in a way that maintains order. ([1,2],[3,4],[5,6] -> [1,3,5,2,4,6])
10malicious_nuclei_templates. Collection of nuclei templates that can be used for malicious purposes
9twister. A very fast IP rotating HTTP proxy daemon that will rotate proxies based on target website instead of having a single queue.
8Just-Arrived-TweetDeck. A Chrome extension to kick mindless scrolling habit. Fork made for it to work on TweetDeck.
5unihttpx. a wrapper that makes projectdiscovery's httpx tool reach more ports faster, by combining it with unimap.
5TREVORproxy-tor. Fork of TREVORProxy with experimental Tor Stream Isolation support
4PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
3crawlergo. A powerful browser crawler for web vulnerability scanners
3cynScan. TCP Port Scanner
3cheatthebox. HackTheBox.eu Cheater Tracker
3pam-destruct. Basic PAM module and test application
3cdncheck. A filter to check for CDN IP addresses during port scanning.
2celesianblog. SCSS
2static-toolbox. A collection of statically compiled tools like Nmap and Socat.
2subfinder. Fast passive subdomain enumeration tool.
1UserControl. MySQL User Control Tool
1dc_bot. Mining bot for DreamCraft
1client-side-prototype-pollution. Prototype Pollution and useful Script Gadgets
1fish_shortcuts. Aliases/Functions for fish shell that help with everyday life
1aaaaaa. aa
1cdfind. this will CD to a specified path and list files which contain a specified string in its name
1off-by-slash. Burp extension to detect alias traversal via NGINX misconfiguration at scale.
1ie-validator-js. Registration state validator for Brazilian companies (aka Inscrição Estadual)
1aaadwadaw.
1katana. A next-generation crawling and spidering framework.
1feroxbuster. A fast, simple, recursive content discovery tool written in Rust.
1clinicaboaesperanca. Software de gestão de pacientes, médicos e consultas para uma clínica médica fictícia.
1MacacoClicker. c++ autoclicker made for minecraft pvp, old version.
1mordhau_ranked_region_changer. A simple Windows/PyInstaller program that changes MORDHAU's matchmaking region. This is made for Brazilian MORDHAU players who want to play ranked 1v1 or 3v3 but can't stand the high latency of MatchMaking automatically picking NA servers.
1g. g"><img src=x>
1pendentia. Identify potentially hijackable Route53 hosted zones - then hijack them! Based on github.com/SHELLTHIEF/Plunderer, forked to add some new detection logic
1