This is your work, valued
Pentest-Tools-Framework. Pentest Tools Framework is a database of exploits, Scanners and tools for penetration testing. Pentest is a powerful framework includes a lot of tools for beginners. You can explore kernel vulnerabilities, network vulnerabilities
460XRCross. XRCross is a Reconstruction, Scanner, and a tool for penetration / BugBounty testing. This tool was built to test (XSS|SSRF|CORS|SSTI|IDOR|RCE|LFI|SQLI) vulnerabilities
349nodesub. Nodesub is a command-line tool for finding subdomains in bug bounty programs
149nuubi. Nuubi Tools (Information-ghatering|Scanner|Recon.)
86nuclei-templates. Community curated list of template files for the nuclei engine to find security vulnerability and fingerprinting the targets.
63js-finding. JS Finding can be used to extract JavaScript (JS) files from either a single domain URL or a list of domains. The tool supports various extraction methods and provides additional options for file download and wordlists creation.
50mtk-su. mtk-su
33hostinject. hostinject (Host Header Injection) Tool is a Python script that allows you to perform host header injection vulnerability testing on a target URL or a list of URLs. It injects various header values and checks for potential vulnerabilities.
30subdomain-monitoring-elasticsearch. Go
20nuclei-fuzz.
19nodecraw. nodecraw allows you to perform web crawling on specified URLs. It utilizes various modules and libraries to crawl web pages, extract information, and save the results.
13naomi. Naomi is a simple OSINT and information gathering tool that can scan quickly.
10awesome-cve-poc. ✍️ A curated list of CVE PoCs.
9kurosploit. KuroSploit is an exploit tool, KuroSploit provides an easy way to create backdoors and payload.
8bash-recon. [+] bash recon
7WebHackersWeapons. ⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting
6ResIm. ResIm is designed as a bash tool to find out domains,subdomains,ip subdomains, ports, DNS
6ip2host. This tool performs TLS connections to specified IP addresses, retrieves host information, and optionally gathers detailed IP information using the ipapi.co API.
6awesome-oneliner-bugbounty. A collection of awesome one-liner scripts especially for bug bounty tips.
6my-nuclei-templates.
5CloudFail. Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network
5EsubIz. EsubIz Tools,Passive subdomain Enumeration
5crlfi. Go
4bbot. OSINT automation for hackers.
3open-source-web-scanners. A list of open source web security scanners
3jaeles. The Swiss Army knife for automated Web Application Testing
2TheFatRat. Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This tool compiles a malware with popular payload and then the compiled malware can be execute on windows, android, mac . The malware that created with this tool also have an ability to bypass most AV software
2Awesome-WAF. 🔥 Everything about web-application firewalls (WAF).
2freegeoip. IP geolocation web server
2Bug-Bounty-Roadmaps. Bug Bounty Roadmaps
2xssmap. XSSMap 是一款基于 Python3 开发用于检测 XSS 漏洞的工具
2wadl-dumper. Dump all available paths and/ endpoints on WADL file.
2fuzzing-templates. Community curated list of nuclei templates for finding unknown security vulnerabilities.
2bug-actions.
2pentest-tools. Custom pentesting tools
2dotfile. Vim Script
2Warez. All your base are belong to us!
2bugbounty. Bugbounty Resources
1dProgBb. Detect Program Bug Bounty
1tlds. Go
1cent. Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place
1SubOver. A Powerful Subdomain Takeover Tool
1webHunt. Web App bug hunting
1KingOfBugBountyTips.
1top25-parameter. For basic researches, top 25 vulnerability parameters that can be used in automation tools or manual recon. 🛡️⚔️🧙
1Bug-Bounty-Toolz. BBT - Bug Bounty Tools
1axiom. A dynamic infrastructure toolkit for red teamers and bug bounty hunters!
1bugbounty-cheatsheet. A list of interesting payloads, tips and tricks for bug bounty hunters.
1PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
1Payloads_xss_sql_bypass.
1nuclei. Nuclei is a fast tool for configurable targeted scanning based on templates offering massive extensibility and ease of use.
1festin. FestIn - S3 Bucket Weakness Discovery
1PoC-in-GitHub. 📡 PoC auto collect from GitHub.
1