This is your work, valued
databasement. Self-hosted database backup manager with a web UI. Schedule, backup, and restore MySQL, PostgreSQL, MariaDB, Microsoft SQL Server, MongoDB, SQLite & Redis to S3, SFTP, Samba or local storage. SSH Tunnel support.
★ 1.9kcc-vuln-researcher. Python
★ 7claude-code-deepseek. Run Claude Code CLI with DeepSeek API — cheap high-volume automation for security research & bug bounty
★ 27hackingtool. ALL IN ONE Hacking Tool For Hackers
★ 79kNginx-Rift. NGINX RCE exploits
★ 910sherlock. Hunt down social media accounts by username across social networks
★ 87kNotes.
★ 2.7kbeszel. Lightweight server monitoring with historical data, docker stats, and alerts.
★ 24kWallos. Wallos: Open-source, self-hostable personal subscription tracker. Visualize your recurring expenses, manage your budget, and save money.
★ 8.3kpayloads_flipperZero. Collection of Payloads BadUSB for Flipper Zero with DuckyScript 1.0
★ 388malicious_extension_sentry. Malicious Extension Database
★ 189awesome. 😎 Awesome lists about all kinds of interesting topics
★ 491kawesome-threat-intelligence. A curated list of Awesome Threat Intelligence resources
★ 10kcli. Tool to help automate adding contributor acknowledgements according to the all-contributors specification ✨
★ 425devops-directive-kubernetes-course. This is the companion repo for the DevOps Directive "Kubernetes: Beginner to Pro" course!
★ 1.9kunwaf. Unwaf is a Go tool designed to help identify WAF bypasses using passive techniques. It automates the process of discovering the real origin IP behind a WAF/CDN by combining multiple discovery methods and verifying candidates through HTML similarity comparison, SSL certificate fingerprinting, and HTTP header analysis.
★ 185redamon. An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
★ 2.3kThreat-Hunting. Threat Hunting queries of multiple platforms
★ 76EpsteOut. See which of your LinkedIn connections appear in the Epstein files.
★ 641mitmrouter. Bash script to automate setup of Linux router useful for IoT device traffic analysis and SSL mitm
★ 744awesome-selfhosted. A list of Free Software network services and web applications which can be hosted on your own servers
★ 310kCeWL. CeWL is a Custom Word List Generator
★ 2.8kGOAD. game of active directory
★ 8.1kvulnerability-Checklist. This repository contain a lot of web and api vulnerability checklist , a lot of vulnerability ideas and tips from twitter
★ 3.6kxsshunter-express. An easy-to-setup version of XSS Hunter. Sets up in five minutes and requires no maintenance!
★ 2.4kfluxion. Unified Vulnerability Intelligence Platform
★ 74katana. A next-generation crawling and spidering framework.
★ 17kdozzle. Realtime log viewer for containers. Supports Docker, Swarm and K8s.
★ 14kawesome-security. A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.
★ 15kreact2shell-scanner. High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)
★ 2.5kweb-check. 🕵️♂️ All-in-one OSINT tool for analysing any website
★ 34kno-as-a-service. No-as-a-Service (NaaS) is a simple API that returns a random rejection reason. Use it when you need a realistic excuse, a fun “no,” or want to simulate being turned down in style.
★ 7.8kvulnx. Modern CLI for exploring vulnerability data with powerful search, filtering, and analysis capabilities.
★ 2.6kJSONBee. A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.
★ 765bounty-targets-data. This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports
★ 3.9ks3dns. Find S3 AWS/GCP/Azure buckets while surfing. S3DNS acts as DNS server, follows CNAMEs and matches any bucket pattern
★ 129Dynamic-Path-Traversal-Tester. Python
★ 26firecrawl. The API to search, scrape, and interact with the web at scale. 🔥
★ 159krec0n. A fully automated subdomain reconnaissance and sensitive data discovery toolkit.
★ 47One-Liner-OSINT. One Liner OSINT is a collection of powerful one-liner commands for Open-Source Intelligence (OSINT) gathering.
★ 794-ZERO-3. 403/401 Bypass Methods + Bash Automation + Your Support ;)
★ 1.7k