This is your work, valued

Meerut, Uttar Pradesh, India

Abhinav Singwal

Elite
@yogsec

Finding Vulnerabilities in Websites | Penetration Tester | Cybersecurity | Open to Work

Hacking-Tools. A curated list of penetration testing and ethical hacking tools, organized by category. This compilation includes tools from Kali Linux and other notable sources.

1.8k

API-Pentesting-Tools. API Pentesting Tools are specialized security tools used to test and analyze the security of Application Programming Interfaces (APIs).

322

Digital-Forensics-Tools. A curated list of essential digital forensics tools used for investigation, data recovery, and security analysis. These tools help in disk forensics, memory analysis, network monitoring, malware analysis, and more.

114

SQL-Injection-Payloads. This repository is a comprehensive collection of SQL Injection Payloads designed for educational, research, and testing purposes. It includes a wide variety of payloads for different SQLi techniques.

106

Physical-Pentesting-Tools. Physical penetration testing is a critical aspect of security assessment that involves simulating real-world attacks to evaluate the effectiveness of physical security controls.

97

One-Liner-OSINT. One Liner OSINT is a collection of powerful one-liner commands for Open-Source Intelligence (OSINT) gathering.

79

Social-Engineering-Tactics. Social Engineering Tactics contains real-world social engineering tactics used for manipulation, persuasion, and deception. Stay aware and stay secure!

78

Social-Engineering-Tools. A powerful collection of tools designed for social engineering research, penetration testing, and security awareness training.

68

OSINT-Tools. The OSINT Framework is a powerful collection of tools and methods designed for open-source intelligence gathering. This framework covers a wide range of categories to help security researchers, investigators, and analysts uncover crucial information effectively.

67

OneLinerBounty. OneLinerBounty is a collection of quick, actionable bug bounty tips in one-liner format. Perfect for bug hunters looking to boost their skills and efficiency. Contribute your own tips or use these to streamline your workflow and uncover more vulnerabilities. #BugBounty #Cybersecurity #HackTips #SecurityResearch #OneLinerBugBounty #OneLinerBounty

62

BugBoard. Bugboard is a comprehensive open-source cybersecurity tool for vulnerability detection and bug hunting.

49

Hardware-Hacking-Tools. Lists various tools used in hardware hacking.

41

Pen-Testing-Google-Dorks. Google Dorks that can be used for penetration testing, security research, and information gathering.

37

XSS-Payloads. This repository is a comprehensive collection of Cross-Site Scripting (XSS) Payloads designed for educational, research, and testing purposes. It includes payloads for various XSS attack types such as Reflected XSS, Stored XSS, DOM-Based XSS, and WAF Bypass Techniques.

28

Hacker-AI. This tool combines the power of Ollama (Mistral) with your terminal to turn natural language into real shell commands. Whether you want to scan websites with nmap or ping a server, just type what you want — HackerAI handles the rest. All locally, without any API costs!

26

DorkTerm. DorkTerm is a security tool designed to assist security researchers in performing Google Dork queries efficiently. The tool generates multiple Google Dork search queries for a given domain and opens them in new browser tabs to help identify potential vulnerabilities.

21

HACKING-BOT. HACKING BOT is an automated bug bounty tool that streamlines security testing by running multiple cybersecurity tools in parallel. It allows you to customize the tools list and automate reconnaissance, scanning, exploitation, and post-exploitation analysis.

20

endpoints-extractor. A powerful Bash script for extracting URLs and API endpoints from HTML, JavaScript, and JSON content of web pages. Designed for security researchers, bug bounty hunters, and developers to streamline endpoint discovery. Simple to use, supports single or multiple URLs, and offers file-saving capabilities.

18

YogSec-Search. YogSec Search is a powerful and flexible search tool designed to fetch search results from Bing.

13

xss-labs. xss-labs for learning web application security. Each lab demonstrates a different XSS vulnerability with interactive examples and solutions. Frontend-only, no server required.

13

email-finder. Email Finder is a powerful and fast Python-based tool designed to extract email addresses from websites. It helps security researchers, penetration testers, and web analysts quickly discover contact information from target websites by scanning common contact endpoints.

10

Alive. Alive is a fast and concurrent URL checker that identifies live domains returning HTTP 200 OK status. It supports single URLs and bulk lists, bypasses WAF protections using random user agents, and offers optional saving of results.

9

HTTP-FILTER. HTTP FILTER is a fast and efficient Bash tool that automates HTTP response code analysis for security researchers, penetration testers, and bug bounty hunters. It processes a list of URLs concurrently, categorizing them into separate files based on HTTP status codes (e.g., 200.txt, 404.txt, 500.txt).

9

CyberSecurity-Vulnerability-CheatSheet. CyberSecurity-Vulnerability-CheatSheet is a comprehensive guide for bug bounty hunters, ethical hackers, and developers. It covers 100+ web application vulnerabilities, including authentication, cryptography, business logic flaws, and DoS, with actionable insights, tools, and examples to enhance security assessments.

8

URL_Extractor. URL Extractor | Designed By YogSec is a powerful Bash script that helps you extract URLs from a single file or all files inside a folder

6

Web-History-Analysis. Web History Analysis is an advanced tool for classifying and categorizing URLs from browser history logs using machine learning techniques.

5

yogsec. I find vulnerabilities in web applications before attackers do. I test web apps, APIs, and mobile apps from an attacker's point of view. I look for flaws like IDOR, XSS, SSRF, CORS issues, access control problems, and other security misconfigurations.

5

cors. A fast tool to detect CORS misconfigurations in web applications.

5

CorsScanner. CorsScanneris a Bash script designed to detect and analyze CORS misconfigurations in web applications. With its efficient concurrency and detailed output, it empowers developers and security researchers to identify potential vulnerabilities in Access-Control headers, ensuring robust web security.

4

LFI-Payloads. LFI Payloads - A comprehensive collection of Local File Inclusion (LFI) payloads for security researchers and penetration testers. This repository includes common, advanced, and bypass techniques to help identify and exploit LFI vulnerabilities effectively.

4

cybersecurity-social-engineering. A collection of real-world social engineering techniques used in cybersecurity, complete with examples and explanations.

4

Email-Filter. Email Filter is a command-line tool designed to clean and filter email lists by removing unwanted or invalid emails, removing duplicates, and keeping only the most useful email for each domain (such as contact@ or info@). It also handles noisy lines and extracts only valid emails from messy inputs.

3

exposed-file-scanner. Exposed File Finder is a lightweight and efficient Bash script designed to enhance web application security by identifying exposed files in HTML, JavaScript, and JSON code. It helps developers and security researchers uncover potential vulnerabilities and sensitive information in websites or hosted GitHub repositories.

3

wordpress-fix. Detects vulnerabilities in WordPress websites.

3

Open-Redirect. Open Redirect - An educational web application demonstrating open redirect vulnerabilities.

3

bash-utility-script. A powerful Bash utility script for managing wordlists, saving outputs, and displaying version information. Simplify your tasks with this user-friendly tool, designed for developers, security researchers, and system administrators. 🚀

2

Bug-Bounty-Checklist. A “Bug Bounty Checklist” GitHub repo will not only help you stay organized but also help others in the community.

2

job-search. Job Search tool

2

Vulnerable-shopping-Cart. A deliberately insecure e-commerce application designed for cybersecurity education and penetration testing practice.

2

Vulnerable-Login. Vulnerable login form designed for security education and training.

2

Open-Redirect-Payloads. A collection of various Open Redirect payloads for security researchers, penetration testers, and bug bounty hunters.

1

Header-Generator. Header Generator is a simple yet powerful Python CLI tool that converts your text into beautiful ASCII art headers using the art library. Perfect for adding some flair to your scripts, projects, and tools!

1

Secure-Communication-Tool. A Bash-based encryption & decryption tool using AES-256-CBC, allowing secure message exchange with a single password. Easy-to-use CLI for bug bounty hunters, security researchers, and privacy enthusiasts.

1

GetSubDomains. GetSubDomains is a fast and efficient Bash tool for retrieving subdomains of a given domain using the crt.sh certificate transparency logs. This tool is useful for security researchers, penetration testers, and bug bounty hunters to quickly enumerate subdomains with minimal overhead.

1

Malicious-Website-Demo. Malicious-Website-Demo is a cybersecurity demonstration project that simulates common web vulnerabilities in a controlled environment. Built with a red danger-themed design, this website showcases scenarios like malicious redirects and landing pages to educate researchers and enthusiasts about online threats.

1

google-bug-report-access-control-bug. A comprehensive report on a Broken Access Control vulnerability in Google Photos, exposing unauthorized access to private photos. This repository includes proof of concept, impact analysis, and mitigation recommendations for better security practices.

1

payloads. Bug Bounty Payloads

1