There is just one way to do security: TOGETHER.
4-ZERO-3. 403/401 Bypass Methods + Bash Automation + Your Support ;)
1.7kkarma_v2. ⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)
1kback-me-up. This tool will check for Sensitive Data Leakage with some useful patterns/RegEx. The patterns are mostly targeted on waybackdata and filter everything accordingly.
229Lilly. Tool to find the real IP behind CDNs/WAFs like cloudflare using passive recon by retrieving the favicon hash. For the same hash value, all the possible IPs, PORTs and SSL/TLS Certs are searched to validate the target in-scope.
184notes. Bug Bounty & Other Stuff
59karma_v1. KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Ports.
58subzzZ. SubzzZ to find possible subdomains using passive recon. Tool also support Permutations, Mutations, Alterations.
38Prototype-Pollution-Lab_me_dheeraj. Prototype-Pollution-Lab to chain the vulnerabilities between multiple accounts.
13Dheerajmadhukar. Director | Trainer at CDAC Under The Ministry of Electronics and Information | Corporate Trainer at Indian Air Force Under the Ministry of Defense ... Jai Hind
12BB-Hunt-A-Day. A simple mind map with some automation/bash commands/tools execution. I hope it may help you all :)
7GitApp. GITAPP : Tool will display all data URLs from GitHub including XML, JSON, Java, Text, Kotlin, Ruby, Markdown, CSV, Python, PHP, GO, YAML, Elixir, C++, JavaScript, HTML & many more . . .
7scant3r. ScanT3r - Module based Bug Bounty Automation Tool
6oh-my-dorks. HTML
5Resources-for-Beginner-Bug-Bounty-Hunters. A list of resources for those interested in getting started in bug bounties
5Insecure-Comparison-Lab_me_dheeraj. Insecure Comparison in JavaScript. CTF written in nodejs Express module.
5Sudomy. Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting / pentesting
4community. For US
3reconftw. ReconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
3Funny_Me_Dheeraj. trip
2GitOps-CTF. Master Git through Capture-the-Flag challenges
2pr2tik1. My GitHub profile-README (Don't Just Fork, star too 🥺)
2fdns. To resolve IP/Domain to check the correct resolver.
2Amass. In-depth Attack Surface Mapping and Asset Discovery
2GraphQLmap. GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes.
1cariddi. Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more...
1learn365. This repo is about @harshbothra_ 365 days of learning Tweet & Mindmap collection
1asn. ASN / RPKI validity / BGP stats / IPv4v6 / Prefix / URL / ASPath / Organization / IP reputation and geolocation lookup tool / Traceroute server
1lazyscripts. bash scripts to automate server administration tasks
1PrototypePollution-Lab. Prototype Pollution Lab
1submax. All in one subdomain Enumeration tool
1davtest. A simple CLI tool to check WebDAV vulnerability
1BugBountyScanner. A Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use.
1github-dorks. Find leaked secrets via github search
1