The Jewel of java

PikPikcU

Expert
@pikpikcu

Pentest-Tools-Framework. Pentest Tools Framework is a database of exploits, Scanners and tools for penetration testing. Pentest is a powerful framework includes a lot of tools for beginners. You can explore kernel vulnerabilities, network vulnerabilities

460

XRCross. XRCross is a Reconstruction, Scanner, and a tool for penetration / BugBounty testing. This tool was built to test (XSS|SSRF|CORS|SSTI|IDOR|RCE|LFI|SQLI) vulnerabilities

349

nodesub. Nodesub is a command-line tool for finding subdomains in bug bounty programs

149

nuubi. Nuubi Tools (Information-ghatering|Scanner|Recon.)

86

nuclei-templates. Community curated list of template files for the nuclei engine to find security vulnerability and fingerprinting the targets.

63

js-finding. JS Finding can be used to extract JavaScript (JS) files from either a single domain URL or a list of domains. The tool supports various extraction methods and provides additional options for file download and wordlists creation.

50

mtk-su. mtk-su

33

hostinject. hostinject (Host Header Injection) Tool is a Python script that allows you to perform host header injection vulnerability testing on a target URL or a list of URLs. It injects various header values and checks for potential vulnerabilities.

30

subdomain-monitoring-elasticsearch. Go

20

nuclei-fuzz.

19

nodecraw. nodecraw allows you to perform web crawling on specified URLs. It utilizes various modules and libraries to crawl web pages, extract information, and save the results.

13

naomi. Naomi is a simple OSINT and information gathering tool that can scan quickly.

10

awesome-cve-poc. ✍️ A curated list of CVE PoCs.

9

kurosploit. KuroSploit is an exploit tool, KuroSploit provides an easy way to create backdoors and payload.

8

bash-recon. [+] bash recon

7

WebHackersWeapons. ⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting

6

ResIm. ResIm is designed as a bash tool to find out domains,subdomains,ip subdomains, ports, DNS

6

ip2host. This tool performs TLS connections to specified IP addresses, retrieves host information, and optionally gathers detailed IP information using the ipapi.co API.

6

awesome-oneliner-bugbounty. A collection of awesome one-liner scripts especially for bug bounty tips.

6

my-nuclei-templates.

5

CloudFail. Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network

5

EsubIz. EsubIz Tools,Passive subdomain Enumeration

5

crlfi. Go

4

bbot. OSINT automation for hackers.

3

open-source-web-scanners. A list of open source web security scanners

3

jaeles. The Swiss Army knife for automated Web Application Testing

2

TheFatRat. Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This tool compiles a malware with popular payload and then the compiled malware can be execute on windows, android, mac . The malware that created with this tool also have an ability to bypass most AV software

2

Awesome-WAF. 🔥 Everything about web-application firewalls (WAF).

2

freegeoip. IP geolocation web server

2

Bug-Bounty-Roadmaps. Bug Bounty Roadmaps

2

xssmap. XSSMap 是一款基于 Python3 开发用于检测 XSS 漏洞的工具

2

wadl-dumper. Dump all available paths and/ endpoints on WADL file.

2

fuzzing-templates. Community curated list of nuclei templates for finding unknown security vulnerabilities.

2

bug-actions.

2

pentest-tools. Custom pentesting tools

2

dotfile. Vim Script

2

Warez. All your base are belong to us!

2

bugbounty. Bugbounty Resources

1

dProgBb. Detect Program Bug Bounty

1

tlds. Go

1

cent. Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place

1

SubOver. A Powerful Subdomain Takeover Tool

1

webHunt. Web App bug hunting

1

KingOfBugBountyTips.

1

top25-parameter. For basic researches, top 25 vulnerability parameters that can be used in automation tools or manual recon. 🛡️⚔️🧙

1

Bug-Bounty-Toolz. BBT - Bug Bounty Tools

1

axiom. A dynamic infrastructure toolkit for red teamers and bug bounty hunters!

1

bugbounty-cheatsheet. A list of interesting payloads, tips and tricks for bug bounty hunters.

1

PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF

1

Payloads_xss_sql_bypass.

1

nuclei. Nuclei is a fast tool for configurable targeted scanning based on templates offering massive extensibility and ease of use.

1

festin. FestIn - S3 Bucket Weakness Discovery

1

PoC-in-GitHub. 📡 PoC auto collect from GitHub.

1
53
Apply