PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
80kSSRFmap. Automatic SSRF fuzzer and exploitation tool
3.6kInternalAllTheThings. Active Directory and Internal Pentest Cheatsheets
2.3kGraphQLmap. GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)
1.7kHardwareAllTheThings. Hardware/IOT Pentesting Wiki
915Wordpresscan. WPScan rewritten in Python + some WPSeku ideas
653DamnWebScanner. Another web vulnerabilities scanner, this extension works on Chrome and Opera
471SharpLAPS. Retrieve LAPS password from LDAP
447Vulny-Code-Static-Analysis. Python script to detect vulnerabilities inside PHP source code using static analysis, based on regex
425WHID_Toolkit. Simple script for the WHID injector - a rubberducky wifi
120Nephelees. Néphélées (Νεφήλαι, Nephḗlai) : cloud nymphs greek - also NTDS cracking tool on Google Cloud
38swisskyrepo.github.io. Source of swisskyrepo.github.io - Public
31jsleak. Upgrading jsleak with a CI/CD and new rules
17ygo-meta-deck. Deck analysis with OpenAI
1