I find security vulnerabilities for a living · HackerOne & Intigriti
JSA. Javascript security analysis (JSA) is a program for javascript analysis during web application security assessment.
567bugbounty_changelogs.
61Open_Redirects_list. -
11chaos-hacks.
9totally-not-web-hacking. Python
7GoogD0rker. GoogD0rker is a tool for firing off google dorks against a target domain, it is purely for OSINT against a specific target domain. READ the readme before messaging or tweeting me.
4CSPBypass. JavaScript
2pentest-tools. Custom pentesting tools
2subjack. Subdomain Takeover tool written in Go
1PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
1urlwatch. urlwatch monitors webpages for you
1SecretFinder. SecretFinder - A python script for find sensitive data (apikeys, accesstoken,jwt,..) and search anything on javascript files
1hacks. A collection of hacks and one-off scripts
1recollapse. REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications
1nuclei-templates. Community curated list of templates for the nuclei engine to find a security vulnerability in application.
1fuzz.txt. Potentially dangerous files
1subjs. Fetches javascript file from a list of URLS or subdomains.
1slack-unhide. Chrome extension that bypasses the message viewing restriction on UI.
1