Starred repositories
Open Source Vulnerability Management Platform
Scalpel is a Burp extension for intercepting and rewriting HTTP traffic, either on the fly or in the Repeater using Python 3 scripts.
EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.
Sample images for testing Exif metadata retrieval.
An open source Bitcoin wallet password and seed recovery tool designed for the case where you already know most of your password/seed, but need assistance in trying different possible combinations.
Burp extention to automatically generate OpenAPI Json for Swagger from proxy traffic
Mishka Chelekom is a fully featured components and UI kit library for Phoenix & Phoenix LiveView
latest version of scanners for IIS short filename (8.3) disclosure vulnerability
List of Awesome Red Teaming Resources
A wordlist framework to fullfill your kinks with your wordlists. For security researchers, bug bounty and hackers.
Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
A collection of one-liners for bug bounty hunting.
jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice
real time face swap and one-click video deepfake with only a single image
Top disclosed reports from HackerOne
Wordlists that have been compiled using Commonspeak2. This repo is updated every time new wordlists are generated.
A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target
This is a useful Python script for generating a target specific wordlist for fuzzing backup files.
A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
Speech To Speech: an effort for an open-sourced and modular GPT4-o