Starred repositories
This tool is an efficient scanner designed to detect Cache Deception vulnerabilities in web servers. It automates the process of testing URLs by using customizable delimiters and extensions, with m…
📡 PoC auto collect from GitHub.
One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password 🛡️
🔎 Static code analysis engine to find security issues in code.
Stealth patch for Frida, stealth knowledge collection
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).
bookmark for javascript endpoint extractor
Scope gathering tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!
Some Useful Tricks for Pentest Android and iOS Apps
A collection of Semgrep rules derived from the OWASP MASTG specifically for Android applications.
federicodotta / semgrep-rules-android-security
Forked from mindedsecurity/semgrep-rules-android-securityA collection of Semgrep rules derived from the OWASP MASTG specifically for Android applications.
Burp plugin able to find reflected XSS on page in real-time while browsing on site
A client library to multiplex connections from and to iOS devices
A tool for adding new lines to files, skipping duplicates
This Chromium extension scans the page for external iFrames, Scripts, and Styles, logs them to the console, and checks if their domains are resolvable.
Notify is a Go-based assistance package that enables you to stream the output of several tools (or read from a file) and publish it to a variety of supported platforms.
GBounty Profiles are customizable security test definitions used by the GBounty web scanner to identify vulnerabilities in web applications. These profiles outline a series of steps and conditions …
GBounty is a multi-step website vulnerability scanner developed in Golang designed to help companies, pentesters, and bug hunters identify potential vulnerabilities in web applications.
A streamlined tool for discovering private TLDs for security research.
Yet another frida based iOS dumpdecrypted. Also decrypts app extensions
Nuclei plugin for BurpSuite
🍯 T-Pot - The All In One Multi Honeypot Platform 🐝