Starred repositories
🔎 Static code analysis engine to find security issues in code.
Stealth patch for Frida, stealth knowledge collection
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).
bookmark for javascript endpoint extractor
Scope gathering tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!
Some Useful Tricks for Pentest Android and iOS Apps
A collection of Semgrep rules derived from the OWASP MASTG specifically for Android applications.
federicodotta / semgrep-rules-android-security
Forked from mindedsecurity/semgrep-rules-android-securityA collection of Semgrep rules derived from the OWASP MASTG specifically for Android applications.
Burp plugin able to find reflected XSS on page in real-time while browsing on site
A client library to multiplex connections from and to iOS devices
A tool for adding new lines to files, skipping duplicates
This Chromium extension scans the page for external iFrames, Scripts, and Styles, logs them to the console, and checks if their domains are resolvable.
Notify is a Go-based assistance package that enables you to stream the output of several tools (or read from a file) and publish it to a variety of supported platforms.
GBounty Profiles are customizable security test definitions used by the GBounty web scanner to identify vulnerabilities in web applications. These profiles outline a series of steps and conditions …
GBounty is a multi-step website vulnerability scanner developed in Golang designed to help companies, pentesters, and bug hunters identify potential vulnerabilities in web applications.
A streamlined tool for discovering private TLDs for security research.
Yet another frida based iOS dumpdecrypted. Also decrypts app extensions
Nuclei plugin for BurpSuite
🍯 T-Pot - The All In One Multi Honeypot Platform 🐝
Opensource assets and vulnerability scanning tool
Secrets Patterns DB: The largest open-source Database for detecting secrets, API keys, passwords, tokens, and more.
Command-line tool that allows searching and downloading app packages (known as ipa files) from the iOS App Store
Using z3 to predict `Math.random` in v8