Stars
a tool to get Facebook data, and some Facebook bots, and extra tools found on Facebook Toolkit ++.
Six Degrees of Domain Admin
W00t3k / social-analyzer
Forked from qeeqbox/social-analyzerAPI and Web App for analyzing & finding a person profile across +300 social media websites (Detections are updated regularly)
Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.
The official Exploit Database repository
This tool allows you to perform OSINT and reconnaissance on an organisation or an individual. It allows one to search 1.4 Billion clear text credentials which was dumped as part of BreachCompilatio…
Passhunt is a simple tool for searching of default credentials for network devices, web applications and more. Search through 523 vendors and their 2084 default passwords.
ISeeYou is a Bash and Javascript tool to find the exact location of the users during social engineering or phishing engagements. Using exact location coordinates an attacker can perform preliminary…
BigBountyRecon tool utilises 58 different techniques using various Google dorks and open source tools to expedite the process of initial reconnaissance on the target organisation.
E-mails, subdomains and names Harvester - OSINT
The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR
Th3Inspector 🕵️ Best Tool For Information Gathering 🔎
X Attacker Tool ☣ Website Vulnerability Scanner & Auto Exploiter
Deprecated - Low Orbit Ion Cannon - An open source network stress tool, written in C#. Based on Praetox's LOIC project. USE ON YOUR OWN RISK. WITHOUT ANY EXPRESS OR IMPLIED WARRANTIES. IF YOU GET V…
A collection of awesome penetration testing resources, tools and other shiny things
UndeadSec / Blazy
Forked from s0md3v/BlazyBlazy is a modern login bruteforcer which also tests for CSRF, Clickjacking, Cloudflare and WAF .
📱 🐟 An app to remote control SocialFish.