Starred repositories
Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan, VirusTotal & Intelligence X!
Correlated injection proxy tool for XSS Hunter
A high-speed tool for passively gathering URLs, optimized for efficient and comprehensive web asset discovery without active scanning.
Rust Bootcamp week 1: Set up you Rust development environment
Draw.io libraries for threat modeling diagrams
ServiceLens is a Python tool for analyzing services linked to Microsoft 365 domains. It scans DNS records like SPF and DMARC to identify services, categorizing them into Email, Cloud, Security, and…
An open source threat modeling tool from OWASP
Secrets Patterns DB: The largest open-source Database for detecting secrets, API keys, passwords, tokens, and more.
ripgrep recursively searches directories for a regex pattern while respecting your gitignore
Script to Automate installtion of Apps ,frida server and moving Burpsuite certificate to root folder
Misconfig Mapper is a fast tool to help you uncover security misconfigurations on popular third-party services used by your company and/or bug bounty targets!
⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.
AD Miner is an Active Directory audit tool that leverages cypher queries to crunch data from the #Bloodhound graph database to uncover security weaknesses
A rapid HTTP downgrade smuggling scanner written in Go.
An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
Identify hardcoded secrets in static structured text
Scan DockerHub images that match a keyword to find secrets.
The goal of this repository is to document the most common techniques to bypass AppLocker.
Tools and Techniques for Red Team / Penetration Testing
ScriptSentry finds misconfigured and dangerous logon scripts.
REX-Ray is a container storage orchestration engine enabling persistence for cloud native workloads
PabloDraw is an Ansi/Ascii text and RIPscrip vector graphic art editor/viewer with multi-user capabilities.
Simple HS256, HS384 & HS512 JWT token brute force cracker.