
recon-skills
Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Agentic Pentesting MCP server that discovers, exploits, and reports web application vulnerabilities.

python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。

Advanced cross-platform web crawler for security professionals, enabling automated reconnaissance, information gathering, and OSINT data collection…

A fast WordPress plugin enumeration tool

🕵️ Python project to crawl for JavaScript files and search for secrets like API keys, authorization tokens, hardcoded credentials, etc.

API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites

Web technology identification scanner with 1800+ plugins for detecting CMS, servers, JS libraries, and embedded devices. Supports stealthy to…

A fast, simple, recursive content discovery tool written in Rust.

Automated CMS vulnerability scanner with intelligent shell injection, subdomain enumeration, port scanning, DNS analysis, and dork-based exploit…

Multi-module OSINT tool for email harvesting, subdomain enumeration, PGP key lookup, Shodan queries, Telegram scraping, phone number lookup, and…

One-liner bug bounty workflows for recon, subdomain enumeration, endpoint extraction, and web vulnerability scanning using Nuclei, sqlmap, and CVE…