
awesome-search-queries
Community curated list of search queries for various products across multiple search engines.

Community curated list of search queries for various products across multiple search engines.

Infosec wordlists for content discovery, directory brute-force, and subdomain enumeration: CMS/technology paths, robots.txt disallowed paths, and SSL…

Curated, continuously validated list of reliable DNS resolvers for DNS enumeration, reconnaissance, and bug bounty workflows.

Curated bug-bounty methodology library with runbooks, recon/fuzz playbooks, checklists, and CLI helpers for target scoping, cert enumeration, and…

🐶 A curated list of Web Security materials and resources.

Practical study notes and walkthroughs for PortSwigger Academy labs, covering web vulnerabilities, payloads, enumeration, and BSCP exam strategies.

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

OWASP enumeration of common security and privacy weaknesses in mobile applications, serving as a reference bridging the MASVS verification standard…

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Curated list of OSINT tools for offensive security, covering email harvesting, subdomain enumeration, threat intelligence, and social engineering for…

Curated bug bounty reconnaissance methodology with 400+ one-liners for subdomain enumeration, vulnerability scanning, API testing, and OSINT.…

Vendor-neutral cloud security testing guide with structured phases for enumeration, privilege escalation, lateral movement, and post-exploitation…

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

Local static query builder for precise search across web engines, Shodan, crt.sh, and Wayback Machine. Supports Google dorks, filetype filters, date…

Scans Discord links across mutual guilds to extract profiles, cross‑references 700+ sites, searches usernames with 30+ tools, and generates an…

Published security research repository featuring academic papers on domain hijacking, 2FA bypass, and large-scale spoofing techniques, authored by…

A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.

A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC