
Red-Teaming-Toolkit
This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.

Curated framework of free OSINT tools and resources for gathering intelligence from public sources, organized by category with structured metadata…

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

Open Cyber Threat Intelligence Platform

Your personal intelligence agent. Watches the world from multiple data sources and pings you when something changes.

A list of public penetration test reports published by several consulting firms and academic security groups.

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

Curated, community-maintained directory of data broker opt-out instructions to help individuals remove personal information from people-search sites…

This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports

📡 Comprehensive collection of OSINT tools for cybersecurity professionals, researchers, and bug bounty hunters. Topics: information gathering,…

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

A list of interesting payloads, tips and tricks for bug bounty hunters.

🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩💻

Tools and Techniques for Blue Team / Incident Response

All about bug bounty (bypasses, payloads, and etc)

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are…