


A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak…

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24…

MCP server enabling AI agents to autonomously execute 150+ cybersecurity tools for automated penetration testing, vulnerability discovery, bug bounty…

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

A list of web application security

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are…

Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia,…

A high performance offensive security tool for reconnaissance and vulnerability scanning

Modern CLI for exploring vulnerability data with powerful search, filtering, and analysis capabilities.

Tips and Tutorials for Bug Bounty and also Penetration Tests.

A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.

A Telegram Mass Surveillance Bot in Python

Aggregates CVE details, exploit databases, and EPSS scores with AI risk assessment and vulnerability scanner import for prioritized patching.

evilwaf is a penetration testing tool designed to detect and bypass common Web Application Firewalls (WAFs).

A Penetration Testing Framework, Information gathering tool & Website Vulnerability Scanner

Offensive security platform that automates attack surface discovery and vulnerability management

Nightingale Docker for Pentesters is a comprehensive Dockerized environment tailored for penetration testing and vulnerability assessment. It comes…