
AzureHound
Collects Azure tenant data (users, groups, roles, resources) and exports it for BloodHound attack path analysis in cloud penetration testing and red…

Collects Azure tenant data (users, groups, roles, resources) and exports it for BloodHound attack path analysis in cloud penetration testing and red…

Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

🐶 A curated list of Web Security materials and resources.

A tool for mapping cyber crime

Terminal-based toolkit for GitHub data analysis.

Zoho ManageEngine ServiceDesk Plus MSP - Active Directory User Enumeration (CVE-2021-31159) - https://ricardojoserf.github.io/CVE-2021-31159/

Fast Python-based subdomain enumeration tool combining passive OSINT and active brute-force scanning with DNS wildcard detection, port scanning, and…

Omnisci3nt is an open-source web reconnaissance and intelligence tool for extracting deep technical insights from domains, including subdomains, SSL…

A Chrome/Firefox browser extension to show alerts for reflected query params, show Wayback archive links for the current path, show hidden elements…

A Python script that allows you to automatically scrape and download stories from your Telegram friends using the Telethon library. The script…

Curated list of web application security resources including books, tools, cheat sheets, labs, and courses for learning penetration testing and…

A list of resources for those interested in getting started in bug bounties

Email OSINT & Password breach hunting tool, locally or using premium services. Supports chasing down related email

This is the development tree. Production downloads are at:

pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching

Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.


Take back your privacy. Lose yourself in the haystack.