
recon-skills
Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

A collection of awesome penetration testing resources, tools and other shiny things

The Offensive Manual Web Application Penetration Testing Framework.

A tool that transforms Firefox browsers into a penetration testing suite

Attack surface discovery and AI-assisted triage for security researchers. Endpoint & parameter mapping with actionable testing hints.


Wicked sick v2.0 script is intended to automate your reconnaissance process in an organized fashion.

User Enumeration vulnerability in Kaiten (workflow management system)

A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24…

Advanced dork Search & Mass Exploit Scanner

Weaponizing WaybackUrls for Recon, BugBounties , OSINT, Sensitive Endpoints and what not

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Social Network Tabs Wordpress Plugin Vulnerability - CVE-2018-20555

Passive recon & attack surface mapper — zero requests sent

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

Broken Object Level Authorization (BOLA) in CERN's Indico leads to authenticated user enumeration.

A list of resources for those interested in getting started in bug bounties