
awesome-web-security
🐶 A curated list of Web Security materials and resources.

🐶 A curated list of Web Security materials and resources.

Rock-On is a all in one Recon tool that will just get a single entry of the Domain name and do all of the work alone.

⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting

Orbis is an full spectrum automated external attack surface intelligent toolkit.

Python 3.5+ DNS asynchronous brute force utility

Subdomain enumeration tool with analysis features for discovered domains

Reconky is an great Content Discovery bash script for bug bounty hunters which automate lot of task and organized in the well mannered form which…

Passive DNS server that detects exposed cloud storage buckets (AWS S3, GCP, Azure) by resolving DNS requests, tracing CNAME chains, and flagging…

Multi-source subdomain enumeration tool with 50+ collection modules, DNS brute-force, passive DNS analysis, certificate transparency, search engine…

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

Automated Recon for Pentesting & Bug Bounty

Social Network Tabs Wordpress Plugin Vulnerability - CVE-2018-20555

Tips and Tutorials for Bug Bounty and also Penetration Tests.

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting /…

Subdomain and target enumeration tool built for offensive security testing

PAVELOW Exploit Toolbox is a BASH script that corresponds with your KALI distro to better help your vulnerability hunting and exploiting proccess…