
Shockwave-OSS
Curated collection of bug bounty tips, one-liners, and automation workflows for recon, fuzzing, and web exploitation, with private nuclei templates…

Curated collection of bug bounty tips, one-liners, and automation workflows for recon, fuzzing, and web exploitation, with private nuclei templates…

Subdomain brute-forcing tool that enumerates existing subdomains and detects misconfigured cloud-hosted subdomains vulnerable to takeover across AWS,…

Fast Python-based subdomain enumeration tool combining passive OSINT and active brute-force scanning with DNS wildcard detection, port scanning, and…

Automated Recon for Pentesting & Bug Bounty

VPN Overall Reconnaissance, Testing, Enumeration and eXploitation Toolkit

Master script for web reconnaissance

Curated collection of wordlists for bug bounty hunting, covering directories, subdomains, parameters, usernames, passwords, and web fuzzing payloads.

Go-based tool that scans webpages and JavaScript files to discover hidden subdomains and secrets, with optional crawling and real-time proxy analysis…

Crawls web applications to detect second-order subdomain takeover vulnerabilities by collecting URLs and matching configurable rules for non-200…

A New Approach to Directory Bruteforce with WaybackLister v1.0

A script to extract subdomains/emails for a given domain using SSL/TLS certificate dataset on Censys

Ashok is a OSINT Recon Tool , a.k.a 😍 Swiss Army knife .

🦚 A web-app pentesting suite written in rust .

Search for information related to domain: Emails - IP addresses - Sub-Domains - Information on WEB technology - Type of Firewall - NS and MX records.

A script to extract domain names from Content Security Policy(CSP) headers

Searching for virtual hosts among non-resolvable domains

Tool for checking Whether a domain or its multiple sub-domains are up and running.

A really simple utility to concate wordlists to a domain name - to pipe into your favourite resolver!