
GraphCrawler
GraphQL automated security testing toolkit

GraphQL automated security testing toolkit

Vulnerability scanner based on vulners.com audit API

Curated inventory of cybersecurity tools and resources covering penetration testing, forensics, OSINT, web security, malware analysis, cryptography,…

Curated directory of bug bounty tools organized by category: reconnaissance, subdomain enumeration, port scanning, content discovery, exploitation,…

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are…

有关burpsuite的插件(非商店),文章以及使用技巧的收集(此项目不再提供burpsuite破解文件,如需要请在博客mrxn.net下载)---Collection of burpsuite plugins (non-stores), articles and tips for using…

Tools and Techniques for Blue Team / Incident Response

⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting

All the deals for InfoSec related software/tools this Black Friday

A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.

A collection of awesome one-liner scripts especially for bug bounty tips.

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Curated, categorized wordlist generator for web fuzzing, directory enumeration, and subdomain discovery. Automatically syncs 36+ sources, classifies…


A collection of real world AI/ML exploits for responsibly disclosed vulnerabilities

Nuclei Templates Collection

A collection of ZAP scripts and tips provided by the community - pull requests very welcome!