
semgrep-rules
Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

🐶 A curated list of Web Security materials and resources.

Curated collection of top HackerOne bug bounty reports organized by vulnerability type and program, with scripts to fetch, deduplicate, and rank…

⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting

Sudomy is a subdomain enumeration tool to collect subdomains and analyzing domains performing automated reconnaissance (recon) for bug hunting /…

Tips and Tutorials for Bug Bounty and also Penetration Tests.

Concurrent DNS takeover scanner detecting CNAME, NS, AXFR, SPF, MX, SRV, and stale A record vulnerabilities across cloud providers, with multi-level…

Subdomain takeover vulnerability checker

Find open databases - Powered by Binaryedge.io

XSS payloads designed to turn alert(1) into P1

Field-validated offensive security skill pack with 169 techniques for reconnaissance and penetration testing. Covers CORS, SSRF, subdomain takeover,…

A Powerful Subdomain Takeover Tool

Curated collection of bug bounty writeups covering OWASP Top 10 vulnerabilities, including XSS, SQLi, SSRF, and RCE, for educational learning and…

An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for…

ReconPi - A lightweight recon tool that performs extensive scanning with the latest tools.

Vajra is a highly customizable target and scope based automated web hacking framework to automate boring recon tasks and same scans for multiple…

Database firewall written in Go

Automated Recon for Pentesting & Bug Bounty