
noir
Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

Flags parameters commonly associated with injection, SSRF, path traversal, IDOR, and SSTI, via passive Burp/ZAP scanning; also organizes manual…

Curated bug-bounty methodology library with runbooks, recon/fuzz playbooks, checklists, and CLI helpers for target scoping, cert enumeration, and…

The collaborative web app pentest suite

Defensive remediation and auditing toolkit for CVE-2026-54420 in LiteSpeed cPanel Plugin. Automates patching, detects suspicious symlinks, hunts…

A utility for detecting webpage inputs and conducting XSS scans.

This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and…

「🔑」A tool used to hunt down API key leaks in JS files and pages

Automated Python scanner to detect hardcoded secrets (Private Keys, API Tokens) in client-side JavaScript files.

Reproducible incident micro-postmortem for on-prem Microsoft SharePoint “ToolShell” (CVE-2025-53770): ATT&CK snapshot, “logs that matter” table,…

Next.js CVE-2025-29927 Hunter

An easy-to-setup version of XSS Hunter. Sets up in five minutes and requires no maintenance!

CVE-2023-27524

🥀 Search Engine Tookit,URL采集、Favicon哈希值查找真实IP、子域名查找

A basic phishing kit scanner for dedicated and semi-dedicated hosting

Learning and hunting SQL injection bugs for 50 continuous days

The XSS Hunter service - a portable version of XSSHunter.com

Website Sensitive Personal Information Hunter 网站个人敏感信息文件扫描器