subDomainsBrute by lijiejie

A fast sub domain brute tool for pentesters

created at April 1, 2015, 7:22 a.m.

Python

116 +0

3,406 +4

1,008 +0

GitHub
bug-bounty-reference by ngalongc

Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature

created at Sept. 1, 2016, 12:53 p.m.

Unknown languages

244 +1

3,627 +4

980 +0

GitHub
Some-PoC-oR-ExP by coffeehb

各种漏洞poc、Exp的收集或编写

created at March 13, 2015, 3:31 p.m.

Python

156 +0

2,336 +2

971 +0

GitHub
awesome-bug-bounty by djadmin

A comprehensive curated list of available Bug Bounty & Disclosure Programs and Write-ups.

created at Feb. 13, 2016, 11 p.m.

Unknown languages

290 +1

4,422 +2

900 +0

GitHub
aquatone by michenriksen

A Tool for Domain Flyovers

created at Nov. 19, 2015, 11:30 a.m.

Go

135 +0

5,523 +11

865 +1

GitHub
gitrob by michenriksen

Reconnaissance tool for GitHub organizations

created at Jan. 7, 2015, 1:58 p.m.

Go

154 +0

5,856 +4

822 +0

GitHub
commix by commixproject

Automated All-in-One OS Command Injection Exploitation Tool.

created at March 20, 2015, 8:38 a.m.

Python

161 +0

4,387 +7

801 +1

GitHub
social_mapper by Greenwolf

A Social Media Enumeration & Correlation Tool by Jacob Wilkin(Greenwolf)

created at July 7, 2018, 2:50 p.m.

Python

227 +0

3,713 +3

784 +0

GitHub
AwesomeXSS by UltimateHackers

Awesome XSS stuff

created at March 11, 2018, 2:35 p.m.

JavaScript

240 +0

4,676 +3

759 +0

GitHub
awesome-cve-poc by qazbnm456

✍️ A curated list of CVE PoCs.

created at Feb. 2, 2017, 6:43 a.m.

Unknown languages

322 +0

3,253 +3

719 +0

GitHub
DOMPurify by cure53

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:

created at Feb. 17, 2014, 9:48 p.m.

JavaScript

150 +0

13,119 +44

681 +1

GitHub
tplmap by epinna

Server-Side Template Injection and Code Injection Detection and Exploitation Tool

created at July 6, 2016, 8:33 p.m.

Python

85 +1

3,658 -1

663 +1

GitHub
js-xss by leizongmin

Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist

created at Sept. 18, 2012, 2:05 p.m.

HTML

117 +0

5,131 +3

633 +1

GitHub
command-injection-payload-list by payloadbox

🎯 Command Injection Payload List

created at Nov. 3, 2018, 6:35 p.m.

Unknown languages

73 +1

2,729 +10

601 +2

GitHub
weevely3 by epinna

Weaponized web shell

created at Sept. 20, 2014, 10:16 a.m.

Python

132 +0

3,102 +1

600 +0

GitHub
openrasp by baidu

🔥Open source RASP solution

created at Aug. 10, 2017, 11:09 a.m.

C++

108 +0

2,717 +3

592 +0

GitHub
LinkFinder by GerbenJavado

A python script that finds endpoints in JavaScript files

created at June 9, 2017, 11:50 a.m.

Python

64 +1

3,539 +19

585 -2

GitHub
cloudgoat by RhinoSecurityLabs

CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool

created at July 17, 2018, 12:21 a.m.

Python

72 +0

2,800 +7

584 +1

GitHub
FOCA by ElevenPaths

Tool to find metadata and hidden information in the documents.

created at Oct. 2, 2017, 5:05 p.m.

C#

142 +0

2,806 +6

532 +0

GitHub
GSIL by FeeiCN

GitHub Sensitive Information Leakage(GitHub敏感信息泄露监控)

created at Oct. 11, 2017, 10:14 a.m.

Python

62 +0

2,112 +0

486 +0

GitHub