tinfoleak by vaguileradiaz

The most complete open-source tool for Twitter intelligence analysis

updated at Nov. 17, 2024, 4:38 a.m.

Python

73 +0

1,932 +3

270 +1

GitHub
prowler by prowler-cloud

Prowler is an Open Source Security tool for AWS, Azure, GCP and Kubernetes to do security assessments, audits, incident response, compliance, continuous monitoring, hardening and forensics readiness. Includes CIS, NIST 800, NIST CSF, CISA, FedRAMP, PCI-DSS, GDPR, HIPAA, FFIEC, SOC2, GXP, Well-Architected Security, ENS and more

updated at Nov. 17, 2024, 3:11 a.m.

Python

130 +0

10,847 +39

1,543 +3

GitHub
retire.js by RetireJS

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

updated at Nov. 17, 2024, 3:04 a.m.

JavaScript

83 -1

3,692 +6

417 +0

GitHub
bXSS by LewisArdern

bXSS is a utility which can be used by bug hunters and organizations to identify Blind Cross-Site Scripting.

updated at Nov. 17, 2024, 2:45 a.m.

JavaScript

14 +0

518 +5

64 +0

GitHub
juice-shop by juice-shop

OWASP Juice Shop: Probably the most modern and sophisticated insecure web application

updated at Nov. 17, 2024, 2:16 a.m.

TypeScript

161 +0

10,468 +20

10,939 +47

GitHub
gitleaks by gitleaks

Protect and discover secrets using Gitleaks 🔑

updated at Nov. 17, 2024, 2:12 a.m.

Go

163 +0

17,953 +114

1,469 +6

GitHub
radare2 by radareorg

UNIX-like reverse engineering framework and command-line toolset

updated at Nov. 17, 2024, 1:24 a.m.

C

488 +1

20,710 +33

3,006 +3

GitHub
mitmproxy by mitmproxy

An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.

updated at Nov. 17, 2024, 12:42 a.m.

Python

624 +0

36,847 +91

4,041 +6

GitHub
dirhunt by Nekmo

Find web directories without bruteforce

updated at Nov. 16, 2024, 11:46 p.m.

Python

33 +0

1,770 +5

255 +0

GitHub
aquatone by michenriksen

A Tool for Domain Flyovers

updated at Nov. 16, 2024, 11:32 p.m.

Go

136 +0

5,643 +2

885 +2

GitHub
Raccoon by evyatarmeged

A high performance offensive security tool for reconnaissance and vulnerability scanning

updated at Nov. 16, 2024, 11:31 p.m.

Python

108 +0

3,090 +2

400 +0

GitHub
DOMPurify by cure53

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:

updated at Nov. 16, 2024, 11:22 p.m.

JavaScript

151 -1

14,021 +40

726 +3

GitHub
a2sv by hahwul

Auto Scanning to SSL Vulnerability

updated at Nov. 16, 2024, 10:36 p.m.

Python

46 +0

627 +1

169 +0

GitHub
domato by googleprojectzero

DOM fuzzer

updated at Nov. 16, 2024, 10:14 p.m.

Python

67 +0

1,695 +9

278 +0

GitHub
social_mapper by Greenwolf

A Social Media Enumeration & Correlation Tool by Jacob Wilkin(Greenwolf)

updated at Nov. 16, 2024, 8:30 p.m.

Python

225 +0

3,808 +2

788 +0

GitHub
bug-bounty-reference by ngalongc

Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature

updated at Nov. 16, 2024, 7:50 p.m.

Unknown languages

239 +0

3,754 +4

988 -1

GitHub
webshell by tennc

This is a webshell open source project

updated at Nov. 16, 2024, 6:10 p.m.

PHP

488 +0

10,123 +15

5,574 +1

GitHub
ReconDog by UltimateHackers

Reconnaissance Swiss Army Knife

updated at Nov. 16, 2024, 4:05 p.m.

Python

83 +0

1,814 +5

340 +0

GitHub
XSStrike by UltimateHackers

Most advanced XSS scanner.

updated at Nov. 16, 2024, 3:25 p.m.

Python

274 +0

13,376 +28

1,906 +3

GitHub
fuzzdb by fuzzdb-project

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

updated at Nov. 16, 2024, 2:50 p.m.

PHP

366 +0

8,244 +8

2,098 -1

GitHub