- All languages
- ActionScript
- Assembly
- Batchfile
- BlitzBasic
- Boo
- C
- C#
- C++
- CSS
- Clojure
- CodeQL
- DIGITAL Command Language
- Dart
- Dockerfile
- Go
- HCL
- HTML
- Hack
- Isabelle
- Java
- JavaScript
- Jinja
- Jupyter Notebook
- Kotlin
- Lua
- Makefile
- Markdown
- Max
- Mustache
- Nim
- OCaml
- Objective-C
- PHP
- Pascal
- Perl
- PowerShell
- Python
- R
- Rich Text Format
- Ruby
- Rust
- SCSS
- Scala
- Shell
- Smali
- Svelte
- Swift
- TeX
- TypeScript
- VBScript
- Vim Script
- Vue
- WebAssembly
- XSLT
- YARA
- Zeek
Starred repositories
This repo tries to explain complex security vulnerabilities in simple terms that even a five-year-old can understand!
Simple tool to scan a website for (DOM-based) XSS vulnerabilities and Open Redirects.
This repository contain a lot of web and api vulnerability checklist , a lot of vulnerability ideas and tips from twitter
wzqs / hackerone-reports
Forked from reddelexc/hackerone-reportsTop disclosed reports from HackerOne
A Burp Suite extension to add OpenAI (GPT) on Burp and help you with your Bug Bounty recon to discover endpoints, params, URLs, subdomains and more!
Python Script to Bypass Cloudflare Protection
Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!
List of tools for monitoring and analyze everything
A curated list of the most important and useful resources about elasticsearch: articles, videos, blogs, tips and tricks, use cases. All about Elasticsearch!
ZincSearch . A lightweight alternative to elasticsearch that requires minimal resources, written in Go.
Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more
domain_hunter的高级版本,SRC挖洞、HW打点之必备!自动化资产收集;快速Title获取;外部工具联动;等等
Sometimes we want to fuzz a set of sub-domain URLs with a common wordlist. Fuzzing them one by one is a tedious task, not to mention the false positives we obtain in those results. To solve this pr…
Burpsuite Extension to bypass 403 restricted directory
This tool downloads, installs, and configures a shiny new copy of Chromium.
GoSecure / wsuspect-proxy
Forked from ctxis/wsuspect-proxyWSUSpect Proxy - a tool for MITM'ing insecure WSUS connections
TLS Fingerprinting
A proof of concept that demonstrates asynchronous scanning for Java deserialization bugs
GoSecure / packer
Forked from hashicorp/packerPacker is a tool for creating identical machine images for multiple platforms from a single source configuration.
GoSecure / find-sec-bugs
Forked from find-sec-bugs/find-sec-bugsThe FindBugs plugin for security audits of Java web applications and Android applications. (Also work with Groovy and Scala projects)
GoSecure / yasuo
Forked from 0xsauby/yasuoA ruby script that scans for vulnerable & exploitable 3rd-party web applications on a network
Demonstration for the presentation Modern XSS
Finds unknown classes of injection vulnerabilities