Hands-on projects for beginners to learn and practice essential cybersecurity skills through security assessments.
🛡️ The Ultimate Cybersecurity Library | 160+ curated books, guides & resources covering Ethical Hacking, Penetration Testing, Bug Bounty, Re…
Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps a…
My collection of various security tools created mostly in Python and Bash. For CTFs and Bug Bounty.
This script is designed to help expedite a web application assessment by automating some of the assessment steps (e.g., running nmap, sublis…
CLI security scanner built for the agentic era. Detects CI/CD misconfigs, agent permission risks, MCP tool injection, hardcoded secrets, and…
AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)
Semi-automatic OSINT framework and package manager
This repository is a comprehensive collection of SQL Injection Payloads designed for educational, research, and testing purposes. It include…
Simple python script supported with BurpBouty profile that helps you to detect SQL injection "Error based" by sending multiple requests with…
SQL Injection Vulnerability Scanner made with Python
Automatic SQL injection and database takeover tool. Supports detection and exploitation of all major SQL injection types across MySQL, MSSQL…
an exploit of Server-side request forgery (SSRF)
SSRF (Server Side Request Forgery) testing resources
Automatic SSRF (Server-Side Request Forgery) fuzzer and exploitation tool. Tests for SSRF vulnerabilities and exploits them to reach interna…
Automatic SSRF fuzzer and exploitation tool
Checks for SSRF using built-in custom Payloads after fetching URLs from Multiple Passive Sources & applying complex patterns aimed at SSRF
Red Kite, the Extensible Attack Surface Management tool.
A very (very) FAST and simple subdomain finder based on online & free services. Without any configuration requirements.
A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.
The Internets #1 Subdomain Takeover Tool
A fast subdomain takeover tool
DNS Takeover tool written in Go
A massive, curated collection of information security books, study guides, cheat sheets, and resources. This library is intended for educati…