HackLiners: CyberSec/BugHunting OneLiners
The all-in-one browser extension for offensive security professionals 🛠
API security testing framework for REST, GraphQL, and gRPC that validates authorization logic using role-based testing and YAML-driven templ…
A living document for penetration testing and offensive security.
utility to sanitize hast nodes
Use python helios.py --help for a full list of options and usage instructions.
Hooks in to interesting functions and helps reverse the web app faster.
HopLa Burp Suite Extender plugin - Brings AI capabilities, autocompletion support, and a set of useful payloads to Burp Suite
The most comprehensive Hack The Box writeup collection - 500+ machines, 400+ challenges, interactive knowledge graph, skill trees, attack pa…
Cleans HTML to avoid XSS attacks
A humble, and 𝗳𝗮𝘀𝘁, security-oriented HTTP headers analyzer.
Advanced reconnaissance framework for bug bounty hunters - Automate subdomain enumeration, vulnerability scanning, and security reconnaissan…
IDOR Forge is an advanced and versatile tool designed to detect Insecure Direct Object Reference (IDOR) vulnerabilities in web applications.
InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable sc…
Out-of-band interaction gathering server. Generates unique collaboration URLs for detecting blind vulnerabilities like SSRF, XXE, SSTI, blin…
Asset inventory of over 800 public bug bounty programs.
This is more of a checklist for myself. May contain useful tips and tricks. Still need to add a lot of things.
🔨 List all IP ranges from: Google (Cloud & GoogleBot), Bing (Bingbot), Amazon (AWS), Microsoft, Oracle (Cloud), GitHub, Facebook (Meta), Ope…
Use DOMPurify on server and client in the same way
JANUSEC Application Gateway provides secure access, including reverse proxy, K8S Ingress Controller, Automatic ACME Certificate, WAF, 5-Seco…
JAR, Java, and JSP shells that work on Linux OS, macOS, and Windows OS.
Java web and command line applications demonstrating various security topics
JavaScript library for building web-based applications that employ secure multi-party computation (MPC).
Jok3r v3 BETA 2 - Network and Web Pentest Automation Framework