Mahmoud Azam's starred repositories

CheatSheetSeries

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Language:PythonLicense:CC-BY-SA-4.0Stargazers:27425Issues:570Issues:439

awesome-pentest

A collection of awesome penetration testing resources, tools and other shiny things

h4cker

This repository is primarily maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), artificial intelligence security, vulnerability research, exploit development, reverse engineering, and more.

Language:Jupyter NotebookLicense:MITStargazers:18057Issues:895Issues:95

awesome-osint

:scream: A curated list of amazingly awesome OSINT

personal-security-checklist

🔒 A compiled checklist of 300+ tips for protecting digital security and privacy in 2024

Language:TypeScriptLicense:NOASSERTIONStargazers:16589Issues:212Issues:84

trufflehog

Find, verify, and analyze leaked credentials

Language:GoLicense:AGPL-3.0Stargazers:15420Issues:168Issues:622

wpscan

WPScan WordPress security scanner. Written for security professionals and blog maintainers to test the security of their WordPress websites. Contact us via contact@wpscan.com

Language:RubyLicense:NOASSERTIONStargazers:8466Issues:268Issues:1439

Penetration_Testing_POC

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms

Language:HTMLLicense:Apache-2.0Stargazers:6475Issues:255Issues:7

cve

Gather and update all available and newest CVEs with their PoC.

Language:HTMLLicense:MITStargazers:6397Issues:335Issues:50

awesome-infosec

A curated list of awesome infosec courses and training resources.

keyhacks

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

KingOfBugBountyTips

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wish to influence Onelinetips and explain the commands, for the better understanding of new hunters..

bounty-targets-data

This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports

License:MITStargazers:3088Issues:235Issues:0

OneListForAll

Rockyou for web fuzzing

pentest-guide

Penetration tests guide based on OWASP including test cases, resources and examples.

gitGraber

gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...

Language:PythonLicense:GPL-3.0Stargazers:1993Issues:42Issues:26

zen-rails-security-checklist

Checklist of security precautions for Ruby on Rails applications.

Language:RubyLicense:MITStargazers:1811Issues:76Issues:7

API-s-for-OSINT

List of API's for gathering information about phone numbers, addresses, domains etc

git-all-secrets

A tool to capture all the git secrets by leveraging multiple open source git searching tools

Language:GoLicense:MITStargazers:1100Issues:40Issues:37

non-typical-OSINT-guide

The most unusual OSINT guide you've ever seen. The repository is intended for bored professionals only. PRs are welcome!

offensive-bookmarks

A collection of bookmarks for penetration testers, bug bounty hunters, malware developers, reverse engineers and anyone who is just interested in infosec topics.

Language:HTMLLicense:GPL-3.0Stargazers:887Issues:13Issues:0

ohshint.gitbook.io

So what is this all about? Yep, its an OSINT blog and a collection of OSINT resources and tools. Suggestions for new OSINT resources is always welcomed.

Language:HTMLLicense:NOASSERTIONStargazers:711Issues:22Issues:2

TOP

TOP All bugbounty pentesting CVE-2023- POC Exp RCE example payload Things

Language:ShellStargazers:646Issues:30Issues:0

bug-bounty-platforms

A community-powered collection of all known bug bounty platforms, vulnerability disclosure platforms, and crowdsourced security platforms currently active on the Internet.

Language:PythonStargazers:468Issues:12Issues:0

private_templates

Private Nuclei Templates

Security-Research

This repository contains proof of concept for zero days and CVEs that were found by Omar Hashem through Security Research

The-Nen-Book

The Nen Book is a list of personal notes and tips collected from a lot of recourses in different categories like: WebApp Security, API Security, Cloud Security, Network Pentesting, Code Review, Threat Hunting.

bugy

a simple helpful tool for Bug Hunters

Language:PythonStargazers:9Issues:0Issues:0