Matin7697's starred repositories

hashcat

World's fastest and most advanced password recovery utility

GTFOBins.github.io

GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems

Language:HTMLLicense:GPL-3.0Stargazers:10716Issues:144Issues:47

john

John the Ripper jumbo - advanced offline password cracker, which supports hundreds of hash and cipher types, and runs on many operating systems, CPUs, GPUs, and even some FPGAs

Language:CLicense:NOASSERTIONStargazers:10119Issues:265Issues:3188

nikto

Nikto web server scanner

Language:PerlLicense:NOASSERTIONStargazers:8427Issues:281Issues:457

osint_stuff_tool_collection

A collection of several hundred online tools for OSINT

wafw00f

WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

Language:PythonLicense:BSD-3-ClauseStargazers:5203Issues:140Issues:98

knock

Knock Subdomain Scan

Language:PythonLicense:GPL-3.0Stargazers:3849Issues:135Issues:86

Findomain

The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, multiple API Keys for sources and much more.

Language:RustLicense:GPL-3.0Stargazers:3283Issues:59Issues:160

waymore

Find way more from the Wayback Machine, Common Crawl, Alien Vault OTX, URLScan & VirusTotal!

Language:PythonLicense:MITStargazers:1683Issues:15Issues:45

bruteforce-lists

Some files for bruteforcing certain things.

License:Apache-2.0Stargazers:1130Issues:35Issues:0

the-art-of-subdomain-enumeration

This repository contains all the supplement material for the book "The art of sub-domain enumeration"

jsmon

a javascript change monitoring tool for bugbounties

Language:PythonLicense:MITStargazers:584Issues:15Issues:10

haktrails

Golang client for querying SecurityTrails API data

Language:GoLicense:MITStargazers:534Issues:10Issues:12

hakcheckurl

Takes a list of URLs and returns their HTTP response codes

Language:GoLicense:MITStargazers:389Issues:8Issues:6

cloudflare-origin-ip

Try to find the origin IP of a webapp protected by Cloudflare.

Language:PythonLicense:MITStargazers:320Issues:4Issues:13

urless

De-clutter a list of URLs

apidetector

APIDetector: Efficiently scan for exposed Swagger endpoints across web domains and subdomains. Supports HTTP/HTTPS, multi-threading, and flexible input/output options. Ideal for API security testing.

Language:PythonLicense:MITStargazers:295Issues:4Issues:2

zeek-cheatsheets

Zeek Log Cheatsheets

License:NOASSERTIONStargazers:283Issues:33Issues:0

ActiveMQ-RCE

ActiveMQ RCE (CVE-2023-46604) 漏洞利用工具

Forbidden-Buster

A tool designed to automate various techniques in order to bypass HTTP 401 and 403 response codes and gain access to unauthorized areas in the system. This code is made for security enthusiasts and professionals only. Use it at your own risk.

Language:PythonLicense:MITStargazers:157Issues:4Issues:2

sign-saboteur

SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens

Language:JavaLicense:Apache-2.0Stargazers:135Issues:3Issues:5

toxicache

Go scanner to find web cache poisoning vulnerabilities in a list of URLs

CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ

Achieving a Reverse Shell Exploit for Apache ActiveMQ (CVE_2023-46604)

Language:GoStargazers:105Issues:2Issues:0

callow

Dead simple brute force tool for website login forms

Language:PythonLicense:GPL-3.0Stargazers:80Issues:4Issues:19

github-regexp

Basically a regexp over a GitHub search.

Language:GoLicense:MITStargazers:61Issues:7Issues:2

active-ip

🕵️‍♂️🔍 A tool with several scanning techniques that extracts live IP addresses from a list of IP addresses or CIDR notations.

Language:GoLicense:MITStargazers:47Issues:1Issues:0

burpsuite-js-extractor

A simple plugin to export JS files from one or multiple targets

Language:PythonLicense:Apache-2.0Stargazers:38Issues:2Issues:0

favicon-hashtrick

Python script implementing the favicon hash trick to find subdomains.

Language:PythonLicense:MITStargazers:26Issues:2Issues:0

Daily-Notes

A Series of Tweets

thm_writeups

Write-ups of Try Hack me challenge machines