Andrew's starred repositories

cmder

Lovely console emulator package for Windows

agenda

Lightweight job scheduling for Node.js

Language:TypeScriptLicense:NOASSERTIONStargazers:9375Issues:125Issues:822

tsunami-security-scanner

Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.

Language:JavaLicense:Apache-2.0Stargazers:8213Issues:312Issues:81

hetty

An HTTP toolkit for security research.

bullmq

BullMQ - Message Queue and Batch processing for NodeJS and Python based on Redis

Language:TypeScriptLicense:MITStargazers:5988Issues:31Issues:1117

Arjun

HTTP parameter discovery suite.

Language:PythonLicense:AGPL-3.0Stargazers:5155Issues:86Issues:143

app

The SimpleLogin back-end and web app

Language:PythonLicense:AGPL-3.0Stargazers:5042Issues:50Issues:435

can-i-take-over-xyz

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Language:PythonLicense:CC-BY-4.0Stargazers:4772Issues:127Issues:235

tbhm

The Bug Hunters Methodology

bugcrowd_university

Open source education content for the researcher community

jaeles

The Swiss Army knife for automated Web Application Testing

Language:GoLicense:MITStargazers:2146Issues:78Issues:51

client-side-prototype-pollution

Prototype Pollution and useful Script Gadgets

Interception

The Interception API aims to build a portable programming interface that allows one to intercept and control a range of input devices.

Gf-Patterns

GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep

Autorize

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests

Watcher

Watcher - Open Source Cybersecurity Threat Hunting Platform. Developed with Django & React JS.

Language:PythonLicense:AGPL-3.0Stargazers:851Issues:38Issues:48

cloudlist

Cloudlist is a tool for listing Assets from multiple Cloud Providers.

Language:GoLicense:MITStargazers:843Issues:35Issues:46

ChopChop

ChopChop is a CLI to help developers scanning endpoints and identifying exposition of sensitive services/files/folders.

Language:GoLicense:NOASSERTIONStargazers:669Issues:21Issues:18

hidviz

A tool for in-depth analysis of USB HID devices communication

Language:C++License:GPL-3.0Stargazers:555Issues:34Issues:26

PPScan

Client Side Prototype Pollution Scanner

Language:JavaScriptLicense:MITStargazers:505Issues:18Issues:6

DirDar

DirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it

nosqli

NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.

Language:GoLicense:AGPL-3.0Stargazers:351Issues:6Issues:14

qsfuzz

qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.

Language:GoLicense:MITStargazers:295Issues:7Issues:12

posta

🐙 Cross-document messaging security research tool powered by https://enso.security

Language:JavaScriptLicense:MITStargazers:278Issues:9Issues:8

shapeshifter

GraphQL security testing tool

rasp_vusb

This repo explains how to turn your Raspberry Pi Zero into USB Keyboard and Mouse. Also provides sample code and binaries to control them.

Language:C#License:Apache-2.0Stargazers:107Issues:7Issues:18

meteorman

A DDP client with GUI (The Postman for Meteor)

Language:VueLicense:MITStargazers:52Issues:9Issues:4

interception_py

A python port (not a wrapper) of interception dll

Language:PythonLicense:MITStargazers:46Issues:4Issues:10

meteor-login-token

Automatically log in a user if a valid, unexpired, single-use `authToken` is present in the URL.

bsv-docs

backup of /docs from https://github.com/moneybutton/bsv