awesomeaakash's starred repositories

PayloadsAllTheThings

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Language:PythonLicense:MITStargazers:58295Issues:1810Issues:0

SecLists

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

dalfox

🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.

bugcrowd_university

Open source education content for the researcher community

jaeles

The Swiss Army knife for automated Web Application Testing

Language:GoLicense:MITStargazers:2110Issues:78Issues:51

BBTz

BBT - Bug Bounty Tools (examples💡)

subdomain3

A new generation of tool for discovering subdomains( ip , cdn and so on)

Language:PythonLicense:MITStargazers:706Issues:27Issues:16

HTTP-Smuggling-Lab

Use HTTP Smuggling Lab to learn HTTP Smuggling.

Wordlists

Various Payload wordlists

XSSCon

XSSCon: Simple XSS Scanner tool

Language:PythonLicense:MITStargazers:202Issues:9Issues:15

auth_analyzer

Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

Language:JavaLicense:MITStargazers:180Issues:6Issues:38

whoxyrm

A reverse whois tool based on Whoxy API.

Language:GoLicense:MITStargazers:152Issues:3Issues:5

blue_eye

Blue Eye is a python Recon Toolkit script. It shows ports and headers. Subdomain resolves to the IP addresses, company email addresses and much more ..! Author: Jolanda de Koff

Language:PythonLicense:GPL-3.0Stargazers:135Issues:13Issues:0

ghsec-jaeles-signatures

Signatures for jaeles scanner by @j3ssie

awesome-bug-bounty-tips

A curated list of amazingly bug bounty tips from security researchers around the world.

vulnsearch

A deep look at some recon methodologies and web-application vulnerabilities of my interest where I will merge all my notes gathered from books, videos, articles and own experience with bug bounty hunting / web and network hacking

crt.sh

A shell script to grab subdomains from https://crt.sh, and probe for working http and https servers with @tomnomnom's tool https://github.com/tomnomnom/httprobe

Language:ShellLicense:MITStargazers:41Issues:0Issues:0
Language:PythonStargazers:26Issues:3Issues:0

secrets

Offsec Pentest and Bug Bounty Notes

License:MITStargazers:24Issues:2Issues:0
Language:HTMLStargazers:18Issues:0Issues:0

bash_script_templates

Some Templates for Bash Scripting

Language:ShellStargazers:17Issues:3Issues:0

hackmaster9000

hack faster with hackmaster9000

Language:JavaScriptLicense:GPL-3.0Stargazers:13Issues:5Issues:0

cname-check

Check if the subdomains have cnames to the same tld or 3rd party service

Language:ShellStargazers:11Issues:2Issues:0

shoping_site

dummy shopping site for whitebox pentestig

Language:SCSSStargazers:9Issues:3Issues:0

hackerone_wordlist

The wordlists that have been compiled using disclosed reports at HackerOne bug bounty platform

License:GPL-3.0Stargazers:8Issues:0Issues:0

hyperecon

recon setup + automation

Language:ShellStargazers:7Issues:0Issues:0

My-WebSec-Notes

Some notes (tips/tricks) gathered by me during time related to web pentesting, bug bounty and browser/tools stuff.

Stargazers:5Issues:0Issues:0

BountyNotes

A Noob's Journey in the Realm of Bugs

Language:HTMLStargazers:3Issues:0Issues:0