Noman | نعمان | नोमान's starred repositories

dive

A tool for exploring each layer in a docker image

ffuf

Fast web fuzzer written in Go

httpx

httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.

slack-term

Slack client for your terminal

pspy

Monitor linux processes without root permissions

Language:GoLicense:GPL-3.0Stargazers:4755Issues:51Issues:12

keyhacks

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

shhgit

Ah shhgit! Find secrets in your code. Secrets detection for your GitHub, GitLab and Bitbucket repositories.

Language:JavaScriptLicense:MITStargazers:3807Issues:63Issues:65

GitTools

A repository with 3 tools for pwn'ing websites with .git repositories available

Language:ShellLicense:MITStargazers:3782Issues:89Issues:25

gau

Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.

Language:GoLicense:MITStargazers:3742Issues:48Issues:98

LinkFinder

A python script that finds endpoints in JavaScript files

Language:PythonLicense:MITStargazers:3573Issues:64Issues:81

httprobe

Take a list of domains and probe for working HTTP and HTTPS servers

Language:GoLicense:MITStargazers:2779Issues:46Issues:46

Cr3dOv3r

Know the dangers of credential reuse attacks.

Language:PythonLicense:MITStargazers:1994Issues:101Issues:57

dvcs-ripper

Rip web accessible (distributed) version control systems: SVN/GIT/HG...

Language:PerlLicense:GPL-2.0Stargazers:1662Issues:52Issues:18

x8

Hidden parameters discovery suite

Language:RustLicense:GPL-3.0Stargazers:1617Issues:23Issues:51

meg

Fetch many paths for many hosts - without killing the hosts

Language:GoLicense:MITStargazers:1566Issues:36Issues:61

My-Shodan-Scripts

Collection of Scripts for shodan searching stuff.

Language:PythonLicense:MITStargazers:1046Issues:45Issues:2

clairvoyance

Obtain GraphQL API schema even if the introspection is disabled

Language:PythonLicense:Apache-2.0Stargazers:965Issues:12Issues:61

webanalyze

Port of Wappalyzer (uncovers technologies used on websites) to automate mass scanning.

Language:GoLicense:MITStargazers:915Issues:14Issues:52

getJS

A tool to fastly get all javascript sources/files

Language:GoLicense:MITStargazers:644Issues:10Issues:9

urldedupe

Pass in a list of URLs with query strings, get back a unique list of URLs and query string combinations

Language:C++License:MITStargazers:307Issues:6Issues:8

armada

A high performance TCP SYN port scanner.

Language:RustLicense:NOASSERTIONStargazers:305Issues:6Issues:17

awesome-attack-surface-monitoring

Curated list of open-source & paid Attack Surface Monitoring (ASM) tools.

jolokia-exploitation-toolkit

jolokia-exploitation-toolkit

Language:PythonStargazers:274Issues:5Issues:0

leaky-repo

Benchmarking repo for secrets scanning

Language:PythonLicense:MITStargazers:220Issues:9Issues:1

goaltdns

A permutation generation tool written in golang

Language:GoLicense:MITStargazers:202Issues:10Issues:4

CollabOzark

CollabOzark is a simple tool which helps the researchers track SSRF, RCE, Blind XSS, XXE, External Resource Access payloads triggers.

deepsecrets

Secrets scanner that understands code

Language:PythonLicense:MITStargazers:116Issues:4Issues:4

WhereToGo

WhereToGo - is a list of popular services that might be used in organizations. By having an account of the user - you can try to find entry points to the organization data.

spring-boot-actuator-h2-rce

Sample Spring Boot App Demonstrating RCE via Exposed env Actuator and H2 Database

fresh.py

An efficient multi-threaded DNS resolver validator