J Savage's starred repositories

dive

A tool for exploring each layer in a docker image

sshuttle

Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS tunneling.

Language:PythonLicense:LGPL-2.1Stargazers:11660Issues:143Issues:503

subfinder

Fast passive subdomain enumeration tool.

gobuster

Directory/File, DNS and VHost busting tool written in Go

Language:GoLicense:Apache-2.0Stargazers:9663Issues:153Issues:281

httpx

httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.

aquatone

A Tool for Domain Flyovers

Language:GoLicense:MITStargazers:5612Issues:136Issues:0

apkleaks

Scanning APK file for URIs, endpoints & secrets.

Language:PythonLicense:Apache-2.0Stargazers:4882Issues:79Issues:58

can-i-take-over-xyz

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Language:PythonLicense:CC-BY-4.0Stargazers:4784Issues:127Issues:236

KingOfBugBountyTips

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wish to influence Onelinetips and explain the commands, for the better understanding of new hunters..

gau

Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.

knock

Knock Subdomain Scan

Language:PythonLicense:GPL-3.0Stargazers:3849Issues:135Issues:86

Findomain

The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, multiple API Keys for sources and much more.

Language:RustLicense:GPL-3.0Stargazers:3283Issues:59Issues:160

subjack

Subdomain Takeover tool written in Go

Language:GoLicense:Apache-2.0Stargazers:1895Issues:48Issues:63

smuggler

Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3

Language:PythonLicense:MITStargazers:1806Issues:32Issues:17

sslsplit

Transparent SSL/TLS interception

Language:CLicense:BSD-2-ClauseStargazers:1753Issues:103Issues:245

github-search

A collection of tools to perform searches on GitHub.

Language:PythonLicense:MITStargazers:1326Issues:38Issues:30

weaponised-XSS-payloads

XSS payloads designed to turn alert(1) into P1

crlfuzz

A fast tool to scan CRLF vulnerability written in Go

Language:GoLicense:MITStargazers:1317Issues:16Issues:15

Gf-Patterns

GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep

go-dork

The fastest dork scanner written in Go.

Language:GoLicense:MITStargazers:1123Issues:21Issues:17

unfurl

Pull out bits of URLs provided on stdin

Language:GoLicense:MITStargazers:1063Issues:17Issues:14

arp-scan

The ARP Scanner

Language:CLicense:GPL-3.0Stargazers:962Issues:40Issues:87

github-subdomains

Find subdomains on GitHub.

Language:GoLicense:MITStargazers:658Issues:11Issues:24

dnsvalidator

Maintains a list of IPv4 DNS servers by verifying them against baseline servers, and ensuring accurate responses.

Language:PythonLicense:GPL-3.0Stargazers:642Issues:20Issues:28

Nmap-Tools

SpiderLabs shared Nmap Tools

tiscripts

Turbo Intruder Scripts

Language:PythonLicense:MITStargazers:215Issues:6Issues:0

wraith

Uncover forgotten secrets and bring them back to life, haunting security and operations teams.

Language:GoLicense:MITStargazers:206Issues:11Issues:98

http-request-smuggling

HTTP request smuggling examples

Language:ShellStargazers:5Issues:3Issues:0