El Mehdi 's starred repositories

nuclei

Fast and customizable vulnerability scanner based on simple YAML based DSL.

owasp-mastg

The Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the controls listed in the OWASP Mobile Application Security Verification Standard (MASVS).

Language:PythonLicense:CC-BY-SA-4.0Stargazers:11558Issues:424Issues:1092

nuclei-templates

Community curated list of templates for the nuclei engine to find security vulnerabilities.

Language:JavaScriptLicense:MITStargazers:8909Issues:198Issues:1482

OneForAll

OneForAll是一款功能强大的子域收集工具

Language:PythonLicense:GPL-3.0Stargazers:8093Issues:103Issues:320

android-security-awesome

A collection of android security related resources

Language:ShellLicense:Apache-2.0Stargazers:7993Issues:429Issues:42

keyhacks

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

AwesomeXSS

Awesome XSS stuff

Language:JavaScriptLicense:MITStargazers:4729Issues:239Issues:13

naabu

A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentests

KingOfBugBountyTips

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wish to influence Onelinetips and explain the commands, for the better understanding of new hunters..

pentest-tools

A collection of custom security tools for quick needs.

Bug-bounty

Ressources for bug bounty hunting

wordlists

Automated & Manual Wordlists provided by Assetnote

Language:CSSLicense:Apache-2.0Stargazers:1270Issues:26Issues:4

XSS-Payloads

List of XSS Vectors/Payloads

bhg

Code samples for No Starch Press Black Hat Go

Language:JavaScriptLicense:MITStargazers:1114Issues:47Issues:19

leonids

A simple, fixed sidebar two columns Gatsby.js blog starter.

Language:JavaScriptLicense:MITStargazers:868Issues:18Issues:47

XSSTRON

Electron JS Browser To Find XSS Vulnerabilities Automatically

Language:JavaScriptLicense:GPL-3.0Stargazers:682Issues:26Issues:25

whonow

A "malicious" DNS server for executing DNS Rebinding attacks on the fly (public instance running on rebind.network:53)

Language:JavaScriptLicense:MITStargazers:618Issues:22Issues:10

qsfuzz

qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.

Language:GoLicense:MITStargazers:294Issues:7Issues:12

bash_scripting

bash scripting thing!

h1passets

List HackerOne private program assets

Language:PythonLicense:MITStargazers:148Issues:8Issues:7

maravel-permissions

Because in the Maravelous univer every user deserves super power

Language:PHPStargazers:141Issues:7Issues:0

dr_robot

This tool can be used to enumerate the subdomains associated with a company by aggregating the results of multiple OSINT (Open Source Intelligence) tools.

Language:PythonLicense:NOASSERTIONStargazers:140Issues:13Issues:41

Android-Vulnerabilities

Covers Top 10 OWASP Mobile Vulnerabilities

Language:ShellStargazers:114Issues:10Issues:0

CTF

My CTF writeups

Language:PythonStargazers:96Issues:7Issues:0

shania

Scan secrets from Continuous Integration Build Logs

Language:PythonLicense:MITStargazers:52Issues:4Issues:2

Enums

Just lists of lists of lists !