El Mehdi 's starred repositories

nuclei

Fast and customizable vulnerability scanner based on simple YAML based DSL.

nuclei-templates

Community curated list of templates for the nuclei engine to find security vulnerabilities.

Language:JavaScriptLicense:MITStargazers:8546Issues:197Issues:1432

OneForAll

OneForAll是一款功能强大的子域收集工具

Language:PythonLicense:GPL-3.0Stargazers:7922Issues:101Issues:312

android-security-awesome

A collection of android security related resources

Language:ShellLicense:Apache-2.0Stargazers:7856Issues:426Issues:41

AwesomeXSS

Awesome XSS stuff

Language:JavaScriptLicense:MITStargazers:4697Issues:240Issues:13

keyhacks

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

naabu

A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentests

pentest-tools

A collection of custom security tools for quick needs.

Bug-bounty

Ressources for bug bounty hunting

shuffledns

MassDNS wrapper written in go to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard filtering and easy input-output support.

Language:GoLicense:GPL-3.0Stargazers:1254Issues:38Issues:72

wordlists

Automated & Manual Wordlists provided by Assetnote

Language:CSSLicense:Apache-2.0Stargazers:1224Issues:25Issues:4

XSS-Payloads

List of XSS Vectors/Payloads

leonids

A simple, fixed sidebar two columns Gatsby.js blog starter.

Language:JavaScriptLicense:MITStargazers:870Issues:18Issues:47

whonow

A "malicious" DNS server for executing DNS Rebinding attacks on the fly (public instance running on rebind.network:53)

Language:JavaScriptLicense:MITStargazers:617Issues:22Issues:10

Command-Mobile-Penetration-Testing-Cheatsheet

Mobile penetration testing android & iOS command cheatsheet

websocket-smuggle

Issues with WebSocket reverse proxying allowing to smuggle HTTP requests

Language:PythonLicense:MITStargazers:330Issues:12Issues:2

qsfuzz

qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.

Language:GoLicense:MITStargazers:294Issues:7Issues:12

bash_scripting

bash scripting thing!

maravel-permissions

Because in the Maravelous univer every user deserves super power

Language:PHPStargazers:141Issues:7Issues:0

dr_robot

This tool can be used to enumerate the subdomains associated with a company by aggregating the results of multiple OSINT (Open Source Intelligence) tools.

Language:PythonLicense:NOASSERTIONStargazers:141Issues:13Issues:41

Android-Vulnerabilities

Covers Top 10 OWASP Mobile Vulnerabilities

Language:ShellStargazers:112Issues:10Issues:0

whoosh

[Prototype] Control a 3D spaceship with hand movements

Language:JavaScriptLicense:GPL-3.0Stargazers:107Issues:8Issues:2

CTF

My CTF writeups

Language:PythonStargazers:96Issues:7Issues:0

alldomains

all domains and his subdoamins

shania

Scan secrets from Continuous Integration Build Logs

Language:PythonLicense:MITStargazers:53Issues:4Issues:2

Enums

Just lists of lists of lists !

disco-data

Discovery data for various bug bounties