El Mehdi 's starred repositories

ffuf

Fast web fuzzer written in Go

hakrawler

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

Language:GoLicense:GPL-3.0Stargazers:4292Issues:58Issues:103

tbhm

The Bug Hunters Methodology

gowitness

🔍 gowitness - a golang, web screenshot utility using Chrome Headless

Language:GoLicense:GPL-3.0Stargazers:2757Issues:45Issues:149

ASVS

Application Security Verification Standard

Language:HTMLLicense:CC-BY-SA-4.0Stargazers:2566Issues:141Issues:1154

bugcrowd_university

Open source education content for the researcher community

Web-CTF-Cheatsheet

Web CTF CheatSheet 🐈

jaeles

The Swiss Army knife for automated Web Application Testing

Language:GoLicense:MITStargazers:2101Issues:78Issues:51

HTTPLeaks

HTTPLeaks - All possible ways, a website can leak HTTP requests

Language:HTMLLicense:BSD-2-ClauseStargazers:1935Issues:90Issues:10

Android-Reports-and-Resources

A big list of Android Hackerone disclosed reports and other resources.

hakrevdns

Small, fast tool for performing reverse DNS lookups en masse.

Language:GoLicense:MITStargazers:1366Issues:19Issues:9

github-search

A collection of tools to perform searches on GitHub.

Language:PythonLicense:MITStargazers:1303Issues:38Issues:30

Corsy

CORS Misconfiguration Scanner

Language:PythonLicense:GPL-3.0Stargazers:1272Issues:31Issues:22

fav-up

IP lookup by favicon using Shodan

Language:PythonLicense:MITStargazers:1040Issues:24Issues:13

bruteforce-lists

Some files for bruteforcing certain things.

License:Apache-2.0Stargazers:1038Issues:34Issues:0

Silver

Mass scan IPs for vulnerable services

Language:PythonLicense:GPL-3.0Stargazers:1022Issues:21Issues:20

unfurl

Pull out bits of URLs provided on stdin

Language:GoLicense:MITStargazers:994Issues:16Issues:12

dnsgen

Generates combination of domain names from the provided input.

Language:PythonLicense:MITStargazers:852Issues:23Issues:13

subjs

Fetches javascript file from a list of URLS or subdomains.

Language:GoLicense:MITStargazers:718Issues:14Issues:14

ReconPi

ReconPi - A lightweight recon tool that performs extensive scanning with the latest tools.

Language:ShellLicense:MITStargazers:710Issues:29Issues:38

JSONBee

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

Language:PHPLicense:GPL-3.0Stargazers:630Issues:20Issues:2

dnspop

Analysis of DNS records to find popular trends

Language:ShellLicense:MITStargazers:437Issues:19Issues:1

chomp-scan

A scripted pipeline of tools to streamline the bug bounty/penetration test reconnaissance phase, so you can focus on chomping bugs.

Language:ShellLicense:GPL-3.0Stargazers:394Issues:20Issues:48

Asnlookup

Leverage ASN to look up IP addresses (IPv4 & IPv6) owned by a specific organization for reconnaissance purposes, then run port scanning on it.

Language:PythonLicense:MITStargazers:386Issues:9Issues:13

inception

A highly configurable Framework for easy automated web scanning

asnip

ASN target organization IP range attack surface mapping for reconnaissance, fast and lightweight

Language:GoLicense:MITStargazers:200Issues:7Issues:4

hacks

Repo of useful scripts

SundayStreams

Data from my Sunday streams

Language:HTMLStargazers:72Issues:4Issues:0

ScanApi

Subdomains-enumeration, subdomain-takeover monitoring api and S3 bucket scanner.

Language:PythonStargazers:38Issues:0Issues:0