El Mehdi 's starred repositories

SecLists

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

fabric

fabric is an open-source framework for augmenting humans using AI. It provides a modular framework for solving specific problems using a crowdsourced set of AI prompts that can be used anywhere.

Language:PythonLicense:MITStargazers:10954Issues:184Issues:185

osint_stuff_tool_collection

A collection of several hundred online tools for OSINT

awesome-bugbounty-tools

A curated list of various bug bounty tools

bug-bounty-reference

Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature

bounty-targets-data

This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports

License:MITStargazers:2999Issues:234Issues:0

massdns

A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)

Language:CLicense:GPL-3.0Stargazers:2983Issues:74Issues:109

medusa

Binary instrumentation framework based on FRIDA

Language:PythonLicense:GPL-3.0Stargazers:1425Issues:45Issues:44

xsshunter-express

An easy-to-setup version of XSS Hunter. Sets up in five minutes and requires no maintenance!

Language:JavaScriptLicense:MITStargazers:1382Issues:10Issues:26

wordlists

Real-world infosec wordlists, updated regularly

bug-bounty-dorks

List of Google Dorks for sites that have responsible disclosure program / bug bounty program

filterbypass

Browser's XSS Filter Bypass Cheat Sheet

postMessage-tracker

A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon

Language:JavaScriptLicense:MITStargazers:979Issues:37Issues:5

cook

A wordlist framework to fullfill your kinks with your wordlists. For security researchers, bug bounty and hackers.

Language:GoLicense:MITStargazers:946Issues:20Issues:15

Nuclei-Templates-Collection

Nuclei Templates Collection

cookiemonster

🍪 CookieMonster helps you detect and abuse vulnerable implementations of stateless sessions.

Language:GoLicense:MITStargazers:748Issues:11Issues:6

http-garden

Differential testing and fuzzing of HTTP servers and proxies

Language:PythonLicense:GPL-3.0Stargazers:609Issues:10Issues:33

surf

Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable SSRF candidates.

leakScraper

LeakScraper is an efficient set of tools to process and visualize huge text files containing credentials. Theses tools are designed to help penetration testers and redteamers doing OSINT by gathering credentials belonging to their target.

Language:PythonLicense:GPL-3.0Stargazers:385Issues:15Issues:5

cssInjection

Stealing CSRF tokens with CSS injection (without iFrames)

Language:HTMLLicense:GPL-2.0Stargazers:312Issues:15Issues:0

sj

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Language:GoLicense:MITStargazers:297Issues:1Issues:1

RepeaterSearch

This extension adds a search bar to the Repeater tab that can be used to highlight all repeater tabs where the request and/or response matches a query via simple text matching or Regex.

trickest-cli

Execute Trickest workflows right from your terminal

Language:GoLicense:MITStargazers:68Issues:4Issues:38

DOMClobbering

DOM Clobbering Wiki, Browser Testing, and Payload Generation

Language:JavaScriptLicense:GPL-3.0Stargazers:36Issues:3Issues:6
Language:PythonStargazers:7Issues:0Issues:0