prime-hacker's starred repositories

SecLists

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

hiring-without-whiteboards

⭐️ Companies that don't have a broken hiring process

Language:JavaScriptLicense:MITStargazers:45729Issues:853Issues:0

RustScan

🤖 The Modern Port Scanner 🤖

Language:RustLicense:GPL-3.0Stargazers:14669Issues:134Issues:259

explainshell

match command-line arguments to their help text

Language:PythonLicense:GPL-3.0Stargazers:13244Issues:206Issues:278

ffuf

Fast web fuzzer written in Go

amass

In-depth attack surface mapping and asset discovery

Language:GoLicense:NOASSERTIONStargazers:12066Issues:214Issues:653

obsidian-releases

Community plugins list, theme list, and releases of Obsidian.

rengine

reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.

Language:HTMLLicense:GPL-3.0Stargazers:7506Issues:141Issues:865

fromthetransistor

From the Transistor to the Web Browser, a rough outline for a 12 week course

awesome-infosec

A curated list of awesome infosec courses and training resources.

can-i-take-over-xyz

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Language:PythonLicense:CC-BY-4.0Stargazers:4864Issues:127Issues:239

awesome-bug-bounty

A comprehensive curated list of available Bug Bounty & Disclosure Programs and Write-ups.

tbhm

The Bug Hunters Methodology

P4wnP1_aloa

P4wnP1 A.L.O.A. by MaMe82 is a framework which turns a Rapsberry Pi Zero W into a flexible, low-cost platform for pentesting, red teaming and physical engagements ... or into "A Little Offensive Appliance".

Language:JavaScriptLicense:GPL-3.0Stargazers:3775Issues:201Issues:327

retire.js

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

Language:JavaScriptLicense:NOASSERTIONStargazers:3690Issues:83Issues:259

interactsh

An OOB interaction gathering server and client library

InfoSec-Black-Friday

All the deals for InfoSec related software/tools this Black Friday

bug-bounty-dorks

List of Google Dorks for sites that have responsible disclosure program / bug bounty program

Security_Engineer_Interview_Questions

Every Security Engineer Interview Question From Glassdoor.com

webshells

Various webshells. We accept pull requests for additions to this collection.

ctf-archives

CTF Archives: Collection of CTF Challenges.

Language:PythonLicense:MITStargazers:874Issues:23Issues:2

ReconAIzer

A Burp Suite extension to add OpenAI (GPT) on Burp and help you with your Bug Bounty recon to discover endpoints, params, URLs, subdomains and more!

fuzz4bounty

1337 Wordlists for Bug Bounty Hunting

study-bug-bounty

Beginner Guide to Bug Hunting

Web-App-Pentest-Checklist

A OWASP Based Checklist With 500+ Test Cases

bug-bounty-platforms

A community-powered collection of all known bug bounty platforms, vulnerability disclosure platforms, and crowdsourced security platforms currently active on the Internet.

Challenges_2023_Public

Files + Writeups for DownUnderCTF 2023 Challenges

Language:PythonStargazers:169Issues:10Issues:0

writeups

Writeups for vulnerable machines.

Language:HTMLStargazers:168Issues:5Issues:0