Robotshell's starred repositories

CrackMapExec

A swiss army knife for pentesting networks

Language:PythonLicense:BSD-2-ClauseStargazers:7478Issues:303Issues:541

keyhacks

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

KingOfBugBountyTips

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wish to influence Onelinetips and explain the commands, for the better understanding of new hunters..

Instagram-

Bruteforce attack for Instagram

Language:PythonLicense:MITStargazers:3963Issues:642Issues:0

GitTools

A repository with 3 tools for pwn'ing websites with .git repositories available

Language:ShellLicense:MITStargazers:3742Issues:89Issues:25

dalfox

🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.

awesome-mobile-security

An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.

fuzz.txt

Potentially dangerous files

TorBot

Dark Web OSINT Tool

Language:PythonLicense:NOASSERTIONStargazers:2658Issues:100Issues:102

RedTeam-OffensiveSecurity

Tools & Interesting Things for RedTeam Ops

Language:PythonLicense:MITStargazers:2086Issues:60Issues:0

JAWS

JAWS - Just Another Windows (Enum) Script

Language:PowerShellLicense:MITStargazers:1575Issues:42Issues:1

nginxpwner

Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.

Language:PythonLicense:Apache-2.0Stargazers:1363Issues:11Issues:6

hakrevdns

Small, fast tool for performing reverse DNS lookups en masse.

Language:GoLicense:MITStargazers:1351Issues:19Issues:9

weaponised-XSS-payloads

XSS payloads designed to turn alert(1) into P1

Bug-Bounty-Wordlists

A repository that includes all the important wordlists used while bug hunting.

uro

declutters url lists for crawling/pentesting

Language:PythonLicense:Apache-2.0Stargazers:1033Issues:17Issues:32

diva-android

DIVA Android - Damn Insecure and vulnerable App for Android

Language:JavaLicense:GPL-3.0Stargazers:915Issues:50Issues:7

bbscope

Scope gathering tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

Language:GoLicense:Apache-2.0Stargazers:870Issues:15Issues:41

symbiote

Your target's phone's front and back cameras📸 can be accessed by sending a link🔗.

Language:PythonLicense:MITStargazers:750Issues:18Issues:10

ovaa

Oversecured Vulnerable Android App

Language:JavaLicense:BSD-2-ClauseStargazers:608Issues:6Issues:4

Frack

Frack - Keep and Maintain your breach data

Language:PythonLicense:GPL-3.0Stargazers:283Issues:7Issues:1

urless

De-clutter a list of URLs

InsecureShop

An Intentionally designed Vulnerable Android Application built in Kotlin.

Language:KotlinLicense:MITStargazers:224Issues:11Issues:5

pivaa

Created by High-Tech Bridge, the Purposefully Insecure and Vulnerable Android Application (PIVAA) replaces outdated DIVA for benchmark of mobile vulnerability scanners.

Language:JavaLicense:GPL-3.0Stargazers:104Issues:5Issues:2

DVPA

Damn Vulnerable PHP Application (DVPA) - It is Lab Written in The PHP lang, Which Contains PHP Type Juggling - RCE Challenges

Language:PHPLicense:GPL-3.0Stargazers:31Issues:3Issues:1
Language:PythonStargazers:30Issues:0Issues:0

Android_install

Android Pentest Setup Environment

Language:ShellStargazers:28Issues:0Issues:0

Proxyshell-Exchange

Poc script for ProxyShell exploit chain in Exchange Server