Highlights
- Pro
-
pfzf Public
fzf for yanking code/workspace context for LLM workflows.
-
gau Public
Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.
-
trufflehog Public
Forked from trufflesecurity/trufflehogFind and verify credentials
-
upload-scanner Public
Forked from PortSwigger/upload-scannerHTTP file upload scanner for Burp Proxy
-
theftfuzzer Public
TheftFuzzer is a tool that fuzzes Cross-Origin Resource Sharing implementations for common misconfigurations.
-
subjs Public archive
Fetches javascript file from a list of URLS or subdomains.
-
-
secretz Public
secretz, minimizing the large attack surface of Travis CI
-
-
Fast web fuzzer written in Go
-
-
-
-
230-OOB Public
An Out-of-Band XXE server for retrieving file contents over FTP.
-
certspotter Public
Forked from SSLMate/certspotterCertificate Transparency Log Monitor
-
-
-
sslc2 Public
Simple C&C example in assembly that retrieves commands from the Organizational Unit (OU) field in an SSL certificate
-
-
brute53 Public
A tool to bruteforce nameservers when working with subdomain delegations to AWS.
-
otxurls Public archive
Fetch known urls from AlienVault's Open Threat Exchange for given hosts
-
-
jenkinz Public
jenkinz is a tool to retrieve every build for every job ever created and run on a given Jenkins instance.
-
rlyCTF Public
rlyCTF (relay CTF) challenge to emulate real-world SSRF attacks.
-
-
-
color Public
Forked from fatih/colorColor package for Go (golang)
-
-
ds_storescanner Public
Forked from internetwache/ds_storescannerA tool to scan for .DS_Store files on webservers