A list of useful payloads and bypass for Web Application Security and Pentest/CTF
-
Updated
Jan 12, 2023 - Python
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
A collection of hacking tools, resources and references to practice ethical hacking.
API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
A list of resources for those interested in getting started in bug bounties
K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)
Program for determining types of files for Windows, Linux and MacOS.
A curated list of awesome infosec courses and training resources.
Next generation web scanner
暂停维护 | ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup
Ladon modular hacking framework penetration scanner & Cobalt strike, Ladon 10.1 has 180 built-in modules, including information collection / surviving host / port scanning / service identification / password blasting / vulnerability detection / vulnerability utilization. Vulnerability detection includes ms17010 / smbghost / Weblogic / ActiveMQ
A fast, simple, recursive content discovery tool written in Rust.
All about bug bounty (bypasses, payloads, and etc)
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password
Add a description, image, and links to the pentest topic page so that developers can more easily learn about it.
To associate your repository with the pentest topic, visit your repo's landing page and select "manage topics."