Asset inventory dataset for public bug bounty program targets
Skills for threat modeling, scanning, triage, patching, etc.
The SpotBugs plugin for security audits of Java web applications
Bug-fix-only libev port of shadowsocks
Fast passive subdomain enumeration tool
Automate search engine dorking across hundreds of websites
Automated framework for running pentesting tools and workflows
Command-line OSINT and reconnaissance tool without API keys
Discover exposed internet hosts using multiple search engine APIs
Real-time GitHub monitor that detects leaked API keys and secrets
XRay for recon, mapping and OSINT gathering from public networks
Fast open source tool for discovering and monitoring domain subdomains
Mine parameterized URLs from web archives for security testing
Fast Go web crawler for discovering URLs and web app endpoints
Simple Password Manager
A network stress testing application