Asset inventory dataset for public bug bounty program targets
A Claude Code skill bundle for bug hunting
ezXSS is an easy way for penetration testers and bug bounty hunters
Cloud native, security-first, API security for your infrastructure
Skills for threat modeling, scanning, triage, patching, etc.
The SpotBugs plugin for security audits of Java web applications
Fast and customizable vulnerability scanner based on simple YAML
Bug-fix-only libev port of shadowsocks
Fast passive subdomain enumeration tool
Scalable fuzzing infrastructure
Automate search engine dorking across hundreds of websites
Command-line OSINT and reconnaissance tool without API keys
OSINT fuzzing tool using Google dorks to find exposed resources
Fast open source tool for discovering and monitoring domain subdomains
Automated framework for web application reconnaissance and scanning
Discover exposed internet hosts using multiple search engine APIs
Automated framework for running pentesting tools and workflows
Search GitHub for leaked API keys, credentials, and exposed secrets
Automated framework for domain reconnaissance and vulnerability scans.
Real-time GitHub monitor that detects leaked API keys and secrets
XRay for recon, mapping and OSINT gathering from public networks
IBM's TPM 2.0 TSS
An advanced file manager with qss themes and iso and folder previews
Mine parameterized URLs from web archives for security testing