OSINT tool for discovering email addresses in known data breaches
A generic, spec-compliant, thorough implementation of the OAuth
A single archive of public exploit PoCs and vulnerability research
Check breached emails and find exposed passwords from public dumps
Bleeding edge django template focused on code quality and security
Utility for sending notifications, on demand and when commands finish
Automatic SQL injection and database takeover tool
High-performance reconnaissance and vulnerability scanning tool
Utilize all available CPU cores for accepting new client connections
A list of useful payloads and bypass for Web Application Security
Daily updated lists of cloud, bot, and service IP ranges
WAFW00F allows one to identify and fingerprint Web App Firewall
A TLS MITM proxy for Non-HTTP traffic, with support for TLS upgrades
Privacy and Security focused Segment-alternative, in Golang
AWS Encryption SDK
A tool that allows you to create vulnerable environments
Automation framework for reconnaissance and penetration testing tasks
A Burp Extension for GraphQL Security Testing
Alerta monitoring system
Skills for threat modeling, scanning, triage, patching, etc.
A Claude Code skill bundle for bug hunting
CTFs as you need them
Know the dangers of credential reuse attacks
With Django Hijack, admins can log in and work on behalf of others
Generate probable usernames from LinkedIn company employee lists