Asset inventory dataset for public bug bounty program targets
A Claude Code skill bundle for bug hunting
ezXSS is an easy way for penetration testers and bug bounty hunters
Skills for threat modeling, scanning, triage, patching, etc.
The SpotBugs plugin for security audits of Java web applications
Cloud native, security-first, API security for your infrastructure
Bug-fix-only libev port of shadowsocks
Fast and customizable vulnerability scanner based on simple YAML
Fast passive subdomain enumeration tool
Scalable fuzzing infrastructure
Automate search engine dorking across hundreds of websites
Automated framework for running pentesting tools and workflows
Command-line OSINT and reconnaissance tool without API keys
Discover exposed internet hosts using multiple search engine APIs
Real-time GitHub monitor that detects leaked API keys and secrets
XRay for recon, mapping and OSINT gathering from public networks
Fast open source tool for discovering and monitoring domain subdomains
IBM's TPM 2.0 TSS
An advanced file manager with qss themes and iso and folder previews
Mine parameterized URLs from web archives for security testing
Security-focused static analysis for the Phoenix Framework
OneForAll is a powerful subdomain collection tool
Fast Go web crawler for discovering URLs and web app endpoints
An HTTP toolkit for security research