Highlights
- Pro
-
-
Easy-to-use, customizable, high-quality secure code review skills for AI agents.
-
Easy-to-use, customizable, high-quality vulnerability management skills for AI agents.
-
threat-modeling-agent-skills Public
Easy-to-use, customizable, high-quality threat modeling skills for AI agents.
-
powershell-reverse-tcp Public
PowerShell scripts for communicating with a remote host.
-
chad Public
Search Google Dorks like Chad. / Broken link hijacking tool.
-
nagooglesearch Public
Not another Google searching tool.
-
nagooglesearch-playwright Public
Not another Google searching tool.
-
malware-apk Public
As a bug hunter, are your bug bounty reports getting rejected because you don't use a "malicious" Proof of Concept (PoC) app to exploit the vulnerabilities? I've got you covered!
-
auto-recon Public
Not another auto-reconnaissance framework.
-
browser-extension-automation Public
Run a browser extension in a sandboxed web browser and without any fear of corrupting or loosing your real data.
-
Work in progress...
-
Work in progress...
-
bot-safe-agents Public
A library for fetching a list of bot-safe user agents.
-
scrapy-scraper Public
Web crawler and scraper based on Scrapy and Playwright's headless browser.
-
php-reverse-shell Public
PHP shells that work on Linux OS, macOS, and Windows OS.
-
java-reverse-tcp Public
JAR, Java, and JSP shells that work on Linux OS, macOS, and Windows OS.
-
file-scraper Public
Scrape files for sensitive information, and generate an interactive HTML report. Based on Rabin2.
-
property-lister Public
Extract and convert property list files from SQLite database files and from other property list files.
-
forbidden Public
Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.
-
Work in progress...
-
amounts Public
Generate a wordlist to fuzz amounts or any other numerical values.
-
go-actions Public archive
Golang SAST workflows.
-
solidity-learning Public
Work in progress...
-
Work in progress...
-
xss-catcher Public
Simple API for storing all incoming XSS requests and various XSS templates.
-
dns-exfiltrator Public archive
Exfiltrate data with DNS queries. Based on CertUtil and NSLookup.
-
jwt-bf Public archive
Brute force a JWT token. Script uses multithreading.
-
mixaudit-sarif Public archive
Convert MixAudit's JSON formatted results to SARIF format.
-
python-actions Public archive
Python SAST workflows.