A list of useful payloads and bypass for Web Application Security and Pentest/CTF
-
Updated
Aug 27, 2026 - Python
A bug bounty program is a deal offered by many websites, organizations and software developers by which individuals can receive recognition and compensation for reporting bugs, especially those pertaining to security exploits and vulnerabilities.
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Web path scanner
The recursive internet scanner for hackers. 🧡
OneForAll是一款功能强大的子域收集工具
The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
Scanning APK file for URIs, endpoints & secrets.
A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference
Automated Αll-in-One OS command injection exploitation tool.
A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise identity + infrastructure attack matrices.
💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp Collaborator or Interact.sh
Knock Subdomain Scan
pagodo (Passive Google Dork) - Automate Google Hacking Database scraping and searching
Automated NoSQL database enumeration and web application exploitation tool.
A collection of custom security tools for quick needs.
Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing
Flutter Reverse Engineering Framework
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...