Starred repositories
📚 Freely available programming books
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
The 30 Days of Python programming challenge is a step-by-step guide to learn the Python programming language in 30 days. This challenge may take more than 100 days. Follow your own pace. These vide…
Automatic SQL injection and database takeover tool
Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any other CA that uses the ACME protocol.
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
Open-source AI hackers to find and fix your app’s vulnerabilities.
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
E-mails, subdomains and names Harvester - OSINT
Impacket is a collection of Python classes for working with network protocols.
The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWA…
Incredibly fast crawler designed for OSINT.
Osintgram is a OSINT tool on Instagram. It offers an interactive shell to perform analysis on Instagram account of any users by its nickname
Scapy: the Python-based interactive packet manipulation program & library.
📝 A text file containing 479k English words for all your dictionary/word-based projects e.g: auto-completion / autosuggestion
Fast subdomains enumeration tool for penetration testers
The recursive internet scanner for hackers. 🧡
A swiss army knife for pentesting networks
📱 objection - runtime mobile exploration
HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug b…
Cybersecurity AI (CAI), the framework for AI Security
Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥
🐍 A toolkit for testing, tweaking and cracking JSON Web Tokens
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️