03 Aug 2026
HTML
★ 12
Reconal is an advanced OSINT reconnaissance framework designed to streamline and automate over 70 Google dorks and detailed infrastructure analysis via a native desktop application. Key features include a zero-config experience for end users, a diverse range of recon modules covering cloud services, infrastructure configurations, and API discovery, as well as a robust command-line interface for terminal usage, ensuring no external exposure during operations.
03 Aug 2026
Java
★ 220
PyCript is a Burp Suite extension designed for encrypting and decrypting HTTP requests, responses, and WebSocket messages, catering to both manual and automated application penetration testing. It enables the creation of custom encryption and decryption logic utilizing multiple programming languages, thus allowing users extensive flexibility for tailored security implementations. Notable features include automatic request encryption, decryption of multiple requests, and the ability to manipulate encrypted traffic seamlessly within Burp Suite.
03 Aug 2026
Go
★ 63
Pinakastra is an AI-powered penetration testing framework designed for automated reconnaissance and exploitation, specifically tailored for penetration testers and bug bounty hunters. It features extensive capabilities for subdomain discovery, live host probing, URL analysis, and active exploitation of vulnerabilities like XSS and SQL injection, enhanced by AI-driven vulnerability detection and smart payload generation to minimize false positives. The tool also generates customizable reports in various formats, thereby streamlining the assessment process and improving efficiency in security testing.
03 Aug 2026
Shell
★ 218
Pentest Lab is a Docker Compose-based local pentesting environment that sets up multiple victim services alongside a Kali Linux attacker service. Its primary use case is to facilitate penetration testing and security assessments through a variety of pre-configured applications like Juice Shop and DVWA, and it includes a Heimdall interface for easy navigation of services. Notable features include automated dependency checks, customizable service configurations, and integrated monitoring capabilities using Grafana and Prometheus.
03 Aug 2026
Go
★ 34
PathFinder v1.1.0 is a military-grade web path discovery tool designed for professional penetration testing, featuring a real-time TUI dashboard and animated pathfinding visualization. Its notable capabilities include adaptive splash screens, live redirect tracking, recursive directory scanning, and the ability to export detailed pentest reports in multiple formats, all optimized for performance with high request rates and low resource usage. PathFinder is particularly distinguished by its animation of breadth-first search algorithm solving unique mazes, providing intuitive visual feedback during scans.
03 Aug 2026
★ 209
One-Liner OSINT is a command-line tool that provides a comprehensive collection of one-liner commands specifically designed for efficient Open-Source Intelligence gathering. Its primary use case is to automate the extraction of valuable information from public sources, including email addresses, social media profiles, and personal data, catering to security researchers, bug bounty hunters, and ethical hackers. Notable features include the ability to find personal information across various platforms and the use of specialized search queries for targeted data retrieval.
03 Aug 2026
Shell
★ 15
nucleihubquery is a bash utility designed to extract and organize search dorks from the nucleihub-templates YAML collection. Its primary use case is to facilitate reconnaissance by generating targeted search queries for multiple asset discovery platforms, enabling users to run structured scans based on vulnerability templates. Notable features include deduplication of queries, generation of severity-based outputs per provider, and a straightforward integration with standard Unix utilities.
03 Aug 2026
★ 84
The Nuclei-MonaCodeScanner repository provides a set of custom Nuclei templates focused on source code security analysis, targeting vulnerabilities such as hardcoded secrets, configuration leaks, debug routes, and exposure of sensitive files. Designed for use in Static Application Security Testing (SAST) and CI/CD pipelines, these templates facilitate the identification of OWASP Top 10 vulnerability patterns within source code, enhancing security assessments and red team activities.
03 Aug 2026
JavaScript
★ 12
NarrowX is a specialized browser extension designed for bug bounty hunters and security engineers that facilitates the extraction of endpoints, parameters, and sensitive indicators from JavaScript and network activity. Notable features include advanced inline and external JavaScript parsing, network request capturing, and automatic extraction capabilities using safe synthetic interactions, all while maintaining user privacy through local processing. Additionally, it supports scope filtering across multiple domains/subdomains to refine focus on specific targets.
03 Aug 2026
Python
★ 35
MongoBleed is a high-performance proof-of-concept scanner designed to identify vulnerable MongoDB instances affected by CVE-2025-14847, a pre-authentication heap memory disclosure vulnerability. Utilizing asynchronous I/O with Python's asyncio, the tool efficiently scans large network ranges, ensuring precise detection and minimal false positives by validating response lengths against the requested leak size, while automatically logging vulnerable targets. Additionally, it requires no external dependencies, making it straightforward to deploy in authorized security testing environments.
03 Aug 2026
★ 60
Meta-Owned-IT-Assets is a reconnaissance tool designed to assist security researchers in identifying and cataloging interesting IT assets owned by Meta Platforms, Inc. The repository aggregates data on various subdomains and applications used by Meta, highlighting potential vulnerabilities primarily in client-side and business logic contexts. Key features include detailed asset information, methodologies for asset discovery, and the utilization of multiple online reconnaissance tools like Shodan and DNSDumpster for thorough examination.
03 Aug 2026
★ 96
Learn250 is an educational resource aimed at documenting a 250-day journey of learning various cybersecurity topics, particularly focused on penetration testing and mobile application security. Its notable features include detailed write-ups, blog posts, and video tutorials covering practical techniques such as HTTP request smuggling, SSL pinning bypass, and iOS and Android pentesting strategies. This repository serves as both a learning tool and a structured guide for individuals seeking to enhance their cybersecurity skills.
03 Aug 2026
★ 13
The JWT Authentication Bypass tool demonstrates the exploitation of a vulnerability where the server fails to verify the signature of JSON Web Tokens (JWTs), allowing attackers to forge tokens and impersonate users, including administrators. Its primary use case is for bug bounty hunters and web security professionals to illustrate how improper JWT implementation can lead to unauthorized access to sensitive application areas, such as admin panels. Notable features include detailed step-by-step instructions for executing the exploit using tools like Burp Suite and JWT Inspector.
03 Aug 2026
JavaScript
★ 11
JS-endpoint-extractor is a JavaScript tool designed to extract endpoints from minified scripts by utilizing a bookmarklet. Users can easily add a bookmark, paste the minified URL, and activate the bookmark on a webpage to retrieve the JavaScript endpoints, streamlining the process of analyzing web scripts for security or development purposes. Notable features include user-friendly bookmark integration and minimal setup requirements.
03 Aug 2026
Shell
★ 10
IP-Vortex is an advanced IP rotation tool designed for security professionals, enabling anonymous security testing by frequently changing public IP addresses. Its primary use case is to facilitate fuzzing and vulnerability scanning while avoiding IP-based rate limiting, featuring automatic IP rotation, timed intervals, multi-interface support, and optional MAC address randomization. Notable features include comprehensive logging, network status monitoring, and seamless integration with security testing workflows.
03 Aug 2026
Python
★ 22
InstaRecon is an open-source intelligence (OSINT) tool specifically designed for gathering publicly available information from Instagram profiles, aimed at cybersecurity professionals and ethical hackers. It features user intelligence gathering, engagement analysis, and the ability to extract detailed account metrics, business intelligence, and public contact information. The tool operates across multiple platforms, supports automatic dependency installation, and requires users to provide a valid Instagram session ID for functionality.
03 Aug 2026
★ 22
Hacker101 CTF Solutions is a comprehensive repository that provides detailed walkthroughs and solutions for challenges encountered in the Hacker101 Capture The Flag (CTF) platform, focusing on web application security vulnerabilities. Key features include a structured organization with solution documentation and supporting screenshots for each challenge, as well as coverage of various attack vectors such as XSS, SQL injection, and permission issues. This educational tool is aimed at both novices and experienced individuals seeking to improve their penetration testing skills through practical, hands-on experience.
03 Aug 2026
Go
★ 41
grep-backURLs is an automated web security tool designed for extracting sensitive information during bug hunting by enumerating subdomains and analyzing Wayback Machine URLs. It leverages the subfinder tool for subdomain discovery and utilizes grep to filter results based on user-defined keywords, providing outputs in HTML, JSON, and Markdown formats. Key features include customizable configurations, concurrency control, and automatic report generation, effectively streamlining the process of credential discovery.
03 Aug 2026
Shell
★ 35
The github-scanner-local tool enables users to locally scan all repositories of a specified GitHub organization. Its primary use case is to identify and analyze URLs within the repositories, facilitating the detection of broken links and dependency management. Notable features include repository cloning, URL extraction, and status code validation for the identified links, along with the capability to search for specific strings across all cloned repositories.
03 Aug 2026
Python
★ 31
ghmon is a command-line security scanning tool designed to identify leaked secrets in GitHub and GitLab repositories by utilizing TruffleHog for in-depth scanning. Its primary use case is for DevOps and security teams to maintain secure code practices through automated discovery of repositories, continuous monitoring, and multi-platform notifications. Notable features include intelligent filtering of findings, automated token rotation, and comprehensive logging capabilities, making it suitable for both one-time scans and ongoing security assessments.
03 Aug 2026
JavaScript
★ 65
FBack is a command-line tool designed for generating target-specific wordlists to aid in fuzzing backup files. Its primary use case is for security professionals and penetration testers, featuring customizable pattern generation using URL components, date ranges, and various extensions for efficient wordlist creation. Notable features include fast processing, flexible JSON configuration, and the ability to support multiple sources for wordlists and extensions, optimizing it for diverse testing scenarios.
03 Aug 2026
Go
★ 496
Exif Looter is a command-line utility designed to analyze and manipulate image metadata, specifically EXIF data. Its primary use case includes analyzing individual images or entire directories for metadata extraction, as well as removing metadata to enhance privacy. Notable features include piping functionality for integration with other tools, the ability to extract GPS coordinates for mapping, and comprehensive support for various image formats.
03 Aug 2026
Python
★ 20
EWE (Execution Workflow Engine) is a robust automation tool designed for executing tasks in structured workflows using JSON or YAML files, ideal for automated reconnaissance and tool orchestration. Key features include parallel task execution, conditional task execution, real-time logging, and an interactive CLI mode for live task management. It facilitates efficient automation by supporting dynamic placeholders and providing both silent and interactive modes for flexibility in various operational environments.
03 Aug 2026
HTML
★ 20
Elite Google Dorks Search by Biscuit is a curated set of advanced Google search queries designed to uncover hidden information and vulnerabilities on the web, primarily targeting cybersecurity professionals and ethical hackers. Notable features include a selection of smart and improved dorks that enhance search effectiveness and a user-friendly interface for easy application. The tool enables users to efficiently identify security weaknesses by utilizing specific search patterns directly in Google.
03 Aug 2026
★ 11
CTF-to-Pentest is a guide that emphasizes the transition from a Capture the Flag (CTF) mindset to a penetration testing (pentest) approach, highlighting how common vulnerabilities like SQL injection and remote code execution must be handled with precision and discipline in real-world scenarios. It provides insights on translating CTF techniques into practical, low-impact strategies that prioritize thorough reporting over noise generation. Noteworthy features include personalized methods for vulnerability probing, safe proof-of-concept recommendations, and real-world case studies showcasing vulnerabilities found in high-value companies.