My Main App Hacking CheckList
☆35Jun 20, 2026Updated 2 months ago
Alternatives and similar repositories for Main-App-Hacking-CheckList
Users that are interested in Main-App-Hacking-CheckList are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Stealth hybrid URL mapper☆31May 1, 2026Updated 4 months ago
- ☆79May 5, 2025Updated last year
- Burp Suite extension — passively detects secrets, API keys, credentials, JWTs & PII in HTTP traffic. 160+ detection rules, bulk scan, ent…☆54Aug 24, 2026Updated 2 weeks ago
- Here's an updated Google Dorking list for 2025 Bug Bounty Hunting, incorporating new patterns and, the latest trends.☆21Apr 26, 2025Updated last year
- A tool for detecting subdomain takeover vulnerabilities by checking DNS records☆34May 28, 2026Updated 3 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- TokenTwin Checker — Dual Token BAC/IDOR Tester for Burp Suite☆97Aug 24, 2026Updated 2 weeks ago
- Burp Suite extension for cross-identity & cross-tenant access-control testing — BAC, IDOR, BOLA, and privilege escalation.☆61Jul 12, 2026Updated 2 months ago
- BountyLens MCP server — connect Claude Code to your Hunter Tracker☆64Jun 22, 2026Updated 2 months ago
- Replay any request as another user to find IDOR/BOLA/BFLA, right in the browser.☆29Jun 16, 2026Updated 2 months ago
- SSRFHunter☆18Jan 17, 2026Updated 7 months ago
- 0xJS is an AI-powered JavaScript Security Tool☆67Apr 16, 2026Updated 4 months ago
- xnew is a fast, low-memory CLI that appends only unique lines to files. Built in Go for large datasets, it streams input efficiently and …☆30May 23, 2026Updated 3 months ago
- Burp Suite extension + port-based highlighter: dedupes HTTP history into a live unique-request feed and color-codes attacker/victim traff…☆13Aug 14, 2026Updated 3 weeks ago
- One-command Docker deployment wizard for BugTraceAI — interactive setup, 3 deployment modes, auto-configuration☆34Sep 2, 2026Updated last week
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- A curated collection of my security research and bug bounty writeups, documenting real-world vulnerabilities, exploitation methods☆26Jul 15, 2026Updated last month
- A simple HAR-based JavaScript recon automation kit for organizing JS files, endpoints, secrets, and gf-filtered attack surface during bug…☆18May 20, 2026Updated 3 months ago
- API-Pentesting-Checklist☆29Feb 27, 2023Updated 3 years ago
- Chrome DevTools HTTP workbench with built-in AI.☆19Dec 9, 2025Updated 9 months ago
- ☆96May 11, 2026Updated 4 months ago
- ☆39Sep 5, 2026Updated last week
- A bash script that extracts `shodan-query, google-query, censys-query, fofa-query, hunter-query, zoomeye-query` in nucleihub-templates.☆15Feb 17, 2026Updated 6 months ago
- A python-based vulnerability scanner designed to identify open redirect flaws in website applications.☆26Mar 15, 2026Updated 5 months ago
- Active Directory forensic framework☆16May 18, 2026Updated 3 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A Python tool to resolve domains to IPs, fetch related CVEs, and display open ports☆17Nov 21, 2025Updated 9 months ago
- How To approach recon on real targets — from passive enumeration to origin IP discovery. Covers tools, automation, and the logic behind e…☆402Jul 5, 2026Updated 2 months ago
- A comprehensive WordPress vulnerability scanner and exploitation framework for authorized penetration testing. This tool automatically de…☆75May 21, 2026Updated 3 months ago
- CVE-2026-63030, CVE-2026-60137, wp2shell scanner☆63Jul 18, 2026Updated last month
- Enhanced Burp Suite extension for finding links and sensitive data in JavaScript files☆26May 10, 2026Updated 4 months ago
- A Chrome extension that watches your HackerOne reports and alerts you when their status changes. Its main reason to exist is internal act…☆15Jul 3, 2026Updated 2 months ago
- Web2 bug bounty Agent Skill — evidence-based, no AI slop. Covers 18 vulnerability classes across HackerOne, Bugcrowd, Intigriti, and YesW…☆71Feb 21, 2026Updated 6 months ago
- JS+ is a browser extension that captures JS URLs from specified domains and scans them with AI.☆22Mar 16, 2026Updated 5 months ago
- Collection of scripts and tools used during bug bounty work. This will be the location of my automation scripts created for my own person…☆153Dec 18, 2025Updated 8 months ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- ☆394Aug 30, 2026Updated 2 weeks ago
- take a list of resolved subdomains and output any corresponding CNAMES en masse.☆18Jan 29, 2026Updated 7 months ago
- ex-redirect — An automated open redirect scanner using Wayback Machine archives. Supports subdomain grouping, live URL filtering, and Wor…☆15May 9, 2025Updated last year
- This website is dedicated to Awesome.☆13Apr 23, 2020Updated 6 years ago
- ☆264Dec 10, 2025Updated 9 months ago
- The malicious IdP you were looking for. A weaponized Single Sign-On (SSO) Identity Provider (IdP) for security testing of OIDC and SAML 2…☆65Jul 23, 2026Updated last month
- Caido plugin to send HTTP requests to external CLI security tools with preview, batch execution, and live output☆24Aug 20, 2026Updated 3 weeks ago