A curated collection of my security research and bug bounty writeups, documenting real-world vulnerabilities, exploitation methods
☆26Jul 15, 2026Updated 2 weeks ago
Alternatives and similar repositories for security-writeups
Users that are interested in security-writeups are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An obsessive, expert-tier knowledge base + AI skill system for professional bug bounty hunting, security research, and penetration testin…☆27Apr 25, 2026Updated 3 months ago
- xnew is a fast, low-memory CLI that appends only unique lines to files. Built in Go for large datasets, it streams input efficiently and …☆28May 23, 2026Updated 2 months ago
- Automated Cloud Misconfiguration Testing☆26Jun 20, 2025Updated last year
- A simple HAR-based JavaScript recon automation kit for organizing JS files, endpoints, secrets, and gf-filtered attack surface during bug…☆18May 20, 2026Updated 2 months ago
- 🎯 Chrome Extension - Passive scanner for Dependency Confusion vulnerabilities in npm/PyPI packages☆37Jan 31, 2026Updated 6 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- ☆78May 5, 2025Updated last year
- TokenTwin Checker — Dual Token BAC/IDOR Tester for Burp Suite☆88Jun 28, 2026Updated last month
- ☆38Updated this week
- My Main App Hacking CheckList☆33Jun 20, 2026Updated last month
- ☆96May 11, 2026Updated 2 months ago
- Here's an updated Google Dorking list for 2025 Bug Bounty Hunting, incorporating new patterns and, the latest trends.☆15Apr 26, 2025Updated last year
- Stealth hybrid URL mapper☆26May 1, 2026Updated 3 months ago
- The "Let's-defend-solution" directory contains the answers to all paths of the Let's Defend platform that were saved by the creator 8 mon…☆13Apr 27, 2023Updated 3 years ago
- My ATO Via Password Reset Methodology☆53May 13, 2026Updated 2 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Passive JavaScript reconnaissance for penetration testers — bridging Burp Suite traffic into structured, AST-based analysis in VSCode.☆36Feb 5, 2026Updated 5 months ago
- CLAUDE.md configs and skills I use for bug bounty hunting with Claude Code☆29Apr 14, 2026Updated 3 months ago
- A powerful subdomain enumeration tool that aggregates data from multiple sources to create comprehensive lists of root subdomains.☆51May 2, 2026Updated 3 months ago
- CVE-2026-63030, CVE-2026-60137, wp2shell scanner☆46Jul 18, 2026Updated 2 weeks ago
- Spec-driven bug bounty writeups and real world security failures.☆42Jul 5, 2026Updated 3 weeks ago
- AISecLists - Your AI Red Teaming Arsenal. Discover a curated collection of prompt lists for diverse AI security assessments, including LL…☆16Jan 18, 2025Updated last year
- SSRFHunter☆18Jan 17, 2026Updated 6 months ago
- 多维度,UI/UX友好的Burp suite越权漏洞检测插件☆34Jul 26, 2026Updated last week
- A very simple AEM detector written in rust.🦀☆20Jun 27, 2023Updated 3 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Use AI to install penetration testing tool suites in one click.☆117Oct 5, 2025Updated 9 months ago
- An exotic service bruteforce tool.☆14Apr 12, 2025Updated last year
- Process URLs and remove duplicate query parameters.☆27Mar 19, 2024Updated 2 years ago
- A bash script that extracts `shodan-query, google-query, censys-query, fofa-query, hunter-query, zoomeye-query` in nucleihub-templates.☆15Feb 17, 2026Updated 5 months ago
- PoC for CVE-2026-48907 - Joomla! JCE extension < 2.9.99.5 unauthenticated RCE☆15Jun 11, 2026Updated last month
- This lab is for **EDUCATIONAL PURPOSES ONLY**. Use it responsibly and only on systems you own or have explicit permission to test. Do not…☆21Feb 20, 2026Updated 5 months ago
- Search for all leaked keys/secrets using one regex! bugbounty☆242Mar 29, 2025Updated last year
- CVE-2025-55182-bypass-waf☆31Jan 8, 2026Updated 6 months ago
- Bug bounty methodology, checklists, and hunting notes.☆30Jul 10, 2026Updated 3 weeks ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A cheatsheet for common JavaScript sources and sinks that lead to potential vulnerabilities.☆65Jun 13, 2023Updated 3 years ago
- Chrome DevTools HTTP workbench with built-in AI.☆19Dec 9, 2025Updated 7 months ago
- Replay any request as another user to find IDOR/BOLA/BFLA, right in the browser.☆26Jun 16, 2026Updated last month
- Extensión de Burp Suite que incorpora detección pasiva de vulnerabilidades mediante inteligencia artificial.☆17Jun 27, 2026Updated last month
- Web File Manager☆11Updated this week
- 🐐 GoatOS - A lightweight Linux distribution focused on Web & API penetration testing. Built on Debian with GNOME, featuring nuclei, http…☆18Dec 26, 2025Updated 7 months ago
- Find The Admin Panel & SQL Injection Endpoints, Using Google Dorks !!!☆30Nov 15, 2024Updated last year