A curated collection of my security research and bug bounty writeups, documenting real-world vulnerabilities, exploitation methods
☆26Jul 15, 2026Updated last month
Alternatives and similar repositories for security-writeups
Users that are interested in security-writeups are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An obsessive, expert-tier knowledge base + AI skill system for professional bug bounty hunting, security research, and penetration testin…☆31Apr 25, 2026Updated 3 months ago
- xnew is a fast, low-memory CLI that appends only unique lines to files. Built in Go for large datasets, it streams input efficiently and …☆30May 23, 2026Updated 3 months ago
- Automated Cloud Misconfiguration Testing☆26Jun 20, 2025Updated last year
- A simple HAR-based JavaScript recon automation kit for organizing JS files, endpoints, secrets, and gf-filtered attack surface during bug…☆18May 20, 2026Updated 3 months ago
- 🎯 Chrome Extension - Passive scanner for Dependency Confusion vulnerabilities in npm/PyPI packages☆40Jan 31, 2026Updated 6 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ☆79May 5, 2025Updated last year
- TokenTwin Checker — Dual Token BAC/IDOR Tester for Burp Suite☆90Updated this week
- ☆39Jul 29, 2026Updated 3 weeks ago
- My Main App Hacking CheckList☆34Jun 20, 2026Updated 2 months ago
- ☆96May 11, 2026Updated 3 months ago
- Here's an updated Google Dorking list for 2025 Bug Bounty Hunting, incorporating new patterns and, the latest trends.☆19Apr 26, 2025Updated last year
- Stealth hybrid URL mapper☆31May 1, 2026Updated 3 months ago
- The "Let's-defend-solution" directory contains the answers to all paths of the Let's Defend platform that were saved by the creator 8 mon…☆13Aug 11, 2026Updated last week
- My ATO Via Password Reset Methodology☆54May 13, 2026Updated 3 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Passive JavaScript reconnaissance for penetration testers — bridging Burp Suite traffic into structured, AST-based analysis in VSCode.☆36Feb 5, 2026Updated 6 months ago
- CLAUDE.md configs and skills I use for bug bounty hunting with Claude Code☆30Apr 14, 2026Updated 4 months ago
- A powerful subdomain enumeration tool that aggregates data from multiple sources to create comprehensive lists of root subdomains.☆66May 2, 2026Updated 3 months ago
- CVE-2026-63030, CVE-2026-60137, wp2shell scanner☆54Jul 18, 2026Updated last month
- Spec-driven bug bounty writeups and real world security failures.☆42Jul 5, 2026Updated last month
- AISecLists - Your AI Red Teaming Arsenal. Discover a curated collection of prompt lists for diverse AI security assessments, including LL…☆16Jan 18, 2025Updated last year
- SSRFHunter☆18Jan 17, 2026Updated 7 months ago
- 多维度,UI/UX友好的Burp suite越权漏洞检测插件☆36Jul 26, 2026Updated 3 weeks ago
- A very simple AEM detector written in rust.🦀☆20Jun 27, 2023Updated 3 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Use AI to install penetration testing tool suites in one click.☆118Oct 5, 2025Updated 10 months ago
- An exotic service bruteforce tool.☆14Apr 12, 2025Updated last year
- Process URLs and remove duplicate query parameters.☆27Mar 19, 2024Updated 2 years ago
- This lab is for **EDUCATIONAL PURPOSES ONLY**. Use it responsibly and only on systems you own or have explicit permission to test. Do not…☆22Feb 20, 2026Updated 6 months ago
- A bash script that extracts `shodan-query, google-query, censys-query, fofa-query, hunter-query, zoomeye-query` in nucleihub-templates.☆15Feb 17, 2026Updated 6 months ago
- buffer overflow skeleton scripts, can be used for any TCP based socket flows.☆10Oct 14, 2020Updated 5 years ago
- PoC for CVE-2026-48907 - Joomla! JCE extension < 2.9.99.5 unauthenticated RCE☆15Jun 11, 2026Updated 2 months ago
- A curated list of Web3 Security materials and resources for Pentesters and Bug Hunters.☆21Jul 31, 2026Updated 3 weeks ago
- Search for all leaked keys/secrets using one regex! bugbounty☆241Mar 29, 2025Updated last year
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- CVE-2025-55182-bypass-waf☆31Jan 8, 2026Updated 7 months ago
- Bug bounty methodology, checklists, and hunting notes.☆34Jul 10, 2026Updated last month
- A cheatsheet for common JavaScript sources and sinks that lead to potential vulnerabilities.☆67Jun 13, 2023Updated 3 years ago
- Chrome DevTools HTTP workbench with built-in AI.☆19Dec 9, 2025Updated 8 months ago
- Replay any request as another user to find IDOR/BOLA/BFLA, right in the browser.☆27Jun 16, 2026Updated 2 months ago
- Extensión de Burp Suite que incorpora detección pasiva de vulnerabilidades mediante inteligencia artificial.☆17Updated this week
- Web File Manager☆11Jul 30, 2026Updated 3 weeks ago