Tool to find the real IP behind CDNs/WAFs like cloudflare using passive recon by retrieving the favicon hash. For the same hash value, all the possible IPs, PORTs and SSL/TLS Certs are searched to validate the target in-scope.
☆183Jan 6, 2021Updated 5 years ago
Alternatives and similar repositories for Lilly
Users that are interested in Lilly are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- SubzzZ to find possible subdomains using passive recon. Tool also support Permutations, Mutations, Alterations.☆38Mar 7, 2021Updated 5 years ago
- This extension redacts potentially sensitive header and parameter values from requests using Shannon Entropy analysis.☆13Dec 29, 2020Updated 5 years ago
- gup aka Get All Urls parameters to create wordlists for brute forcing parameters.☆18Dec 4, 2021Updated 4 years ago
- Random utilities from my security projects that might be useful to others☆182Jan 26, 2025Updated last year
- A FireBase DataBase TakeOver Tool along with POC Generator☆36Sep 16, 2021Updated 4 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Vulnerability Cheatsheet☆54Apr 22, 2022Updated 4 years ago
- A tool to perform permutations, mutations and alteration of subdomains in golang.☆160Nov 24, 2023Updated 2 years ago
- Get all possible href | src | url from target url or domain☆40Aug 5, 2020Updated 6 years ago
- Tool to find JavaScript files on Websites☆531Nov 2, 2023Updated 2 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆134Feb 19, 2021Updated 5 years ago
- Automation for javascript recon in bug bounty.☆1,108Sep 9, 2023Updated 2 years ago
- ☆375Aug 20, 2021Updated 5 years ago
- A tool to check a bunch of URLs that contain reflecting params.☆602Aug 4, 2024Updated 2 years ago
- Signatures for jaeles scanner by @j3ssie☆117Apr 20, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A GO module to get domain name from SSL certificates when an IP address is provided.☆33Apr 14, 2023Updated 3 years ago
- The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices☆649Jul 7, 2025Updated last year
- Removes duplicate entries from a file, resulting in only unique parameter combinations. Useful for parsing waybackurls and making recon m…☆12May 31, 2020Updated 6 years ago
- Urls de-duplication tool for better recon.☆145Apr 13, 2026Updated 4 months ago
- Hidden parameters discovery suite☆225Nov 14, 2022Updated 3 years ago
- A custom built DNS bruteforcer with multi-threading, and handling of bad resolvers.☆57Apr 25, 2022Updated 4 years ago
- OWASP Amass data source scripts (assetfinder, findomain, github, subfinder)☆106Oct 18, 2020Updated 5 years ago
- ⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)☆1,024May 21, 2025Updated last year
- S3 Recon tips and tricks collected from different resources,Sorry if i missed to mention all resources owners☆28Nov 13, 2021Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- BugBounty , sort and delete duplicates param value without missing original value☆22Jul 31, 2021Updated 5 years ago
- ☆38Nov 27, 2020Updated 5 years ago
- A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..e…☆1,193Apr 3, 2026Updated 5 months ago
- Bucky (An automatic S3 bucket discovery tool)☆197Jan 6, 2022Updated 4 years ago
- Burp extension to create target specific and tailored wordlist from burp history.☆263Dec 8, 2021Updated 4 years ago
- Fetches javascript file from a list of URLS or subdomains.☆862Jul 22, 2025Updated last year
- IIS shortname scanner + bruteforce☆56Feb 18, 2024Updated 2 years ago
- Urls status code & content length checker☆146Oct 1, 2020Updated 5 years ago
- 403/401 Bypass Methods + Bash Automation + Your Support ;)☆1,668Jun 6, 2022Updated 4 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- ☆750Jun 26, 2024Updated 2 years ago
- Gotator is a tool to generate DNS wordlists through permutations.☆534Jul 17, 2022Updated 4 years ago
- ☆57Sep 2, 2020Updated 6 years ago
- qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.☆301Feb 12, 2023Updated 3 years ago
- Automation Recon tool which works with Large & Medium scopes. It performs a lot of tasks and gets back all the results in separated files…☆688Jul 15, 2024Updated 2 years ago
- ☆61Apr 8, 2021Updated 5 years ago
- Go scripts for checking API key / access token validity☆223Aug 3, 2021Updated 5 years ago