Dheerajmadhukar / LillyView external linksLinks
Tool to find the real IP behind CDNs/WAFs like cloudflare using passive recon by retrieving the favicon hash. For the same hash value, all the possible IPs, PORTs and SSL/TLS Certs are searched to validate the target in-scope.
☆184Jan 6, 2021Updated 5 years ago
Alternatives and similar repositories for Lilly
Users that are interested in Lilly are comparing it to the libraries listed below
Sorting:
- SubzzZ to find possible subdomains using passive recon. Tool also support Permutations, Mutations, Alterations.☆38Mar 7, 2021Updated 4 years ago
- Random utilities from my security projects that might be useful to others☆183Jan 26, 2025Updated last year
- gup aka Get All Urls parameters to create wordlists for brute forcing parameters.☆18Dec 4, 2021Updated 4 years ago
- A GO module to get domain name from SSL certificates when an IP address is provided.☆34Apr 14, 2023Updated 2 years ago
- A tool to check a bunch of URLs that contain reflecting params.☆599Aug 4, 2024Updated last year
- A tool to perform permutations, mutations and alteration of subdomains in golang.☆155Nov 24, 2023Updated 2 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆132Feb 19, 2021Updated 4 years ago
- The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices☆642Jul 7, 2025Updated 7 months ago
- This extension redacts potentially sensitive header and parameter values from requests using Shannon Entropy analysis.☆12Dec 29, 2020Updated 5 years ago
- Removes duplicate entries from a file, resulting in only unique parameter combinations. Useful for parsing waybackurls and making recon m…☆11May 31, 2020Updated 5 years ago
- Signatures for jaeles scanner by @j3ssie☆117Apr 20, 2024Updated last year
- This is a burp plugin that extracts keywords from response using regexes and test for reflected XSS on the target scope.☆74Nov 5, 2020Updated 5 years ago
- Tool to find JavaScript files on Websites☆526Nov 2, 2023Updated 2 years ago
- Gotator is a tool to generate DNS wordlists through permutations.☆503Jul 17, 2022Updated 3 years ago
- ☆38Nov 27, 2020Updated 5 years ago
- Urls de-duplication tool for better recon.☆145May 29, 2025Updated 8 months ago
- Automation for javascript recon in bug bounty.☆1,067Sep 9, 2023Updated 2 years ago
- ☆105Oct 18, 2020Updated 5 years ago
- Hidden parameters discovery suite☆225Nov 14, 2022Updated 3 years ago
- IIS shortname scanner + bruteforce☆54Feb 18, 2024Updated last year
- Vulnerability Cheatsheet☆54Apr 22, 2022Updated 3 years ago
- Get all possible href | src | url from target url or domain☆40Aug 5, 2020Updated 5 years ago
- ☆375Aug 20, 2021Updated 4 years ago
- Automation Recon tool which works with Large & Medium scopes. It performs a lot of tasks and gets back all the results in separated files…☆684Jul 15, 2024Updated last year
- Burp extension to create target specific and tailored wordlist from burp history.☆255Dec 8, 2021Updated 4 years ago
- OpenBugBounty - https://www.openbugbounty.org/ programs list☆23Mar 15, 2021Updated 4 years ago
- Given a list of domains, you resolve them and get the IP addresses.☆47Mar 2, 2022Updated 3 years ago
- ⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)☆935May 21, 2025Updated 8 months ago
- A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..e…☆1,021Jun 24, 2024Updated last year
- Cross Origin Resource Sharing MisConfiguration Scanner☆173Nov 17, 2021Updated 4 years ago
- A FireBase DataBase TakeOver Tool along with POC Generator☆35Sep 16, 2021Updated 4 years ago
- ☆59Apr 8, 2021Updated 4 years ago
- Nuclei Templates - Here you will find the templates I use while hunting☆120Sep 27, 2021Updated 4 years ago
- ☆299Jul 16, 2022Updated 3 years ago
- Search for secrets inside user data attached to EC2 instances on multiple AWS accounts☆16Jun 19, 2024Updated last year
- ☆13Feb 26, 2021Updated 4 years ago
- Fetches javascript file from a list of URLS or subdomains.☆834Jul 22, 2025Updated 6 months ago
- ☆695Jul 4, 2022Updated 3 years ago
- Automating XSS using Bash☆361Jan 27, 2026Updated 2 weeks ago