A list of useful payloads and bypass for Web Application Security and Pentest/CTF
☆52Mar 30, 2021Updated 5 years ago
Alternatives and similar repositories for PayloadsAllTheThings
Users that are interested in PayloadsAllTheThings are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- This repository contains the PowerShell script for adding and removing the Sticky Key backdoor on Windows☆37May 18, 2020Updated 6 years ago
- Notes only☆21May 2, 2022Updated 4 years ago
- This cheasheet is aimed at the Red Teamers to help them find diffent tools and methods to create a Commmand and Control Server and exploi…☆86Nov 7, 2020Updated 5 years ago
- ☆158Mar 14, 2026Updated 3 months ago
- ☆28Jun 19, 2025Updated 11 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- ☆365Mar 14, 2026Updated 3 months ago
- ☆260Mar 14, 2026Updated 3 months ago
- ☆214Mar 14, 2026Updated 3 months ago
- ☆358Mar 14, 2026Updated 3 months ago
- This cheatsheet is aimed at the CTF Players and Beginners to help them understand Web Application Vulnerablity with examples.☆484Mar 14, 2026Updated 3 months ago
- ☆444Oct 23, 2022Updated 3 years ago
- This cheatsheet is aimed at the Red Teamers to help them understand the fundamentals of Credential Dumping (Sub Technique of Credential A…☆497Mar 14, 2026Updated 3 months ago
- This cheatsheet was created to assist Red Teamers and Penetration Testers in hunting down vulnerabilities using "Nmap."☆768May 29, 2026Updated 2 weeks ago
- This cheatsheet is aimed at the OSCP aspirants to help them understand the various methods of Escalating Privilege on Linux based Machine…☆886Mar 14, 2026Updated 3 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- High quality and text versions of cheat sheets from Cyber Detective Twitter☆42May 1, 2024Updated 2 years ago
- This cheasheet is aimed at the CTF Players and Beginners to help them sort the CTF Challenges on the basis of Difficulties.☆834Mar 14, 2026Updated 3 months ago
- This cheasheet is aimed at the CTF Players and Beginners to help them sort Vulnhub Labs. This list contains all the writeups available on…☆1,233Oct 23, 2022Updated 3 years ago
- This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 …☆2,534Mar 14, 2026Updated 3 months ago
- This cheasheet is aimed at the CTF Players and Beginners to help them sort Hack The Box Labs on the basis of Operating System and Difficu…☆1,797Mar 14, 2026Updated 3 months ago
- 😎 Curated list of awesome programming podcasts, organized alphabetically & topically☆30Oct 28, 2017Updated 8 years ago
- ☆43Dec 24, 2024Updated last year
- Autorev.sh generates reverse shell codes for reverse shell . Supports linux and windows☆17Apr 8, 2022Updated 4 years ago
- Subdomain enumeration using Cloudflare's scanning tool.☆48Jul 11, 2025Updated 11 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A repository of curated lists with elements such as IoCs to use for threat hunting & detection queries.☆35Jul 23, 2024Updated last year
- Short script to decode output logs of *sslsplit* raw HTTP packets.☆17Aug 12, 2016Updated 9 years ago
- ☆74Oct 28, 2020Updated 5 years ago
- bWAPP Docker image based on raesene/bWAPP and mattrayner/lamp☆12Dec 10, 2019Updated 6 years ago
- ☆23Jun 4, 2026Updated last week
- Subdomain crawler with wordlist using python☆15Mar 22, 2020Updated 6 years ago
- Fback is a tool that helps you create target-specific wordlists using a .json pattern.☆64Nov 21, 2025Updated 6 months ago
- ☆24Feb 7, 2025Updated last year
- 🔥 CEHv12 Certificate documentation 📚☆11Jun 29, 2023Updated 2 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Open Redirect Vulnerability Payload List☆12Feb 23, 2021Updated 5 years ago
- The state of the art network attack and monitoring framework.☆17Mar 5, 2018Updated 8 years ago
- Subdomain Scan (knockpy) in Python3☆13Oct 4, 2020Updated 5 years ago
- simple bash script to earn bounties☆37Apr 27, 2024Updated 2 years ago
- ☆49Jan 1, 2018Updated 8 years ago
- Google Dorking Payloads☆13Jun 24, 2024Updated last year
- ☆22Oct 30, 2022Updated 3 years ago