A simple HAR-based JavaScript recon automation kit for organizing JS files, endpoints, secrets, and gf-filtered attack surface during bug bounty hunting.
☆18May 20, 2026Updated 3 months ago
Alternatives and similar repositories for js-recon-automation-kit
Users that are interested in js-recon-automation-kit are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Bug bounty methodology, checklists, and hunting notes.☆35Jul 10, 2026Updated last month
- A curated collection of my security research and bug bounty writeups, documenting real-world vulnerabilities, exploitation methods☆26Jul 15, 2026Updated last month
- A tool which bypasses AMSI (AntiMalware Scan Interface) and PowerShell CLM (Constrained Language Mode) and gives you a FullLanguage Power…☆15Feb 17, 2024Updated 2 years ago
- My Main App Hacking CheckList☆34Jun 20, 2026Updated 2 months ago
- Stealth hybrid URL mapper☆31May 1, 2026Updated 3 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Documenting my security research journey: This repository contains detailed vulnerability write-ups, proof-of-concept (PoC) exploits, and…☆107Updated this week
- A multi-threaded port scanner implementation in Python☆12May 30, 2023Updated 3 years ago
- SSRFHunter☆18Jan 17, 2026Updated 7 months ago
- ☆39Jul 29, 2026Updated 3 weeks ago
- CLAUDE.md configs and skills I use for bug bounty hunting with Claude Code☆31Apr 14, 2026Updated 4 months ago
- CVE-2026-63030, CVE-2026-60137, wp2shell scanner☆55Jul 18, 2026Updated last month
- An obsessive, expert-tier knowledge base + AI skill system for professional bug bounty hunting, security research, and penetration testin…☆31Apr 25, 2026Updated 4 months ago
- TokenTwin Checker — Dual Token BAC/IDOR Tester for Burp Suite☆90Updated this week
- A bash script that extracts `shodan-query, google-query, censys-query, fofa-query, hunter-query, zoomeye-query` in nucleihub-templates.☆15Feb 17, 2026Updated 6 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- SidePeek.js is a curated set of JavaScript payloads for browser-based recon. Run them in DevTools or as bookmarklets to uncover hidden AP…☆22May 13, 2025Updated last year
- Endpoint Extractor Bookmarklet☆50Jul 5, 2026Updated last month
- PoC for CVE-2026-48907 - Joomla! JCE extension < 2.9.99.5 unauthenticated RCE☆15Jun 11, 2026Updated 2 months ago
- Small python script to extract Facebook deeplinks from an APK file☆14Oct 30, 2020Updated 5 years ago
- Chrome DevTools HTTP workbench with built-in AI.☆19Dec 9, 2025Updated 8 months ago
- Replay any request as another user to find IDOR/BOLA/BFLA, right in the browser.☆28Jun 16, 2026Updated 2 months ago
- Extensión de Burp Suite que incorpora detección pasiva de vulnerabilidades mediante inteligencia artificial.☆17Updated this week
- Just a bunch of useful scripts for netsec/admin/others☆18Dec 9, 2025Updated 8 months ago
- Autonomous multi-cipher PE crypter with 18-layer structural metamorphism, 8 encryption engines, and real-time AV/EDR threat modeling☆19Feb 11, 2026Updated 6 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- My ATO Via Password Reset Methodology☆54May 13, 2026Updated 3 months ago
- Use AI to install penetration testing tool suites in one click.☆118Oct 5, 2025Updated 10 months ago
- A Python tool to resolve domains to IPs, fetch related CVEs, and display open ports☆17Nov 21, 2025Updated 9 months ago
- A comprehensive WordPress vulnerability scanner and exploitation framework for authorized penetration testing. This tool automatically de…☆77May 21, 2026Updated 3 months ago
- CEREBRO-RED v2: Advanced LLM Red Team Research Platform with PAIR Algorithm and LLM-as-a-Judge Evaluation☆16Mar 21, 2026Updated 5 months ago
- ☆56Jul 15, 2026Updated last month
- ☆11Jun 19, 2024Updated 2 years ago
- SelfHosted - Bug Bounty Programs | Discover new and fresh bug bounty programs across platforms. Updated frequently to always display the …☆16Nov 24, 2025Updated 9 months ago
- A modern tool written in python for hunting open redirection☆31Aug 8, 2023Updated 3 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- IP Finder tool, ipfinder collects IP addresses from Shodan search queries.☆17Dec 12, 2025Updated 8 months ago
- Proof-of-Concept exploit for CVE-2026-23918 (Apache mod_http2 double-free). Features multi-mode DoS (Rapid-RST, Slow-Drip) and passive RC…☆22May 6, 2026Updated 3 months ago
- Personal Web Application Pentesting Methodology built during my cybersecurity learning journey. Covers reconnaissance, scanning, fuzzing,…☆57Jul 24, 2026Updated last month
- crawler for finding reflected parameters and reflecting special characters!☆21Dec 2, 2024Updated last year
- An advanced Out-of-Band and In-Band SSRF fuzzing scanner with dynamic request tracking.☆40Jun 18, 2026Updated 2 months ago
- DevSecOps for the AI-era CI/CD pipeline. Catches the bugs your AI coding assistant introduces — before they reach production.☆20Jul 14, 2026Updated last month
- xnew is a fast, low-memory CLI that appends only unique lines to files. Built in Go for large datasets, it streams input efficiently and …☆30May 23, 2026Updated 3 months ago