synack / wstg
The Web Security Testing Guide is a comprehensive open source guide to testing the security of web applications and web services.
☆26Updated last year
Related projects ⓘ
Alternatives and complementary repositories for wstg
- ☆65Updated last year
- The project aims at creating target-specific wordlists for any web application that you are testing.☆63Updated 2 years ago
- Archived Please go to https://github.com/adamjsturge/xsshunter-go☆31Updated 8 months ago
- 3klector is an automation Recon tool which collecting information about Acquisitions and ASN which related to Big Scope company☆49Updated 2 years ago
- KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Po…☆58Updated 3 years ago
- ☆60Updated 3 months ago
- Vulnerable SAML infrastructure training applicaiton☆48Updated last year
- golang tool to scan domains or single domains with know security issues against xmlrpc☆59Updated last year
- A collection of code for interacting with API sources directly to improve your understanding of those services.☆65Updated 3 years ago
- Prototype Pollution Scanner☆101Updated 3 years ago
- Get all the CNs from a list of domains☆46Updated 3 years ago
- Misc bounty and vulndisc things☆81Updated 3 years ago
- This extension adds a search bar to the Repeater tab that can be used to highlight all repeater tabs where the request and/or response ma…☆78Updated last year
- Find subdomains and takeovers.☆83Updated last year
- Information Security Information From Web☆26Updated last month
- Awesome cloud enumerator☆36Updated 4 years ago
- s3 brute force tool☆44Updated 3 years ago
- Horizontal Domain Discovery☆74Updated last year
- A list of "secrets" from JWT sample code and readme files.☆51Updated 4 years ago
- A burpsuite extension that helps security researchers find public security reports published on h1 based on the selected host☆42Updated 4 years ago
- Sometimes we want to fuzz a set of sub-domain URLs with a common wordlist. Fuzzing them one by one is a tedious task, not to mention the …☆51Updated 3 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆130Updated 3 years ago
- A tool to guess the rest of the shortnames provided by vulnerable IIS instances.☆34Updated last year
- Reestructured LemonBooster.☆44Updated 3 months ago
- Extract SSL certificate data (Subject Name, Subject Alt Names, Organisation)☆41Updated last year
- Tool for making it easy to collect dns results from the CLI☆39Updated 2 months ago