Cybersecurity
Offensive and defensive security tooling explained by a pentester — scanners, exploit frameworks, secrets detection, and the OSS projects shaping modern security work.
358 articles
Cybersecurity
foospidy/payloads: The 13GB Security Payload Archive Every Pentester Should Know About
Cybersecurity
Statistically Likely Usernames: Why Horizontal Password Attacks Beat Vertical Every Time
Cybersecurity
PwnGitManager: Surgical Git Repository Extraction for Security Researchers
Cybersecurity
Inside can-i-take-over-xyz: The Crowdsourced Database Securing Subdomain Hygiene
Cybersecurity
Red-Teaming-Toolkit: A MITRE ATT&CK-Mapped Arsenal for Offensive Security Operations
Cybersecurity
Curate: Mining VirusTotal's URL Archive for Bug Bounty Reconnaissance
Cybersecurity
EdOverflow/hacks: The Art of Disposable Security Scripts in /usr/local/bin
Cybersecurity
LFISuite: Anatomy of an Automated Local File Inclusion Exploitation Framework
Cybersecurity
Drupalgeddon2: Dissecting the RCE Exploit That Threatened Millions of CMS Installations
Cybersecurity
Cr3dOv3r: Reverse-Engineering a Credential Reuse Attack Framework
Cybersecurity
Smith: The Bug Bounty Wrapper That Makes Meg Actually Useful
Cybersecurity
AWSBucketDump: Weaponizing S3 Misconfigurations With Wordlists and Grep
Cybersecurity
CloudGoat: Learning Cloud Penetration Testing by Breaking Things on Purpose
Cybersecurity
WhatWeb: Ruby-Powered Web Fingerprinting with 1800+ Plugins for Security Reconnaissance
Cybersecurity
RecurseBuster: Why HEAD-First Requests Make Recursive Content Discovery Faster
Cybersecurity
Mining Bug Bounty Scopes at Scale: Inside bounty-targets-data's Automated Intelligence Pipeline
Cybersecurity
Sn1per: The Shell-Script Orchestrator That Weaponized 90+ Security Tools
Cybersecurity
Learning Go for Security Work: A Deep Dive into parsiya/Hacking-with-Go
Cybersecurity
SpiderFoot: How 200+ OSINT Modules Communicate in a Publisher/Subscriber Pipeline
Cybersecurity
Inside gwen001's pentest-tools: A Bug Bounty Hunter's Arsenal of Single-Purpose Security Scripts
Cybersecurity
Gurp: Automating Burp Suite Professional from the Command Line with Go
Cybersecurity
ORTBOT: A Red Teamer's Command Reference That Fits in Your Terminal
Cybersecurity
Running Burp Suite in CI/CD: How Headless-Burp Brings DAST to Your Build Pipeline
Cybersecurity