Cybersecurity
Offensive and defensive security tooling explained by a pentester — scanners, exploit frameworks, secrets detection, and the OSS projects shaping modern security work.
358 articles
Cybersecurity
gau: Mining Web Archives for Security Reconnaissance Without Touching the Target
Cybersecurity
OneForAll: The Subdomain Enumeration Framework That Aggregates 100+ Data Sources
Cybersecurity
httpx: The Swiss Army Knife of HTTP Reconnaissance That Actually Scales
Cybersecurity
GitHub as an Attack Surface: Automating Reconnaissance with github-search
Cybersecurity
o365spray: How Endpoint Diversity Beats Microsoft's Authentication Rate Limiting
Cybersecurity
Xray: China's Most Popular Closed-Source Vulnerability Scanner
Cybersecurity
Building a Custom HTTP Fingerprinting Engine with GoFingerprint
Cybersecurity
Inside the Vault: What 9,500 Stars Worth of Real Penetration Testing Reports Teach Us About Security
Cybersecurity
The GitHub Exploit Aggregator That Security Teams Don't Talk About Publicly
Cybersecurity
Inside Azure/Azure-Network-Security: Microsoft's Hidden Automation Arsenal for Cloud Perimeter Defense
Cybersecurity
Spring Boot Actuator Exploitation: A Security Researcher's Arsenal
Cybersecurity
PowerZure: When Your Azure Credentials Become Someone Else's Attack Surface
Cybersecurity
The macOS Security Arsenal: A Critical Review of kai5263499/osx-security-awesome
Cybersecurity
VulnX: The Aggressive CMS Scanner That Automates What Penetration Testers Do Manually
Cybersecurity
badPods: The Kubernetes Security Testing Toolkit That Maps Every Pod Privilege Escalation Path
Cybersecurity
BruteShark: Automating Credential Extraction from Network Captures with .NET Core
Cybersecurity
KingOfBugBountyTips: A Weaponized Command Reference for Security Reconnaissance
Cybersecurity
h2cSmuggler: Exploiting HTTP/2 Cleartext Upgrades to Bypass Reverse Proxies
Cybersecurity
Bento Toolkit: Running GUI Pentesting Tools in Fedora Containers with X11 Forwarding
Cybersecurity
Cloudlist: Multi-Cloud Asset Discovery for Attack Surface Management
Cybersecurity
Axiom: Distributing Security Scans Across Hundreds of Cloud Instances With Shell Scripts
Cybersecurity
Crossfeed: How CISA Built a Serverless Attack Surface Monitor on AWS
Cybersecurity
Arsenal: A Command Injection Framework for Pentesting (That Literally Injects Your Shell)
Cybersecurity