Skip to content
View phoenix-sec's full-sized avatar

Block or report phoenix-sec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Burpsuite plugin for Interact.sh

Java 232 38 Updated Jun 26, 2024

The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, …

Rust 3,706 394 Updated Mar 21, 2026

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static a…

JavaScript 20,693 3,632 Updated Mar 23, 2026

Find, verify, and analyze leaked credentials

Go 25,203 2,270 Updated Mar 25, 2026

Mobile Hacker's Weapons / A collection of cool tools used by Mobile hackers. Happy hacking , Happy bug-hunting

Ruby 1,043 170 Updated Mar 1, 2026

Burp plugin able to find reflected XSS on page in real-time while browsing on site

Java 1,204 171 Updated Feb 2, 2021

Quick SQLMap Tamper Suggester

Python 1,399 276 Updated Jul 18, 2022

Signatures for jaeles scanner by @j3ssie

117 40 Updated Apr 20, 2024

Fetch & Filter Known URLs

Python 15 3 Updated Aug 3, 2022

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

Python 184 32 Updated Nov 22, 2021

Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.

Go 4,868 506 Updated Mar 20, 2026

🍪 CookieMonster helps you detect and abuse vulnerable implementations of stateless sessions.

Go 969 74 Updated Jan 10, 2025

🐙 Cross-document messaging security research tool powered by https://enso.security

JavaScript 301 38 Updated May 22, 2023

List of Google Dorks for sites that have responsible disclosure program / bug bounty program

1,911 484 Updated Dec 8, 2025

declutters url lists for crawling/pentesting

Python 1,538 170 Updated Feb 23, 2025

Community curated list of templates for the nuclei engine to find security vulnerabilities.

JavaScript 12,093 3,406 Updated Mar 25, 2026

Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place

Go 1,040 166 Updated Aug 23, 2025

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

Shell 7,373 1,146 Updated Mar 25, 2026
Python 809 163 Updated Jul 28, 2024

Monitor subdomains with certstream

Python 5 2 Updated Sep 25, 2020

A cross-platform python based utility to download courses from udemy for personal offline use.

Python 4,950 1,185 Updated Jun 6, 2021

⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting

Ruby 4,552 759 Updated Mar 20, 2026

Ninjref is a fast & light tool for finding urls with reflected parameters from wayback & CommonCrawl it's use threads in threads to optimize it's speed and use Wayback resumption key to divide scan…

Python 23 7 Updated Oct 22, 2020

Collection of methodology and test case for various web vulnerabilities.

7,059 1,924 Updated Jun 25, 2025
Shell 376 160 Updated Aug 20, 2021

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 76,340 16,782 Updated Mar 16, 2026

GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep

1,412 306 Updated Sep 13, 2024

A wrapper around grep, to help you grep for things

Go 2,090 335 Updated Jun 8, 2024

XRCross is a Reconstruction, Scanner, and a tool for penetration / BugBounty testing. This tool was built to test (XSS|SSRF|CORS|SSTI|IDOR|RCE|LFI|SQLI) vulnerabilities

Shell 351 70 Updated Jun 17, 2023
Next