Highlights
- Pro
Stars
🤪 A list of funny and tricky JavaScript examples
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static a…
DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
A collaborative, multi-platform, red teaming framework
💾 dn - offline full-text search and archiving for your Chromium-based browser.
Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime
Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.
Mobile Edge-Dynamic Unified Security Analysis
Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic
Chrome-extension implant that turns victim Chrome browsers into fully-functional HTTP proxies, allowing you to browse sites as your victims.
XSS payloads designed to turn alert(1) into P1
A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon
BGP and RPKI monitoring tool. Pre-configured for real-time detection of visibility loss, RPKI invalid announcements, hijacks, ROA misconfiguration, and more.
Electron JS Browser To Find XSS Vulnerabilities Automatically
Nameserver DNS poisoning attacks made easy
Work in progress...
Collection of useful FRIDA Mobile Scripts
Change monitoring app that checks the content of web pages in different periods.
vulnerable OAuth 2.0 applications: understand the security implications of your OAuth 2.0 decisions.
🐙 Cross-document messaging security research tool powered by https://enso.security
Secrets Ninja is an GUI tool for validating & investigating API keys discovered during pentesting & bug bounty hunting.
JavaScript for Automation (JXA) tool to do Active Directory enumeration.
JavaScript functions intended to be used as an XSS payload against a WordPress admin account.
Extract GraphQL operations from javascript

