Pentesting

Kali Linux Cheat Sheet for Penetration Testers

Welcome to the Penetration Testing Cheat Sheet! This comprehensive guide provides quick references, commands, and techniques for various asp...

Danial Zahoor 17 Sep, 2024

APK2URL: Extract IP and URL Endpoints from APKs with OSINT Tool

apk2url easily extracts URL and IP endpoints from an APK file and performs filtering into a .txt output. This is suitable for information ga...

Danial Zahoor 22 Feb, 2024

Rayder: Lightweight CLI Tool for Bug Hunting Workflows

A lightweight tool for orchestrating and organizing your bug hunting recon / pentesting command-line workflows.

Danial Zahoor 6 Feb, 2024

5 Common Coder Mistakes in Bug Bounty Hunting (with Code Fixes)

Here are some common mistakes coders make when doing bug bounty, along with code examples and tips for avoiding them:

Danial Zahoor 12 Jan, 2024

Securing Linux Exploits: Moonwalk-Back for Zero Traces

Cover your tracks during Linux Exploitation / Penetration Testing by leaving zero traces on system logs and filesystem timestamps.

Danial Zahoor 2 Jan, 2024

NetworkSherlock: Porwerfull Port Scanning With Shodan

NetworkSherlock is a powerful and flexible port scanning tool designed for network security professionals and penetration testers. With its ...

Danial Zahoor 19 Dec, 2023

CloakQuest3r - Uncover the true IP address of websites safeguarded by Cloudflare

CloakQuest3r is a powerful Python tool meticulously crafted to uncover the true IP address of websites safeguarded by Cloudflare, a widely a...

Danial Zahoor 10 Dec, 2023

Mass Bruter - Mass bruteforce network protocols

Simple personal script to quickly mass bruteforce common services in a large scale of network. It will check for default credentials on ftp,...

Danial Zahoor 27 Nov, 2023

GraphQLmap: Pentesting Scripting Engine for GraphQL Endpoints

GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)

Danial Zahoor 23 Oct, 2023

HBSQLI: Automated Tester For Header Based Blind SQL Injection

HBSQLI is an automated command-line tool for performing Header Based Blind SQL injection attacks on web applications. It automates the proce...

Danial Zahoor 15 Oct, 2023