- Prompt Injection Attacks for Dummies
- Fragility of The Internet: How Sacrificial Nameservers allowed potential DNS hijacking of 1.6+ million domains
- Horrors of DNS: A Tale of 1800 potential domain takeovers due to mistyped NS
- Trojan War against SOTA LLMs
- ParamSpider - Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing
- FavFreak - Making Favicon.ico based Recon Great again
- OpenRedireX - A fuzzer for detecting open redirect vulnerabilities
- CertEagle - Weaponizing Live CT logs for automated monitoring of assets
- Quaithe - Quaithe empowers you to execute multiple commands in parallel for blazing-fast performance.
- DNSleuth - DNSleuth allows you to spy on the DNS queries your machine is making.
- Watson - Watson is a utility for note management and search from your terminal.
- ip2cloud - Check IP addresses against known cloud provider IP address ranges
- getresolvers - A simple utility to fetch freshly updated DNS resolvers
- revwhoix - A simple utility to perform reverse WHOIS lookups using whoisxml API
- heaptruffle - Mine URLs from Browser's Heap Snapshot for fun and profit
- ip2asn - A utility to quickly map IP addresses to their respective ASN
- revit - A command-line utility for performing reverse DNS lookups
- getsan - A utility to fetch and display dns names from the SSL/TLS cert data
- headerpwn - A fuzzer for finding anomalies and analyzing how servers respond to different HTTP headers
- dnsaudit - A command-line utility for auditing DNS configuration using Zonemaster API
- rayder - A lightweight tool for orchestrating and organizing your bug hunting recon / pentesting command-line workflows
- realm - A utility for recursively traversing SSL/TLS certificates for collecting DNS names