Target & Scope Control
Capture program rules, in-scope assets, SLAs, and constraints. Prevent scope-creep with visible guardrails and tags for priority/risk.
End-to-end workflow for scope, recon, testing, findings, and reporting in one place. The framework combines a curated security toolbox, a deep test-case library, structured evidence handling, PDF export, and a reproducible Docker-based recon environment.
Capture program rules, in-scope assets, SLAs, and constraints. Prevent scope-creep with visible guardrails and tags for priority/risk.
Opinionated sequences for subdomains, ASN/WHOIS, live host discovery, JS asset surfacing, content discovery, and dorking — mapped to concrete tools and commands.
Curated commands for assetfinder, subfinder, httpx, naabu, nuclei, ffuf, dnsx, gau/gauplus, hakrawler, gospider, httprobe, asnmap and more. Docker image optional.
Reusable inspiration across XSS, CSRF, SSRF, SQLi, GraphQL, MFA/session, and SSO/OIDC/SAML — balanced for real-world surfaces.
Track vulnerabilities with severity, CWE/CVE references, CVSS placeholders, asset links, reproduction steps, and remediation status.
Attach PoC screenshots and artifacts straight into Markdown notes and reports through the optional Supabase flow.
Nuclei-style checks, saved queries, and reusable snippets keep tests consistent while staying agile.
Run tools only against authorized targets with clear audit trails and opt-in persistence mounts.
Frontend: React, Next.js, TypeScript and Tailwind with modular components.
Editing: Markdown editors with preview and Mermaid rendering for fast drafting.
Authentication: Firebase Auth with server-verified session cookies.
Firestore: Session state, lightweight content, timeline entries and admin profiles.
Supabase + PostgreSQL: Targets, assets, templates, notes, findings and reports.
PDF Export: Structured templates for professional reporting workflows.
Reporting: Structured Markdown content and reusable evidence workflows.
Document rules of engagement, in-scope assets, and constraints. Avoid surprises and keep priorities explicit.
Subdomains, ASN/WHOIS, alive hosts, JS scraping, GitHub dorks, wordlists, and directory brute force mapped to concrete commands.
Reusable checks across common bug classes without losing the flexibility needed for manual testing.
Track evidence and export professional PDFs with CWE/CVE references and CVSS placeholders.
10 public repositories, ordered by latest GitHub update.
No repository description has been added yet.
Purpose to remove user agent during bug-bounty testing
created to unrar files within sub directories
this is for the Hack the box academy
No repository description has been added yet.
No repository description has been added yet.
No repository description has been added yet.
Security
Various CTF:s
Counter Strike global offensive Tracks