xer0dayz
1N3
Founder of Sn1perSecurity LLC. Creator of Sn1per and SILENTCHAIN AI. Top 20 worldwide on @BugCrowd in 2016. OSCE/OSCP/CISSP/Security+
Languages
Top Repositories
Attack Surface Management Platform
A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.
Automatically brute force all services running on a target.
Find exploits in local and online databases instantly
A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.
A collection of Windows, Linux and MySQL privilege escalation scripts and exploits.
Repositories
36Quickly analyze and reverse engineer Android packages
Attack Surface Management Platform
Automatically brute force all services running on a target.
A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.
A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website.
Find exploits in local and online databases instantly
Bypass 4xx HTTP response status codes and more. Based on PycURL.
A collection of Windows, Linux and MySQL privilege escalation scripts and exploits.
Wordpress XMLRPC System Multicall Brute Force Exploit (0day) by 1N3 @ CrowdShield
AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)
Discover the attack surface and prioritize risks with our continuous Attack Surface Management (ASM) platform - Sn1per Professional #pentest #redteam #bugbounty
A collection of data exfiltration scripts for Red Team assessments.
Automatically Launch Google Hacking Queries Against A Target Domain
Sr. Penetration Tester. Creator of Sn1per. Top 20 worldwide on @BugCrowd in 2016. OSCE/OSCP/CISSP/Security+
MassBleed SSL Vulnerability Scanner
HTTPoxy Exploit Scanner by 1N3 @CrowdShield
A small python script to check for Cross-Site Tracing (XST)
Exploits by 1N3 @CrowdShield @xer0dayz @XeroSecurity
ServiceLens is a Python tool for analyzing services linked to Microsoft 365 domains. It scans DNS records like SPF and DMARC to identify services, categorizing them into Email, Cloud, Security, and more.
DirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it
In-depth Attack Surface Mapping and Asset Discovery
Find unreferenced AWS S3 buckets which have CloudFront CNAME records pointing to them
An automated Wireless RogueAP MITM attack framework.
CTF Writeups
Supermicro IPMI/BMC Cleartext Password Scanner
A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)
S3 bucket enumerator
Rapidly enumerate subdomains and domains using rapiddns.io.
Find endpoints on GitHub.
Retrieve IP Geolocation information