1/ Everyone knows HackTricks and PortSwigger. These are the...

Per-vuln-class notes plus bypass folders (403/429/2FA), tech-specific pages (Jenkins, Grafana, Jira, Laravel), and Google/GitHub/Shodan dork sheets.
Structured the way a hunter thinks: by class, by bypass, by tech.
github.com/daffainfo/AllA…
Automated recon, modular, wires together 50+ tools.
Use it as a baseline pass, or read the config to learn which tools actually matter in 2025.
github.com/six2dez/reconf…
Extracts URLs and secrets from JS bundles.
The bugs live in the JavaScript almost nobody reads. This tool reads it for you.
github.com/BishopFox/jslu…
Pulls archived URLs and JS from Wayback.
Production endpoints get removed.
The Wayback copy doesn't. Compare current JS to 6-month-old JS. Deleted endpoints often still resolve.
github.com/xnl-h4ck3r/way…
GraphQL introspection disabled? This brute-forces the schema from error messages.
Most hunters quit at "introspection off." This one keeps going.
github.com/nikitastupin/c…
Not tutorials. Reports. You learn what "impact" looks like to a triager.
