All resources
Topic

technique-and-payload-reference

4 resources across 1 kinds

References

  1. Community collection of payloads and bypass techniques organized by vulnerability class; a companion data source referenced alongside SecLists.

    Open ↗
  2. A categorized collection of 40+ Google search queries (dorks) for bug-bounty and pentest reconnaissance, targeting exposed config/log files, XSS/SQLi/SSRF/LFI-prone parameters, API endpoints, login/test environments, cloud storage misconfigurations, and leaked credentials. It also includes an interactive dork tool and links to related dork collections.

    Open ↗
  3. Collection of payloads for AI red teaming, organized around the OWASP AITG-APP (AI Testing Guide) categories. A reference set of adversarial prompt/test payloads for authorized LLM/AI application security testing rather than executable malware.

    Open ↗
  4. A community-maintained collection of scripts and tips for OWASP ZAP (Zed Attack Proxy), organized by category including active scan, passive scan, authentication, encode/decode, HTTP fuzzing, payload generation, and WebSocket testing, written in Python, JavaScript, Kotlin, Ruby and others. Scripts are installable via the ZAP Marketplace and released under Apache 2.0.

    Open ↗