This is your work, valued
Infosec enthusiast. Manager, Security Operations @Bugcrowd.
git_rce. Exploit PoC for CVE-2024-32002
★ 533onaws. Fetch the details of assets hosted on AWS.
★ 89swagroutes. swagroutes is a command-line tool that extracts and lists API routes from Swagger files in YAML or JSON format.
★ 61hook. Hook for the PoC for exploiting CVE-2024-32002
★ 18linux-default-file-locations. Default locations for files on various Linux distros.
★ 10cve-2025-4664. PoC and Setup for CVE-2025-4664
★ 4md2html. Python
★ 1dotfiles. My dotfiles.
★ 1CloudFlair. 🔎 Find origin servers of websites behind by CloudFlare using Internet-wide scan data from Censys.
★ 1bdaybot. A bot to automatically comment thank you on all your birthday posts.
★ 1rescuekerala. Website for coordinating rehabilitation of people affected in the 2018 Kerala Floods
★ 1test_repo. Test repo. Nothing to see here.
★ 1antislop. By slop for slop, to remove slop in an AI slop world.
★ 18file-itr. Python
★ 169mantis. A modular, stack-agnostic toolkit of security review skills for AI coding agents to autonomously find, reproduce, and patch vulnerabilities.
★ 596TokenBurn. HTML
★ 35exploitbench. ExploitBench measures how far AI agents climb, from reaching vulnerable code, to triggering the bug, to building exploit primitives, to arbitrary code execution.
★ 317ironcurtain. A secure* runtime for autonomous AI agents. Policy from plain-English constitutions. (*https://ironcurtain.dev)
★ 567copy-fail-CVE-2026-31431. Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code
★ 4kclearwing. Python
★ 1kwhoop-mcp-server. Python
★ 27distil-ai-slop-detector. Detect AI-generated text locally in your browser
★ 91claude-code-clone. A Claude Code orchestration layer that lets teammates reach your project context through Slack or Telegram while you're away, routing requests to the right workspaces on your own system.
★ 19claude-code-log. A Python CLI tool that converts Claude Code transcript JSONL files into readable HTML / Markdown format.
★ 1.2kshowboat. Create executable documents that demonstrate an agent's work
★ 1.2krodney. CLI tool for interacting with the web
★ 744ironclaw. IronClaw is an Agent OS focused on privacy, security and extensibility
★ 13kvulnerability-spoiler-alert-action. GitHub Action to alert on security patches before the CVE drops.
★ 216claude-code-devcontainer. Sandboxed devcontainer for running Claude Code in bypass mode safely. Built for security audits and untrusted code review.
★ 897nanoclaw. A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Slack, Discord, Gmail and other messaging apps,, has memory, scheduled jobs, and runs directly on Anthropic's Agents SDK
★ 30kbeautiful-mermaid. TypeScript
★ 11kskills. Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows
★ 6.3kreact2shell-scanner. High Fidelity Detection Mechanism for RSC/Next.js RCE (CVE-2025-55182 & CVE-2025-66478)
★ 2.5kCVE-2025-55182-research. CVE-2025-55182 POC
★ 796http-request-smuggler. Java
★ 1.2kremote-mcp-scanner. Python
★ 7quickstart-resources. A repository of servers and clients from the Model Context Protocol tutorials
★ 1.1kinspector. Visual testing tool for MCP servers
★ 11kpqcscan. Post-Quantum Cryptography Scanner - Scan SSH/TLS servers for PQC support
★ 125newtowner. Abuse trust-boundaries to bypass firewalls and network controls
★ 424jxscout. jxscout superpowers JavaScript analysis for security researchers
★ 473FrogPost. FrogPost: postMessage Security Testing Tool
★ 109posthog. :hedgehog: PostHog is the leading platform for building self-driving products. Our developer tools – AI observability, analytics, session replay, flags, experiments, error tracking, logs, and more – capture all the context agents need to diagnose problems, uncover opportunities, and ship fixes. Steer it all from Slack, web, desktop, or the MCP.
★ 37kawesome-cursorrules. 📄 Configuration files that enhance Cursor AI editor experience with custom rules and behaviors
★ 40kbaddns. Check subdomains for subdomain takeovers and other DNS tomfoolery
★ 443life-in-weeks. 📍 A map of my life, where each week I've been alive is a little box.
★ 574cognee. Cognee is the open-source AI memory platform for agents. Give your AI agents persistent long-term memory across sessions with a self-hosted knowledge graph engine.
★ 30khttptap. View HTTP/HTTPS requests made by any Linux program
★ 4.2kundetected-chromedriver. Custom Selenium Chromedriver | Zero-Config | Passes ALL bot mitigation systems (like Distil / Imperva/ Datadadome / CloudFlare IUAM)
★ 13kMisguidedAttention. A collection of prompts to challenge the reasoning abilities of large language models in presence of misguiding information
★ 485meta-ios-pinning. Updated version of https://codeshare.frida.re/@Numenorean/ios-instagram-facebook-ssl-pinning-bypass/
★ 6nowafpls. Burp Plugin to Bypass WAFs through the insertion of Junk Data
★ 1.5kvm_challenge.
★ 198xzbot. notes, honeypot, and exploit demo for the xz backdoor (CVE-2024-3094)
★ 3.6klimiter. A small command-line utility to artificially limit the input rate to STDIN.
★ 18Fabric. Fabric is an open-source framework for augmenting humans using AI. It provides a modular system for solving specific problems using a crowdsourced set of AI prompts that can be used anywhere.
★ 43kburp-awesome-tls. Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.
★ 1.9kbug-bounty-reference. Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature
★ 4.2kswagroutes. swagroutes is a command-line tool that extracts and lists API routes from Swagger files in YAML or JSON format.
★ 61cve. Gather and update all available and newest CVEs with their PoC.
★ 8kE2B. Open-source, secure environment with real-world tools for enterprise-grade agents.
★ 13kdtmf-decoder. Extract phone numbers from an audio recording of the dial tones.
★ 327socksprox. Shell
★ 11awesome-intelligence-writing. Collection of awesome resources on intelligence writing, including manuals/guides, standards, books, tranings, articles, videos, etc
★ 620awesome-security-newsletters. Periodic cyber security newsletters that capture the latest news, summaries of conference talks, research, best practices, tools, events, vulnerabilities, and analysis of trending threats and attacks
★ 1.3kregulator. Automated learning of regexes for DNS discovery
★ 393oscp-pre-preparation-plan-and-notes. My OSCP Pre-Preparation Phase. I'm not sure if I'll be able to afford the exam but what count's trying and learning things. I'm gonna give it a try. [Start Date: 21st March 2022]
★ 575burp-uuid. UUID issues for Burp Suite
★ 55guidtool. A tool to inspect and attack version 1 GUIDs
★ 240See-SURF. Security tool to find potential vulnerable Server Side Request Forgery (SSRF) parameters.
★ 364mastg. The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
★ 13kWhereToGo. WhereToGo - is a list of popular services that might be used in organizations. By having an account of the user - you can try to find entry points to the organization data.
★ 127VisaNotify-for-chrome. An Extension which notifies when a new visa appointment date is available.
★ 1telegram-image-ocr. Subscribe to Telegram messages for a user, perform OCR on the images and execute conditional triggers.
★ 4sourcegraph-scripts. Scripts for Sourcegraph search results. Useful for static analysis <3
★ 28security-study-plan. Complete Practical Study Plan to become a successful cybersecurity engineer based on roles like Pentest, AppSec, Cloud Security, DevSecOps and so on...
★ 5kawesome-ios-security. A curated list of awesome iOS application security resources.
★ 667reverse_ssh. SSH based reverse shell
★ 1.4kcvssjs. CVSS (Common Vulnerability Scoring System) v3.1 Javascript calculator toolkit
★ 68GooglePhishing. HTML
★ 24sitepoint-docker-tutorial. Dockerfile
★ 22DNSStager. Hide your payload in DNS
★ 622awesome-list-of-secrets-in-environment-variables. 🦄🔒 Awesome list of secrets in environment variables 🖥️
★ 909puredns. Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.
★ 2.2kChatterBot. ChatterBot is a machine learning, conversational dialog engine for creating chat bots
★ 15kHuntTheBug. Advanced reconnaissance framework for bug bounty hunters - Automate subdomain enumeration, vulnerability scanning, and security reconnaissance with 30+ integrated tools.
★ 60slurp. A blazing fast & feature rich Amazon S3 bucket enumerator.
★ 99chzone. Daily dump of domains in the .ch zonefile
★ 30log4shell-analysis. Contains all my research and content produced regarding the log4shell vulnerability
★ 31CVE-2021-44228-PoC-log4j-bypass-words. 🐱💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks
★ 950waybacked. Get URLs from the Wayback Machine. Able to handle large outputs.
★ 35htmlq. Like jq, but for HTML.
★ 7.6kJNDI-Exploit-Kit. JNDI-Exploitation-Kit(A modified version of the great JNDI-Injection-Exploit created by @welk1n. This tool can be used to start an HTTP Server, RMI Server and LDAP Server to exploit java web apps vulnerable to JNDI Injection)
★ 942log4shell-vulnerable-app. Spring Boot web application vulnerable to Log4Shell (CVE-2021-44228).
★ 1.1krogue-jndi. A malicious LDAP server for JNDI injection attacks
★ 1.1kcodeql-queries. My CodeQL queries collection
★ 100Log4jAttackSurface.
★ 2.1kmarshalsec. Java
★ 3.7kwriteups. Shell
★ 72github-readme-stats. :zap: Dynamically generated stats for your github readmes
★ 80kmind_chess. JavaScript
★ 5openvscode-server. Run upstream VS Code on a remote machine with access through a modern web browser from any device, anywhere.
★ 6.1kgitoops. all paths lead to clouds
★ 640gowap. Wappalyzer implementation in Go
★ 205mariana-trench. A security focused static analysis tool for Android and Java applications.
★ 1.2kinteractsh-web. Web dashboard for Interactsh client
★ 242RandomScripts. Random Shell Scripts and other ideas I have along the way
★ 73spicedb. Open Source, Google Zanzibar-inspired database for scalably storing and querying fine-grained authorization data
★ 6.9khttp2smugl. Go
★ 562tsunami-security-scanner-plugins. This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
★ 1ktsunami-security-scanner. Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.
★ 8.6ksdow. Six Degrees of Wikipedia
★ 1.9k