This is your work, valued
domloggerpp. A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.
★ 808GMSGadget. This repository is a collection of JavaScript gadgets that can be used to bypass XSS mitigations such as Content Security Policy (CSP) and HTML sanitizers like DOMPurify.
★ 150domloggerpp-caido. A Caido plugin to monitor, intercept, and debug JavaScript sinks based on customizable configurations.
★ 44bot-ctf-template. JavaScript
★ 35Werkzeug-CVE-2022-29361-PoC. Python
★ 5dotfiles. Shell
★ 4domloggerpp-caido. A Caido plugin to monitor, intercept, and debug JavaScript sinks based on customizable configurations.
★ 4DOMFortify. DOMFortify turns on Trusted Types for a page and quietly takes over the browser's default policy, so that old, vulnerable HTML sinks get auto-sanitized before bad markup ever hits the DOM.
★ 21ffffirefox. JavaScript
★ 78ssh-keysign-pwn. Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels.
★ 754paperasse. 🇫🇷 Skills pour agents IA spécialisés dans la bureaucratie française : Comptable, Notaire, ...
★ 2.3kLivepyre. A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.
★ 148OurClaude. TypeScript
★ 25vuln-scout. AI-powered whitebox penetration testing plugin for Claude Code. 9 languages, 22 skills, 7 autonomous agents. STRIDE threat modeling, OWASP 2025 coverage, polyglot monorepo support.
★ 22rtk. CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies
★ 74kgobypass403. A powerful WAF (HTTP 403/401) and URL parser bypass tool developed in Go, designed to preserve exact URL paths and structures during testing.
★ 50riphttp. Rust
★ 11uff. unleashed ffuf
★ 252mongobleed. JavaScript
★ 944React2Shell-CVE-2025-55182-original-poc. Original Proof-of-Concepts for React2Shell CVE-2025-55182
★ 1.1kffuf_claude_skill. This is a "skill" for claude to use FFUF.
★ 201caido. 🚀 Caido releases, wiki and roadmap
★ 2.5khacktivity. Disclosures of bugs and vulnerabilities reported by Hacktron.
★ 16cai. Cybersecurity AI (CAI), the framework for AI Security
★ 9.6kEbka-Caido-AI. AI-powered assistant that integrates seamlessly with Caido
★ 80ShadowBreakers.
★ 51singularity. A DNS rebinding attack framework.
★ 1.3kCaido403Bypasser. 403Bypasser is a simple plugin that lets you bypass 403 status code by transforming HTTP requests with custom templates.
★ 104JsSuite. Real-Time JavaScript reverse engineering and debugging suite - Burp Suite, but for JavaScript
★ 18FindOldSIDTraces. A cross-platform tool to find traces of old SIDs remaining in LDAP objects of the Active Directory
★ 26Hoster. A fast application to create and manage dynamic content and routes with an administration panel and a secure API
★ 6Manticore. A cross platform library to write offensive and defensive security tools in Go
★ 158archivealchemist. Archive Alchemist is a tool for creating specially crafted archives to test extraction vulnerabilities.
★ 239jar-poisoner. Replaces every class in a JAR file with a malicious one
★ 3BFScan. Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR / APK applications.
★ 257responder. Easily create and share Proof of Concepts in HTML, JavaScript, etc. with custom headers, all via query parameters
★ 15LibreOffice_Tips_Bug_Bounty. Some tips for Bug Bounty using LibreOffice
★ 60graphqlextractor. Extract GraphQL operations from javascript
★ 24surf. Escalate your SSRF vulnerabilities on Modern Cloud Environments. `surf` allows you to filter a list of hosts, returning a list of viable SSRF candidates.
★ 757Hippie-OSINT-Toolkit. A web based OSINT ressource and tool
★ 241action-octoscan. 📦 :octocat: A GitHub Action that performs a security scan of your GitHub Actions.
★ 26laravel-crypto-killer. A tool designed to exploit bad implementations of decryption mechanisms in Laravel applications.
★ 145dead-domain-discovery. This Chromium extension scans the page for external iFrames, Scripts, and Styles, logs them to the console, and checks if their domains are resolvable.
★ 68MicroBurst. A collection of scripts for assessing Microsoft Azure security
★ 2.4khack-fastjson-1.2.80.
★ 525CVE-2024-45409. Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409) exploit
★ 84CSPBypass. CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting) vulnerabilities on sites where injections are blocked by CSPs that only allow certain whitelisted domains.
★ 709cupshax. Python
★ 234bbot. The recursive internet scanner for hackers. 🧡
★ 10kchunkloader. A chrome/Firefox extension to retrieve and load react javascript chunks all at once for a wide range of javascript techs
★ 77CSPTBurpExtension. CSPT is an open-source Burp Suite extension to find and exploit Client-Side Path Traversal.
★ 169CTFNote. CTFNote is a collaborative tool aiming to help CTF teams to organise their work.
★ 593MailPermute. Generate email permutations from a name and verify if this email exist with different providers (gmail, duckduckgo, yahoo, yandex)
★ 42SSRFmap. Automatic SSRF fuzzer and exploitation tool
★ 3.6ksmbclient-ng. smbclient-ng, a fast and user friendly way to interact with SMB shares.
★ 1keos. Enemies Of Symfony - Debug mode Symfony looter
★ 360Slanger-RCE. RCE in Slanger using deserialization of Ruby objects
★ 11CVE-2024-4367-PoC. CVE-2024-4367 & CVE-2024-34342 Proof of Concept
★ 203reset-tolkien. Unsecure time-based secret exploitation and Sandwich attack implementation Resources
★ 149business-ctf-2024. Official writeups for Business CTF 2024: The Vault Of Hope
★ 163wconsole_extractor. WConsole Extractor is a python library which automatically exploits a Werkzeug development server in debug mode. You just have to write a python function that leaks a file content and you have your shell :)
★ 67domlogger-configs. Useful configurations for the DomLogger++ extension
★ 48initramfs-toolkit. Toolkit that allows to extract and compress initramfs, useful for Linux kernel exploitation.
★ 9WU-FCSC2024.
★ 8keyhacks. Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.
★ 6.3kldap2json. The ldap2json script allows you to extract the whole LDAP content of a Windows domain into a JSON file.
★ 150HExHTTP. Header Exploitation HTTP
★ 760jsluicepp. jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice
★ 302http-garden. Differential testing framework for HTTP implementations
★ 940Meta-Owned-IT-Assets. Curated list of Meta (formerly Facebook) owned IT assets
★ 60MALVEKE-Flipper-Zero. GAME BOY Tools for Flipper Zero. The perfect companion for your Flipper Zero. Equipped with ESP32-S2 for WiFi. MALVEKE allows you to connect all GAME BOY peripherals and additional accessories such as NRF24, CC1101, and GPS.
★ 270BChecks. BChecks collection for Burp Suite Professional and Burp Suite DAST
★ 785wafer. Python
★ 222pics. File formats dissections and more...
★ 11kwriteups. CTF writeups from The Flat Network Society
★ 158PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
★ 80kclient-side-prototype-pollution. Prototype Pollution and useful Script Gadgets
★ 1.6kwrapwrap. Generates a `php://filter` chain that adds a prefix and a suffix to the contents of a file.
★ 245abuseACL. A python script to automatically list vulnerable Windows ACEs/ACLs.
★ 67shovel. Web interface to explore Suricata EVE outputs
★ 99write-ups. Write-ups for various CTF
★ 216sourcemapper. Extract JavaScript source trees from Sourcemap files
★ 1.4kSightQL. Python
★ 1snow. Use Snow to finally secure your web app's same origin realms!
★ 114chrome_v8_exploit. A collection of 1days and solutions to challenges related to v8/chrome I developed
★ 163pyLDAPWordlistHarvester. A tool to generate a wordlist from the information present in LDAP, in order to crack passwords of domain accounts.
★ 379my-ctf-challenges. CTF challenges I created 🚩
★ 84server-side-prototype-pollution. A collection of Server-Side Prototype Pollution gadgets and exploits
★ 237CVE-2023-38831-winrar-exploit. CVE-2023-38831 winrar exploit generator
★ 782NoFilter. C
★ 306XSS-Bypass-Filters.
★ 599libcurl-crlf.
★ 13LFIHunt. Advanced Tool To Scan And Exploit Local File Inclusion (LFI) Vulnerabilities
★ 41CVE-2023-27372. SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18, 4.0.10, 4.1.8, and 4.2.1.
★ 69awesome-flipperzero. 🐬 A collection of awesome resources for the Flipper Zero device.
★ 24kC_revshell. Basic reverse shell in C using socket() with complete explanation
★ 69cry-me. CRY.ME (CRYptographic MEssaging application)
★ 180ctf-writeups. CTF write-ups
★ 100GeoWordlists. GeoWordlists is a tool to generate wordlists of passwords containing cities at a defined distance around the client city.
★ 165pypotomux. pypotomux - A python protocol demuxed honeypot (potomiel)
★ 12gitGraber. gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...
★ 2.3kobjectwalker. A python module to explore the object tree to extract paths to interesting objects in memory.
★ 104collisions. Hash collisions and exploitations
★ 3.4kBurpJSLinkFinder. Burp Extension for a passive scanning JS files for endpoint links.
★ 817pp-finder. PP-finder Help you find gadget for prototype pollution exploitation
★ 206firefly. Black box fuzzer for web applications
★ 441list. The Public Suffix List
★ 2.9kxanhunt. A lightweight debian-based docker image that contains all the tools you need to do bugbounty.
★ 5Safe-Blob-URL. A Web Platform API proposal for Blob URL
★ 11postMessage-tracker. A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon
★ 1.3kctf-challenges. Fun CTF (capture the flag) security challenges that I've created
★ 9proposal-symbol-proto. TC39 proposal for mitigating prototype pollution
★ 53recollapse. REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications
★ 1.4kKubestroyer. Kubernetes exploitation tool
★ 363DOMPurify. DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
★ 17kFlipperAnimationManager. Visualize and manage your Flipper Zero animations directly from your computer - Flipper Animation Manager
★ 506CVE-2022-46169. CVE-2022-46169 Cacti remote_agent.php Unauthenticated Command Injection.
★ 47css-exfiltration. HTML
★ 7231-days-of-API-Security-Tips. This challenge is Inon Shkedy's 31 days API Security Tips.
★ 2.2kkatana. A next-generation crawling and spidering framework.
★ 17kwappaGo. Go
★ 59blogs. ✨ Build a beautiful and simple website in literally minutes. Demo at https://beautifuljekyll.com
★ 21php_filter_chain_generator. Python
★ 1.1kVolWeb. A centralized and enhanced memory analysis platform
★ 537CVE-2022-0337-PoC-Google-Chrome-Microsoft-Edge-Opera. 🎩 🤟🏻 [P1-$10,000] Google Chrome, Microsoft Edge and Opera - vulnerability reported by Maciej Pulikowski - System environment variables leak - CVE-2022-0337
★ 340osgint. OSINT tool to find informations about a github user (email2username, username2email, creation date ...)
★ 559AllVideoPocsFromHackerOne. This script grab public report from hacker one and make some folders with poc videos
★ 924Awesome-RCE-techniques. Awesome list of step by step techniques to achieve Remote Code Execution on various apps!
★ 1.9kwindows-coerced-authentication-methods. A list of methods to coerce a windows machine to authenticate to an attacker-controlled machine through a Remote Procedure Call (RPC) with various protocols.
★ 601bypass-url-parser. bypass-url-parser
★ 1.1kshellcoding-companion. A python script to automatically generate shellcode payload from assembly files.
★ 13Moodle-webshell-plugin. A webshell plugin and interactive shell for pentesting a Moodle instance.
★ 43CSPass. This tool allows to automatically test for Content Security Policy bypass payloads.
★ 45dead-simple-blog. dead-simple blog template powered by Markdown and PHP
★ 10writeups. Writeups from our CTFs and more!
★ 4