Just a puppet lovers and Open Source Enthusiast. Interested in Research Development and Non-Profit Organization. Passionate with OSINT.
Belati. The Traditional Swiss Army Knife for OSINT
564spose. Squid Pivoting Open Port Scanner
104SSLPinDetect. SSLPinDetect is a tool for analyzing Android APKs to detect SSL pinning implementations by scanning for known patterns in decompiled code. It helps security researchers and penetration testers identify SSL pinning mechanisms used in mobile applications.
87DllProxy-rs. Rust Implementation of SharpDllProxy for DLL Proxying Technique
29APK-FiD. Give me your APK, I will give you framework name
15TMTG. TMTG(Twint Mention to Graph) is tools for converting twint user mentions data to network graph for use in Gephi or others network mapping tools that support GEXF file format.
13android-ssl-pinning-signed-demo. A tiny demo app using SSL pinning to block HTTPS MitM interception
13smali-sslpin-patterns. A collection of Smali patterns to detect SSL pinning implementations in Android apps, covering frameworks like OkHttp, TrustManager, Conscrypt, and more for security analysis and reverse engineering.
8apkpuller. A tool for extracting (Splitted) APK files from installed applications on Android devices. It automates the boring stuff when performing mobile penetration testing, especially for static analysis.
7polyscan. PolyScan is a high-performance security scanner designed to detect and extract embedded executables, scripts, and suspicious content hidden within image files. It's specifically built for defensive security analysis and forensic investigation of image polyglots.
7yaraman. YaraMan is a standalone web application for managing YARA rules and scanning files for malware detection. It provides an intuitive web interface with dedicated pages for file scanning and YARA rule management, featuring comprehensive threat detection results and advanced rule compilation support.
6easy-rust-notes. My personal notes and code for learning Rust in easy_rust tutorial https://github.com/Dhghomon/easy_rust
6unquoted_checker. Scanner for finding Unquoted Service Path for Privilege Escalation
6polkit-auto-exploit. Automatic Explotation PoC for Polkit CVE-2021-3560
5nessus-queue-scan. A tool to automate Nessus scan scheduling, allowing pentesters to queue scans without the hassle of manually creating schedules. Simply define scan details, and the tool will automatically launch the next scan once the previous one finishes, preventing any overlap.
5CheckMyUsername. Python Library for Social Media and Other Service Username Availability Checker
5extract-myreact. Extracting react native app source code from apk file.
4MobileApp-Pentest-Cheatsheet. The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.
4docker-101-id. This ebook about Docker from zero to hero. Just for education purpose only with Indonesian Language.. I hope i can commitment :)
4Dysco. Dysco(Dynamic PHP Shell Command for RCE)
3hacker101. Hacker101
3AM3S. Asterisk Manager/Monitor Multiple Server With Python - Coming Soon
3CVE-2022-1388-rs. CVE-2022-1388 F5 BIG-IP iControl REST Auth Bypass RCE written in Rust
2aancw.
2panduan-memulai-belajar-django. Buku ini merupakan Panduan untuk Memulai Belajar Django bagi pemula. Dibuku ini akan membahas dari teori dasar Django sampai praktek pembuatan aplikasi. Buku ini ditujukan untuk dokumentasi Kuliah Online SinauDev
2Android-Security-Reference. A W.I.P Android Security Ref
2fuzzing-101-solutions-learning. All resource backup from https://github.com/epi052/fuzzing-101-solutions/ with some adaptation for my fuzzing learning purpose. I'm not own any copyright
2Spring4shell-poc-rs. Spring 4 Shell PoC script writted in Rust
2SecLists. SecLists is the security tester's companion. It is a collection of multiple types of lists used during security assessments. List types include usernames, passwords, URLs, sensitive data grep strings, fuzzing payloads, and many more.
2Spring4shell-poc-lab. PoC Lab for Spring4shell vulnerability
2nixpkgs. My Personal Configuration with Nix ƛ
2bettercap-ng. This is a WIP of the new version of bettercap, very alpha, do not use.
2Exploit-Development-Tools. A bunch of my exploit development helper tools, collected in one place.
2AppSecEzine. AppSec Ezine Public Repository.
1datasploit. An #OSINT Framework to perform various recon techniques on Companies, People, Phone Number, Bitcoin Addresses, etc., aggregate all the raw data, and give data in multiple formats.
1SSRF-Testing. SSRF (Server Side Request Forgery) testing resources
1Awesome-WAF. 🔥 A curated list of awesome web-app firewall (WAF) stuff.
1MLWithPytorch. Objective of the repository is to learn and build machine learning models using Pytorch. 30DaysofML Using Pytorch
1API-dnsdumpster.com. (Unofficial) Python API for https://dnsdumpster.com/
1lsacache2hashcat. Give me lsadump::cache output from mimikatz, I will transform it to DCC2 Hashcat compatible. Useful for so many credentials cache
1awesome-iocs. A collection of sources of indicators of compromise
1Useful_Websites_For_Pentester. This repository is to make life of the pentester easy as it is a collection of the websites that can be used by pentesters for day to day studies and to remain updated.
1AndroidKernelExploitationPlayground. C
1android_app_security_checklist. Android App Security Checklist
1codeshare-helper. A browser extension that enhances Frida CodeShare by enabling easy copying and downloading of code snippets as you browse.
1remote-template-injector. VBA Macro Remote Template Injection written in Rust
1Awesome-Red-Teaming. List of Awesome Red Teaming Resources
1awesome-research. :seedling: a curated list of tools to help you with research/life
1ZamasuSearch. Zamasu Search is a Python GUI Based for Searching Exploit from exploit-db.com repository
1awesome-remote-job. A curated list of awesome remote jobs and resources. Inspired by https://github.com/vinta/awesome-python
1awesome-cyber-skills. A curated list of hacking environments where you can train your cyber skills legally and safely
1awesome-threat-intelligence. A curated list of Awesome Threat Intelligence resources
1awesome-social-engineering. A curated list of awesome social engineering resources.
1awesome-pentest-cheat-sheets. Collection of the cheat sheets useful for pentesting
1Awesome-Hacking. A collection of various awesome lists for hackers, pentesters and security researchers
1dirList-JSON-Hash. dirList-JSON-Hash is Command line tool for directory listing with JSON output format, hash(MD5,CRC32,SHA1,SHA256,SHA512) file support and file information. Usefull for generate list of update file for application updater.
1RVIServerMasterOS. This repository is for RumahVoIP Server Master Operating System/RumahVoIP Node Server
1