security researcher and appsec professional
mySapAdventures. A quick methodology on testing / hacking SAP Applications for n00bz and bug bounty hunters
258mazda_getInfo. A PoC that the USB port is an attack surface for a Mazda car's infotainment system and how Mazda hacks are made
166canTot. quick and dirty canbus h4xing framework
150IRC-Bot-Hunters. a collection of Metasploit PoC exploits I wrote for IRC Botnets that allows RCE
78myFlipperInfrared. some of my learned remotes and IR signals while doing Infrared Testing using Flipper Zero
33TuxLogCleaner. a simple log cleaner for Linux
27Flipper-Collections. A couple of my Flipper Zero payloads and files
16sploitchits. My collection of exploit development skeletons for fuzzing, overwriting the stack, remote code execution, etc.
16honeypy. A simple web app honeypot project which leverages SimpleHTTPServer and has a classic theme from the 80's
12cccam-info. A python script that scrapes CCcam information mostly from satellite receivers
10sapConfigServlet_rce. checks for SAP ConfigServlet Unauthenticated Remote Code Execution Vulnerability
4attackvector. AttackVector Linux
3commandsshbotnet. A PoC for command and conquer SSH botnet
3evilcrow-webRequests. Python scripts for automating web requests in EvilCrowRF
3awesome-vehicle-security. 🚗 A curated list of resources for learning about vehicle security and car hacking.
3awesome. :sunglasses: Curated list of awesome lists
2msf-modules. Ruby
2CVE-2025-48466. Modbus Packet Injection on Advantech WISE 4060LAN / IoT Gateway for door control
2nishang. Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
2Piata-Common-Usernames-and-Passwords. A wordlist I harvested from Piata, a mass SSH scanner
2openioc. Control your car inputs (e.g. switches) and outputs (e.g. lights) with software over CAN
2HunterEK_exploit. Arbitrary File Upload Exploit for Hunter Exploit Kit
2xstchecker. checks if the website is vulnerable to Cross-Site Tracing (XST)
2hw-hacking-lab. Guide to setting up a hardware hacking lab
1routersploit. Exploitation Framework for Embedded Devices
1RFmoggy. NodeMCU ESP8266 CC1101 Sub1GHz OOK transmitter & brute forcer w/ pre-saved signals (e.g. TouchTunes Jukebox)
1confsec. Security, hacking conferences (list)
1minipwner. A script to configure a TP-Link MR3040 running OpenWRT into a simple, yet powerful penetration-testing "dropbox".
1awesome-flipperzero. 🐬 A collection of awesome resources for the Flipper Zero device.
1packet_squirrel. Running packet squirrel in qemu and create a dev environment
1awesome-canbus. :articulated_lorry: A curated list of awesome CAN bus tools, hardware and resources
1PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
1APTSimulator. A toolset to make a system look as if it was the victim of an APT attack
1tools. Tools from ROOTCON Labs
1dvbsnoop. This is a fork of the original dvbsnoop hosted on sourceforge.net. I've applied a few minor patches and will continue to add contributed patches from sf.net as well as minor feature enhancements.
1BTLE. Bluetooth Low Energy (BLE) packet sniffer and transmitter for both standard and non standard (raw bit) based on Software Defined Radio (SDR).
1ESP32-WiFi-Hash-Monster. WiFi Hash Purple Monster, store EAPOL & PMKID packets in an SD CARD using a M5STACK / ESP32 device
1Carpunk. The CAN Injection Toolkit
1vulnstrap. A responsive vulnerable web application for practicing your web pentesting skills or for demo purposes.
1