Starred repositories
A Claude Code skill bundle for bug hunting and external red-team work - 82 skills, 15 slash commands, 681 disclosed-report patterns curated across 24 core vulnerability classes, plus enterprise ideβ¦
HTTP Request Smuggling over HTTP/2 Cleartext (h2c)
Nmap script to guess* a GitLab version.
A next generation version of enum4linux (a Windows/Samba enumeration tool) with additional features like JSON/YAML export. Aimed for security professionals and CTF players.
XSS payloads for bypassing WAF. This repository is updating continuously.
Solutions for Ethernaut done fully using Python and web3.py
My small collection of reports templates
Mangle is a tool that manipulates aspects of compiled executables (.exe or DLL) to avoid detection from EDRs
A combined wordlists for files and directory discovery
List of configuration files from WEB-INF and META-INF for use in Unvalidated Forwards and JSP Include vulnerabilities.
A fork and successor of the Sulley Fuzzing Framework
Magicspoofing it's a python script that checks & test SPF/DMARC DNS records an tries to spoof a domain with a open relay mail system.
A wordlist of API names for web application assessments
Chart-Of-Wordlist helps to create your own custom wordlist. Also in one repository, you can find a list of awesome wordlist.
Small but effective wordlist for brute-forcing and discovering hidden things.
Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.
Android penetration testing tool for Kali linux
Debian OpenSSL Predictable PRNG (CVE-2008-0166)
π Improve your files enumeration with specific extensions!
A list of useful payloads and bypass for Web Application Security and Pentest/CTF


