- Hong Kong
- trebledj.me
Lists (12)
Sort Name ascending (A-Z)
🎨 Application
Useful desktop/web apps for various purposes.✏️ Blogging
Awesome frameworks, tools, plugins, and whatnot related to blogging.🕵️♀️ Cybersecurity
Red teaming, blue teaming, and flag hunting all in one nice list.⚡️ Embedded
Embedded systems, software, libraries, and tools.🤪 Fun
Busyness in the front, party in the back.➕ Math
Repositories related to mathematics.🧠 ML + AI
"I'll be back."🎵 Music
Music-related repositories.🖥 Programming
Repositories related to programming languages, libraries, and tools.📖 Reference
Papers, tutorials, documentation, notes, etc. Who said GitHub stars can't be used as bookmarks?🔨 Utility
Helpful utility processes or apps.🌐 Web
Repos related to the world wide web.Stars
Documentation and reverse engineering of reCAPTCHA
Modern CLI for exploring vulnerability data with powerful search, filtering, and analysis capabilities.
SURF - Advanced Go HTTP client with Chrome/Firefox browser impersonation, HTTP/3 with QUIC fingerprinting, JA3/JA4 TLS emulation, and anti-bot bypass for web automation and scraping.
A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.
Use Terraform to create your own vulnerable by design AWS IAM privilege escalation playground.
Scan VS Code extensions, npm/PyPI packages, and local git repositories for GlassWorm supply chain attack indicators. Glassworm-hunter detects invisible Unicode payloads, decoder patterns, C2 marker…
wh1te4ever / super-tart-vphone
Forked from JJTech0130/super-tarttart, but with custom AVPBooter ROM, serial I/O, DFU mode, GDB debugging (port 8000), SEP debugging (port 8001), and panic halting. See help menus for `tart create` and `tart run` for more info. Re…
A Rust-based External C2 client and Python-based server for Cobalt Strike, using third-party / white-listed endpoint as the transport layer.
A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon
Proxifier Alternative to redirect any Windows/MacOS/Linux TCP and UDP traffic to HTTP/Socks5 proxy
jsleak is a tool to find secret , paths or links in the source code during the recon.
A python script that finds endpoints in JavaScript files
SOCKS5 proxy tool that uses Azure Storage services as a means of communication.
Dump LSASS via physical memory read primitives in vulnerable kernel drivers
Arbitrary file read in Claude Code
A collection of servers which are deliberately vulnerable to learn Pentesting MCP Servers.
Exploit Eye searches for vulnerabilities and exploits using keywords you specify. Get CVE details from NVD, working exploits from Exploit-DB, and security tools from GitHub - all in one tool. Searc…
A next-generation crawling and spidering framework.
NucleiFuzzer is a robust automation tool that efficiently detects web application vulnerabilities, including XSS, SQLi, SSRF, and Open Redirects, leveraging advanced scanning and URL enumeration te…
An index of Windows binaries, including download links for executables such as exe, dll and sys files
A SOCKS proxy written in Python that randomizes your source IP address. Round-robin your evil packets through SSH tunnels or give them billions of unique source addresses!
IP Rotation from different providers - Like FireProx but for GCP, Azure, Alibaba and CloudFlare
Automating situational awareness for cloud penetration tests.
Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)