Skip to content
View tarunkant's full-sized avatar

Highlights

  • Pro

Organizations

@7aSecurity @teambi0s @IoT-Appliance-Automation @hotstar

Block or report tarunkant

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

A utility for arming (creating) many bees (micro EC2 instances) to attack (load test) targets (web applications).

Python 6,624 627 Updated Mar 28, 2024
Python 2 Updated Apr 24, 2026

Common User Passwords Profiler (CUPP)

Python 5,954 1,983 Updated Dec 26, 2025

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

1,991 296 Updated Oct 1, 2025

List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

Shell 9,457 1,574 Updated Apr 17, 2026
TypeScript 396 55 Updated May 26, 2026

Damn Vulnerable Bank is designed to be an intentionally vulnerable android application. This provides an interface to assess your android application security hacking skills.

Java 754 239 Updated Dec 13, 2023

"Can I take over DNS?" — a list of DNS providers and how to claim vulnerable domains.

1,091 101 Updated Mar 3, 2025

Automatically install some web hacking/bug bounty tools.

Shell 538 106 Updated Feb 15, 2024

Prototype Pollution and useful Script Gadgets

1,632 222 Updated Jan 27, 2024

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 6,136 1,317 Updated Mar 10, 2021

For basic researches, top 25 vulnerability parameters that can be used in automation tools or manual recon. 🛡️⚔️🧙

1,839 281 Updated Jun 9, 2024

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

6,256 1,225 Updated Aug 14, 2024

This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports

3,775 656 Updated Jun 13, 2026

A collection of awesome one-liner scripts especially for bug bounty tips.

3,154 624 Updated Jul 29, 2024

Pwn stuff.

PHP 1,811 389 Updated May 31, 2022

A collection of tools to perform searches on GitHub.

Python 1,495 356 Updated Feb 9, 2023

Magic hashes – PHP hash "collisions"

834 104 Updated Mar 23, 2025

Checklist of the most important security countermeasures when designing, testing, and releasing your API

23,262 2,660 Updated Feb 10, 2026

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Python 32,260 4,483 Updated Jun 12, 2026

Browser's XSS Filter Bypass Cheat Sheet

1,155 212 Updated May 6, 2017

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Python 7,503 1,173 Updated Mar 26, 2026

The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.

Python 47,673 2,161 Updated Apr 18, 2024

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication

Go 15,185 2,654 Updated Jun 10, 2026

Bypassing disabled exec functions in PHP (c) CRLF

PHP 405 63 Updated Oct 2, 2020

Web CTF CheatSheet 🐈

Ruby 2,974 577 Updated Oct 28, 2025

Stealing Wi-Fi passwords via browser's cache poisoning.

Shell 152 23 Updated Feb 19, 2022

JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool

Python 2,517 640 Updated Jan 21, 2020

Perform a MitM attack and extract clear text credentials from RDP connections

Python 1,454 321 Updated Nov 20, 2025

A list of interesting payloads, tips and tricks for bug bounty hunters.

6,494 1,616 Updated Sep 14, 2023
Next