Skip to content
View koutto's full-sized avatar

Block or report koutto

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

A powerful WAF (HTTP 403/401) and URL parser bypass tool developed in Go, designed to preserve exact URL paths and structures during testing.

Go 50 4 Updated Jun 28, 2026

This repository contains wordlists for each versions of common web applications and content management systems (CMS). Each version contains a wordlist of all the files directories for this version.

Python 539 120 Updated Dec 4, 2024

Detect and bypass web application firewalls and protection systems

Python 2,918 470 Updated Aug 11, 2024

📚 An ultimate collection wordlists of the best-known CMS

96 25 Updated Jun 10, 2024

A curated list of wordlists for bruteforcing and fuzzing

1,275 199 Updated Jul 10, 2026

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive data, such as API endpoints and potential security v…

Go 529 59 Updated Jul 12, 2026

Feature-rich single-binary file server for red teamers and developers. HTTP/S · WebDAV · FTP/SFTP · SMB · LDAP/S · NTLM hash capture · DNS/SMTP callbacks · TLS · Auth · Share links. A powerful pyth…

Go 949 55 Updated Aug 6, 2026

Offline-first, searchable arsenal for pentesting & bug bounty: payloads, a click-to-build command generator, GTFOBins, wordlists, embedded CyberChef, reverse shells, checklists & an engagement trac…

CSS 166 23 Updated Jul 9, 2026

A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.

200,699 20,624 Updated Apr 20, 2026

One CLAUDE.md file. Keeps Claude responses terse. Reduces output verbosity on heavy workflows. Drop-in, no code changes.

Python 5,932 461 Updated Jun 16, 2026

🥷 Engineering habits you already know, turned into skills Claude can run.

Python 6,788 401 Updated Aug 8, 2026

The best-benchmarked open-source AI memory system. And it's free.

Python 58,231 7,483 Updated Aug 8, 2026

Teams-first Multi-agent orchestration for Claude Code

TypeScript 38,443 3,459 Updated Aug 7, 2026

A curated list of awesome Claude Skills, resources, and tools for customizing Claude AI workflows — particularly Claude Code

14,564 1,815 Updated Apr 28, 2026

Claude Code plugin: automated code review loop with Codex

Shell 714 45 Updated Mar 15, 2026

Agent Orchestration Command Center

TypeScript 3,221 340 Updated Aug 8, 2026

Surface AI blindspots before you ship. Put up to 8 AI models on every research, design or coding task.

Shell 3,946 369 Updated Aug 8, 2026

Let your AI go full send. Your home directory stays home.

Go 628 49 Updated Jul 22, 2026

⛰️A General Hill-climbing AI harness that helps you move from Current State to Ideal State in both Life and Work.

TypeScript 17,286 2,336 Updated Aug 7, 2026

An agentic skills framework & software development methodology that works.

Shell 269,304 24,057 Updated Aug 8, 2026

Real-world infosec wordlists, updated regularly

1,778 207 Updated Aug 8, 2026
Java 86 12 Updated May 26, 2026

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

JavaScript 238,815 36,264 Updated Aug 8, 2026

EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify misconfigurations, assess privilege-escalation paths, and s…

PowerShell 157 22 Updated Feb 25, 2026

bypass-url-parser

Python 1,134 122 Updated Aug 8, 2026

A source code static analysis platform for AppSec enthusiasts.

Python 278 37 Updated Apr 27, 2026

A Beacon Object File (BOF) that talks directly to Windows authentication packages through the LSA untrusted/trusted client interface, without touching LSASS process memory.

C 297 38 Updated Feb 21, 2026

Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production.

TypeScript 46,551 5,380 Updated Aug 6, 2026

BYOVD: Use 360 ​​WFP driver to block EDR/XDR network connection.

C 129 20 Updated Feb 10, 2026

The ADSyncDump BOF is a port of Dirk-Jan Mollema's adconnectdump.py / ADSyncDecrypt into a Beacon Object File (BOF) with zero dependencies.

C 182 20 Updated Sep 3, 2025
Next