Skip to content
View tarunkant's full-sized avatar

Highlights

  • Pro

Organizations

@7aSecurity @teambi0s @IoT-Appliance-Automation @hotstar

Block or report tarunkant

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Open-source AI-augmented offensive security harness. 13+ autonomous agents, 150+ LLM providers, 5,300+ models, 7,600+ Ed25519-signed attack skills, 56+ built-in tools, 176+ MCP tools. MITRE ATT&CK,…

TypeScript 1,693 262 Updated Aug 9, 2026

A utility for arming (creating) many bees (micro EC2 instances) to attack (load test) targets (web applications).

Python 6,626 626 Updated Mar 28, 2024
Python 2 Updated Apr 24, 2026

Common User Passwords Profiler (CUPP)

Python 6,490 2,346 Updated Jul 17, 2026

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

2,166 334 Updated Oct 1, 2025

List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

Shell 9,491 1,579 Updated Jul 7, 2026
TypeScript 402 57 Updated May 26, 2026

Damn Vulnerable Bank is designed to be an intentionally vulnerable android application. This provides an interface to assess your android application security hacking skills.

Java 755 239 Updated Dec 13, 2023

"Can I take over DNS?" — a list of DNS providers and how to claim vulnerable domains.

1,100 100 Updated Mar 3, 2025

Automatically install some web hacking/bug bounty tools.

Shell 539 106 Updated Feb 15, 2024

Prototype Pollution and useful Script Gadgets

1,642 223 Updated Jan 27, 2024

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 6,141 1,318 Updated Mar 10, 2021

For basic researches, top 25 vulnerability parameters that can be used in automation tools or manual recon. 🛡️⚔️🧙

1,846 282 Updated Jun 9, 2024

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

6,309 1,225 Updated Aug 7, 2026

This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports

3,888 668 Updated Aug 10, 2026

A collection of awesome one-liner scripts especially for bug bounty tips.

3,177 630 Updated Jul 29, 2024

Pwn stuff.

PHP 1,821 391 Updated May 31, 2022

A collection of tools to perform searches on GitHub.

Python 1,503 355 Updated Feb 9, 2023

Magic hashes – PHP hash "collisions"

835 102 Updated Mar 23, 2025

Checklist of the most important security countermeasures when designing, testing, and releasing your API

23,293 2,652 Updated Jul 21, 2026

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Python 32,855 4,583 Updated Aug 9, 2026

Browser's XSS Filter Bypass Cheat Sheet

1,157 210 Updated May 6, 2017

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Python 7,575 1,176 Updated Mar 26, 2026

The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.

Python 47,703 2,155 Updated Apr 18, 2024

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication

Go 15,455 2,697 Updated Jun 10, 2026

Bypassing disabled exec functions in PHP (c) CRLF

PHP 403 63 Updated Oct 2, 2020

Web CTF CheatSheet 🐈

Ruby 2,980 579 Updated Oct 28, 2025

Stealing Wi-Fi passwords via browser's cache poisoning.

Shell 151 23 Updated Feb 19, 2022

JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool

Python 2,521 640 Updated Jan 21, 2020

Perform a MitM attack and extract clear text credentials from RDP connections

Python 1,454 319 Updated Nov 20, 2025
Next