Skip to content
View tillson's full-sized avatar

Highlights

  • Pro

Organizations

@ireallydontcare

Block or report tillson

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 71,496 16,194 Updated Nov 2, 2025

The Swift Programming Language

C++ 69,281 10,584 Updated Nov 8, 2025

A command-line benchmarking tool

Rust 26,659 427 Updated Oct 1, 2025

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

Go 18,344 1,586 Updated Oct 27, 2025

Evals is a framework for evaluating LLMs and LLM systems, and an open-source registry of benchmarks.

Python 17,247 2,832 Updated Nov 3, 2025

Atmosphère is a work-in-progress customized firmware for the Nintendo Switch.

C++ 17,145 1,339 Updated Oct 8, 2025

Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com

PowerShell 7,398 1,336 Updated Oct 16, 2025

A static analysis security vulnerability scanner for Ruby on Rails applications

Ruby 7,161 758 Updated Nov 4, 2025

Reconnaissance tool for GitHub organizations

Go 6,084 843 Updated Sep 20, 2022

The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power schedules, MOpt mutators, unicorn_mode, and a lot more!

C 6,071 1,185 Updated Nov 5, 2025

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

5,885 1,170 Updated Aug 14, 2024

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Python 5,437 775 Updated Feb 8, 2025

Graph database optimized for fast analysis and real-time data processing. It is provided as an extension to PostgreSQL.

C 3,966 459 Updated Oct 17, 2025

Keep track of internships for Summer 2020 for undergraduates interested in tech./SWE/related fields

Python 1,785 239 Updated Oct 12, 2020

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

Go 1,359 198 Updated Oct 24, 2025

Fast DNS Lookup Library and CLI Tool

Go 1,039 143 Updated Nov 3, 2025

🎄Visualization and annotation of phylogenetic trees

R 893 180 Updated Oct 30, 2025

Train Tesseract LSTM with make

Python 703 215 Updated Apr 18, 2025

A command-line utility designed to discover URLs for a given domain in a simple, efficient way. It works by gathering information from a variety of passive sources, meaning it doesn't interact dire…

Go 646 73 Updated Oct 20, 2025

A set of Zeek scripts to detect ATT&CK techniques.

Zeek 616 83 Updated Jun 26, 2024

A suite of secret scanners built in Rust for performance. Based on TruffleHog (https://github.com/dxa4481/truffleHog) which is written in Python.

Rust 534 64 Updated Jun 28, 2025

A fast Go Avro codec

Go 489 122 Updated Oct 20, 2025

An automated approach to performing recon for bug bounty hunting and penetration testing.

Shell 454 103 Updated Jul 21, 2020

Brosec - An interactive reference tool to help security professionals utilize useful payloads and commands.

JavaScript 355 89 Updated Jan 12, 2023

An up-to-date export of cloud provider IP address ranges

345 48 Updated Jul 25, 2025

Collection of Meta's DNS Libraries

Go 283 29 Updated Oct 24, 2025

Student submissions for the WWDC 2019 Scholarship

282 148 Updated Jul 20, 2021

Poor (rich?) man's bug bounty pipeline https://dubell.io

Shell 276 60 Updated Apr 24, 2023

Visualization tool for Graph Neural Networks

TypeScript 254 29 Updated Sep 20, 2022

This is an intentionally vulnerable smart contract truffle deployment aimed at allowing those interested in smart contract security to exploit a wide variety of issues in a safe environment.

JavaScript 119 30 Updated Oct 24, 2018
Next