Skip to content
View Tasfiul-Hedayet's full-sized avatar

Block or report Tasfiul-Hedayet

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

π RuView turns commodity WiFi signals into real-time spatial intelligence, vital sign monitoring, and presence detection — all without a single pixel of video.

Rust 91,032 12,094 Updated Aug 20, 2026

Use Garry Tan's exact Claude Code setup: 23 opinionated tools that serve as CEO, Designer, Eng Manager, Release Manager, Doc Engineer, and QA

TypeScript 128,816 19,381 Updated Aug 20, 2026

A Bash script for automated nuclei dast scanning by using passive urls

Shell 133 32 Updated Mar 5, 2025

Source control for agents. Use multiple coding agents, track their changes and query them in one place

TypeScript 1,210 217 Updated Aug 19, 2026

Supports RSC fingerprinting and exploitation of the React component vulnerability CVE-2025-55182.

JavaScript 589 88 Updated Dec 5, 2025

176 vulnerabilities in Samsung preinstalled Android apps

Java 328 82 Updated Jul 15, 2026

web cache deception detect

Python 43 4 Updated Aug 10, 2026

A powerful and lightweight tool for bug bounty hunters and security researchers to identify hardcoded secrets, API keys, tokens, credentials, and other sensitive data in code repositories, web appl…

Python 14 6 Updated Aug 29, 2025

A community-powered collection of all known bug bounty platforms, vulnerability disclosure platforms, and crowdsourced security platforms currently active on the Internet.

Python 1,098 215 Updated Aug 11, 2026

⚔️ Community maintained directory, MCP and API of 3,000+ active bug bounty programs and VDPs

TypeScript 398 71 Updated Aug 18, 2026

Legitimate bug bounty programs value ethical practices and provide clear rewards to researchers for identifying security flaws

49 2 Updated Sep 22, 2024

SelfHosted - Bug Bounty Programs | Discover new and fresh bug bounty programs across platforms. Updated frequently to always display the newest public programs.

2 1 Updated Nov 24, 2025

A ruby gem for defending against Server Side Request Forgery (SSRF) attacks

Ruby 124 33 Updated Jul 6, 2026

This project crawls bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) hourly and dumps them into the bounty-targets-data repo

Ruby 724 132 Updated Aug 15, 2026

Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh

Python 1,181 207 Updated Jul 31, 2026

Master Thick Client Penetration Testing: Explore practical methodologies, uncover vulnerabilities, and enhance security.

22 2 Updated Apr 6, 2024

Damn Vulnerable API

CSS 97 52 Updated Sep 22, 2025

Turbo Intruder is a Burp Suite extension for sending large numbers of HTTP requests and analyzing the results.

Kotlin 1,796 237 Updated Aug 13, 2026

My Main App Hacking CheckList

34 10 Updated Jun 20, 2026
HTML 197 83 Updated Jan 23, 2026

A simple Python tool for performing Google Dorking on a target domain to gather information and discover potential vulnerabilities. This script automates the process of running multiple dork querie…

Python 1 1 Updated Feb 20, 2025

Swift SDK for fetching and filtering Forex Factory's weekly financial events with ease.

Swift 1 Updated Apr 19, 2025

Automatic SQL injection and database takeover tool

Python 38,227 6,339 Updated Aug 18, 2026

declutters url lists for crawling/pentesting

Python 1,586 173 Updated Feb 23, 2025

Open-source Claude Code skills, agents, and slash commands for AI-powered penetration testing, bug bounty hunting, and security research

Python 476 73 Updated Jul 29, 2026

The Template Injection Table is intended to help during the testing of an application for template injection vulnerabilities.

SCSS 116 13 Updated Apr 27, 2026

🎯 Chrome Extension - Passive scanner for Dependency Confusion vulnerabilities in npm/PyPI packages

JavaScript 40 10 Updated Jan 31, 2026

Takes a URL and checks the system for the tilde enum vuln and then find the files.

Python 2 Updated Dec 13, 2019

Potentially dangerous files

3 Updated Feb 9, 2022

GimmeYourPassword (GYP) is a tool designed to perform tests on reset password features on websites and analyze the results to identify vulnerabilities and interesting behaviors

Python 4 Updated Aug 20, 2026
Next