Skip to content
View mfkrypt's full-sized avatar

Highlights

  • Pro

Block or report mfkrypt

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
63 stars written in Python
Clear filter

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 71,433 16,182 Updated Nov 2, 2025

Most advanced XSS scanner.

Python 14,448 2,032 Updated Apr 26, 2025

Nginx configuration static analyzer

Python 8,535 442 Updated Jul 28, 2024

🕷️ An undetectable, powerful, flexible, high-performance Python library to make Web Scraping Easy and Effortless as it should be!

Python 8,092 461 Updated Oct 29, 2025

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Python 5,431 775 Updated Feb 8, 2025

Cybersecurity AI (CAI), the framework for AI Security

Python 5,092 703 Updated Nov 6, 2025

An OSINT tool to search for accounts by username and email in social networks.

Python 4,989 585 Updated Jul 13, 2025

Top disclosed reports from HackerOne

Python 4,972 900 Updated Oct 12, 2025

SSH server & client security auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc)

Python 3,952 198 Updated Sep 1, 2025

đź’€ Generate a bunch of malicious pdf files with phone-home functionality. Can be used with Burp Collaborator or Interact.sh

Python 3,532 461 Updated Nov 6, 2025

Automatic SSRF fuzzer and exploitation tool

Python 3,391 555 Updated Sep 4, 2025

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Python 3,225 397 Updated Apr 18, 2023

Tool for Active Directory Certificate Services enumeration and abuse

Python 3,222 433 Updated Sep 30, 2025

Flutter Reverse Engineering Framework

Python 2,296 260 Updated Sep 13, 2025

Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.

Python 1,950 288 Updated Jul 12, 2025

BBT - Bug Bounty Tools (examplesđź’ˇ)

Python 1,853 476 Updated Apr 5, 2024

OSINT Tool: Generate username lists for companies on LinkedIn

Python 1,555 206 Updated Jan 15, 2024

Flutter Reverse Engineering Framework

Python 1,423 188 Updated Apr 11, 2022

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Python 1,342 133 Updated Jul 14, 2025

New generation of wmiexec.py

Python 1,206 151 Updated Oct 17, 2025

Username enumeration and password spraying tool aimed at Microsoft O365.

Python 939 113 Updated Nov 6, 2024

Python script to enumerate users, groups and computers from a Windows domain through LDAP queries

Python 926 158 Updated Apr 20, 2022

Android security insights in full spectrum.

Python 926 125 Updated Jul 26, 2025

A simple tool for bypassing file upload restrictions.

Python 879 136 Updated Jul 22, 2024

A reverse engineering tool for decompiling and disassembling the React Native Hermes bytecode

Python 839 77 Updated Apr 7, 2024

A universal memory dumper using Frida

Python 826 149 Updated Aug 7, 2024

Just another Powerview alternative but on steroids

Python 817 82 Updated Nov 2, 2025

Windows Remote Administration Tool that uses Discord, Telegram and GitHub as C2s

Python 661 150 Updated Jul 18, 2024

Find, analyze, and check for exposed IP cameras with open ports, known vulnerabilities, and weak login credentials.

Python 643 113 Updated Jul 19, 2025

Advanced Active Directory network topology analyzer with SMB validation, multiple authentication methods (password/NTLM/Kerberos), and comprehensive network discovery. Export results as BloodHound‑…

Python 600 65 Updated Oct 21, 2025
Next