Skip to content
View almroot's full-sized avatar
  • ---- ''
  • ---- ''

Block or report almroot

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports

3,699 653 Updated Apr 15, 2026

scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.

JavaScript 4,108 434 Updated Apr 15, 2026

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

CSS 11,167 3,050 Updated Apr 15, 2026

Interesting APT Report Collection And Some Special IOCs

Python 2,962 565 Updated Apr 13, 2026

Directory/File, DNS and VHost busting tool written in Go

Go 13,599 1,567 Updated Apr 10, 2026

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to …

1,154 169 Updated Apr 3, 2026

TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.

C 25,523 3,200 Updated Mar 31, 2026

WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

Python 6,294 1,037 Updated Mar 26, 2026

A list of public penetration test reports published by several consulting firms and academic security groups.

HTML 9,500 2,153 Updated Mar 22, 2026

Random fake data generator written in go

Go 5,332 294 Updated Mar 4, 2026

J2EEScan is a plugin for Burp Suite Proxy. The goal of this plugin is to improve the test coverage during web application penetration tests on J2EE applications.

Java 676 186 Updated Oct 29, 2025

Go package for Ja3 TLS client and server hello fingerprints

Go 154 21 Updated Oct 24, 2025

An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.

CSS 5,927 1,219 Updated Oct 20, 2025

My proof-of-concept exploits for the Linux kernel

C 1,572 370 Updated Sep 11, 2025

Handshake Daemon & Full Node

JavaScript 2,056 301 Updated Aug 22, 2025

Content-Type Research

661 65 Updated Jun 29, 2025

JA3 is a standard for creating SSL client fingerprints in an easy to produce and shareable way.

Python 3,086 312 Updated May 1, 2025

Randomized testing for Go

Go 4,850 276 Updated Sep 24, 2024

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

6,163 1,211 Updated Aug 14, 2024

Notes about attacking Jenkins servers

Python 2,091 326 Updated Jul 10, 2024

The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.

Python 47,619 2,160 Updated Apr 18, 2024

A collection of PHP backdoors. For educational or testing purposes only.

PHP 2,259 468 Updated Mar 9, 2024

Prototype Pollution and useful Script Gadgets

1,610 221 Updated Jan 27, 2024

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

PHP 8,874 2,120 Updated Nov 10, 2023

A list of interesting payloads, tips and tricks for bug bounty hunters.

6,420 1,613 Updated Sep 14, 2023

Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。

Shell 2,041 370 Updated Jul 21, 2023

A cross-platform asynchronous HTTP(S) proxy server in C#.

C# 1,982 653 Updated Jun 29, 2023

Git All the Payloads! A collection of web attack payloads.

Shell 3,928 989 Updated May 15, 2023

HostHunter a recon tool for discovering hostnames using OSINT techniques.

Python 1,157 193 Updated Mar 30, 2023

List of DNS violations by implementations, software and/or systems

243 28 Updated Mar 30, 2023
Next