Skip to content
View almroot's full-sized avatar
  • ---- ''
  • ---- ''

Block or report almroot

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Random fake data generator written in go

Go 5,265 293 Updated Dec 3, 2025

Go package to generate text from regex definitions

Go 97 19 Updated Sep 4, 2020

Prototype Pollution and useful Script Gadgets

1,550 216 Updated Jan 27, 2024

The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.

Python 47,527 2,161 Updated Apr 18, 2024

Process Injection Techniques with Golang

Go 80 15 Updated May 29, 2020

Simple websites vulnerable to Server Side Template Injections(SSTI)

PHP 412 87 Updated Mar 16, 2023

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to …

1,006 157 Updated Jun 24, 2024

Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。

Shell 2,025 370 Updated Jul 21, 2023

Lesser Known Web Attack Lab

CSS 330 47 Updated Feb 7, 2020

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

JavaScript 10,674 2,962 Updated Dec 22, 2025

A list of cloud ranges from different providers.

Ruby 462 74 Updated Oct 20, 2022

Content-Type Research

650 66 Updated Jun 29, 2025

Compilation of ready to run exploits, advisories, tools and online key generators for embedded devices.

HTML 139 43 Updated Mar 13, 2016

This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports

3,579 639 Updated Dec 22, 2025

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

5,975 1,184 Updated Aug 14, 2024

List of DNS violations by implementations, software and/or systems

241 28 Updated Mar 30, 2023
PHP 12 2 Updated Jun 7, 2018

Signature-free approach library to detect injection and commanding attacks

C 97 21 Updated Jan 25, 2022

Go package for Ja3 TLS client and server hello fingerprints

Go 154 21 Updated Oct 24, 2025

JA3 is a standard for creating SSL client fingerprints in an easy to produce and shareable way.

Python 3,038 307 Updated May 1, 2025

Notes about attacking Jenkins servers

Python 2,086 333 Updated Jul 10, 2024

Interesting APT Report Collection And Some Special IOCs

Python 2,797 545 Updated Dec 18, 2025

This script is intended to automate your reconnaissance process in an organized fashion

Shell 2,006 580 Updated Aug 19, 2021

A permutation generation tool written in golang

Go 207 29 Updated Jul 15, 2019

A list of shodan filters

579 123 Updated Nov 25, 2018

HostHunter a recon tool for discovering hostnames using OSINT techniques.

Python 1,143 193 Updated Mar 30, 2023

Asynchronous wordlist based DKIM scanner

Python 58 16 Updated Apr 27, 2021

A security tool to fingerprint PNG libraries used by web applications

Python 81 9 Updated Apr 28, 2019

Handshake Daemon & Full Node

JavaScript 2,027 298 Updated Aug 22, 2025
Next