Skip to content
View federicodotta's full-sized avatar

Block or report federicodotta

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

UNIX-like reverse engineering framework and command-line toolset

C 22,559 3,134 Updated Nov 8, 2025

Welcome to the page where you will find each trick/technique/whatever I have learnt in CTFs, real life apps, and reading researches and news.

JavaScript 10,501 2,929 Updated Nov 8, 2025

The SpecterOps project management and reporting engine

Python 1,665 223 Updated Nov 8, 2025

OWASP Foundation web repository

HTML 431 82 Updated Nov 7, 2025

📱 objection - runtime mobile exploration

Python 8,617 938 Updated Nov 7, 2025

Impacket is a collection of Python classes for working with network protocols.

Python 15,077 3,814 Updated Nov 7, 2025

Metasploit Framework

Ruby 36,852 14,607 Updated Nov 6, 2025

Turbo Intruder is a Burp Suite extension for sending large numbers of HTTP requests and analyzing the results.

Kotlin 1,662 226 Updated Nov 6, 2025

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static a…

JavaScript 19,751 3,509 Updated Nov 5, 2025

Clone this repo to build Frida

Meson 18,944 1,934 Updated Nov 5, 2025

Testing TLS/SSL encryption anywhere on any port

Shell 8,673 1,101 Updated Nov 4, 2025

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 71,489 16,193 Updated Nov 2, 2025

Ghidra is a software reverse engineering (SRE) framework

Java 61,913 6,881 Updated Oct 30, 2025

J2EEScan is a plugin for Burp Suite Proxy. The goal of this plugin is to improve the test coverage during web application penetration tests on J2EE applications.

Java 670 186 Updated Oct 29, 2025

Automated All-in-One OS Command Injection Exploitation Tool.

Python 5,510 899 Updated Oct 27, 2025

Pre-Built Vulnerable Environments Based on Docker-Compose

Dockerfile 19,752 4,714 Updated Sep 19, 2025

Universal Radio Hacker: Investigate Wireless Protocols Like A Boss

Python 11,929 945 Updated Jul 31, 2025

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automa…

Python 1,114 243 Updated Jul 3, 2025

Mallet is an intercepting proxy for arbitrary protocols

Java 286 43 Updated Apr 14, 2025

A collection of Semgrep rules derived from the OWASP MASTG specifically for Android applications.

Java 303 30 Updated Jul 29, 2024

Full featured multi arch/os debugger built on top of PyQt5 and frida

Python 1,311 174 Updated May 16, 2024

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Java 8,576 1,843 Updated Mar 31, 2024

Primefaces <= 5.2.21, 5.3.8 or 6.0 - Remote Code Execution Exploit

Python 91 25 Updated Feb 27, 2024

Open-source, cross platform Qt based IDE for reverse-engineering Android application packages.

C++ 3,071 555 Updated Oct 6, 2023

idb is a tool to simplify some common tasks for iOS pentesting and research

Ruby 950 161 Updated Mar 25, 2023

My bachelor thesis

2 Updated Jun 21, 2022

[WIP] Crappy iOS app analyzer

Vue 1,668 227 Updated Nov 14, 2021

Big Iron Recon & Pwnage

Python 125 33 Updated Nov 8, 2021

.NET debugger and assembly editor

C# 28,506 5,396 Updated Dec 20, 2020
Next