Skip to content
View h4x0rl33tx's full-sized avatar
🥷
Hunting
🥷
Hunting

Block or report h4x0rl33tx

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

List of RegEx DoS (ReDoS) CVEs and resources

30 3 Updated Feb 6, 2023

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

JavaScript 151,290 23,443 Updated Apr 10, 2026

Top disclosed reports from HackerOne

Python 5,655 1,018 Updated Mar 30, 2026

🐛 A list of writeups from the Google VRP Bug Bounty program

Python 1,472 250 Updated Mar 26, 2026

AI-powered bug bounty hunting from your terminal - recon, 20 vuln classes, autonomous hunting, and report generation. All inside Claude Code.

Python 1,691 295 Updated Apr 7, 2026

FOFA Hacking Queries - API Key Hunter

41 7 Updated Mar 29, 2026

Web Fuzzing Box - Web 模糊测试字典与一些Payloads

HTML 2,700 435 Updated Mar 23, 2026

A curated list of awesome GraphQL Security frameworks, libraries, software and resources

389 28 Updated Feb 15, 2024

The ultimate open-source library of highly-structured prompts, tools, and specialized capabilities for autonomous AI agents.

Python 4 5 Updated Mar 6, 2026

List of Mine Private wordlist i use for fuzzing

91 23 Updated Feb 25, 2026

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting) vulnerabilities on sites where injections are blocke…

JavaScript 640 105 Updated Apr 10, 2026

Get PROXY List that gets updated everyday

5,451 1,086 Updated Apr 11, 2026

🚀 Free HTTP, SOCKS4, & SOCKS5 Proxy List * Updated every 5 minutes *

4,478 499 Updated Apr 11, 2026

A lightweight GPT model, trained to discover subdomains.

Python 360 19 Updated Dec 18, 2025

"Can I take over DNS?" — a list of DNS providers and how to claim vulnerable domains.

1,085 102 Updated Mar 3, 2025

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Python 5,620 795 Updated Feb 8, 2025

Tips and Tutorials for Bug Bounty and also Penetration Tests.

1,871 425 Updated Oct 7, 2025

Tools and methods that I personally use for Recon and Exploitations

52 20 Updated May 1, 2025

💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp…

Python 3,659 460 Updated Apr 10, 2026
HTML 11 6 Updated Oct 25, 2021

An Automated Subdomain Enumeration Tool

Shell 289 66 Updated Oct 16, 2024

A security research tool designed to intercept and analyze OAuth requests.

Python 6 Updated Feb 20, 2025

Reflected XSS Payload List for Vue.js (2 & 3)

15 3 Updated Jan 12, 2023

Repositories, Links, Payloads, Blogs, Tools, etc.. which I think might be useful for pentesting and bug bounty

50 5 Updated Jan 6, 2026

jsleak is a tool to find secret , paths or links in the source code during the recon.

Go 584 68 Updated Sep 25, 2025

70k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒

Python 1,225 152 Updated Apr 11, 2026

A list of interesting payloads, tips and tricks for bug bounty hunters.

6,420 1,614 Updated Sep 14, 2023

Pentesting and Bug Bounty Notes, Cheetsheets and Guide for Ethical Hacker, Whitehat Pentesters and CTF Players.

PHP 612 88 Updated Apr 9, 2026
Next