Skip to content
View h3ak's full-sized avatar

Block or report h3ak

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

A high-speed tool for passively gathering URLs, optimized for efficient and comprehensive web asset discovery without active scanning.

Go 856 65 Updated Jan 5, 2026

一款快速、全面、易用的页面信息提取工具,可快速发现和提取页面中的JS、URL和敏感信息。

Go 3,108 230 Updated Jan 5, 2024

Vue框架未授权接口扫描工具

74 5 Updated May 28, 2025

oss存储桶遍历漏洞利用脚本

Python 91 5 Updated Nov 23, 2024

网络安全 · 攻防对抗 · 蓝队清单,中文版

HTML 941 124 Updated Dec 3, 2023

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

Shell 7,388 1,145 Updated Mar 25, 2026

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the …

Go 27,713 3,329 Updated Apr 1, 2026

云资产管理工具 目前工具定位是云安全相关工具,目前是两个模块 云存储工具、云服务工具, 云存储工具主要是针对oss存储、查看、删除、上传、下载、预览等等 云服务工具主要是针对rds、服务器的管理,查看、执行命令、接管等等

1,146 76 Updated Feb 26, 2026

Windows应急响应工具---Hawkeye(鹰眼)。集Windows日志分析,进程扫描,主机信息于一体的综合应急响应分析工具

663 28 Updated Jul 13, 2025

Linux应急处置/信息搜集/漏洞检测工具,支持基础配置/网络流量/任务计划/环境变量/用户信息/Services/bash/恶意文件/内核Rootkit/SSH/Webshell/挖矿文件/挖矿进程/供应链/服务器风险等13类70+项检查

Shell 2,060 428 Updated Jun 19, 2024

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Go 34,284 224 Updated Mar 30, 2026

Find, verify, and analyze leaked credentials

Go 25,299 2,275 Updated Apr 1, 2026

Cloud Native Runtime Security

C++ 8,816 999 Updated Apr 1, 2026

一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。(An intranet comprehensive scanning tool, enabling one-click automated, all-round vulnerability scanning)

Go 13,544 1,866 Updated Jan 31, 2026

deadpool代理池工具,可从hunter、quake、fofa等网络空间测绘平台取高质量socks5代理,或本地导入socks5代理,轮询使用代理进行流量转发。

Go 672 80 Updated Apr 21, 2025

备份的漏洞库,3月开始我们来维护

1,859 502 Updated Mar 31, 2026

ScopeSentry-Cyberspace mapping, subdomain enumeration, port scanning, sensitive information discovery, vulnerability scanning, distributed nodes

Go 1,476 209 Updated Apr 1, 2026

dirsx 是一款能够自动化过滤扫描结果的目录扫描工具

357 16 Updated Mar 12, 2026

best tool for finding SQLi,CRLF,XSS,LFi,OpenRedirect

Python 1,546 333 Updated Dec 7, 2025

NSudo - A Powerful System Administration Tool

C++ 20 23 Updated Feb 6, 2015

KCon is a famous Hacker Con powered by Knownsec Team.

JavaScript 4,669 1,400 Updated Aug 28, 2024

一款用于安全测试中信息收集的自动化工具

Go 147 10 Updated Aug 6, 2024

面向红队的, 高性能高度自由可拓展的自动化扫描引擎 | A highly controllable and extensionable automated scanning engine for red teams

Go 2,037 188 Updated Feb 3, 2026

Wscan is a web security scanner that focuses on web security, dedicated to making web security accessible to everyone.

Go 704 80 Updated Jan 6, 2026

一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.

Java 2,174 233 Updated Aug 21, 2025

Gather and update all available and newest CVEs with their PoC.

HTML 7,651 957 Updated Apr 1, 2026

Burp插件,根据自定义来达到对数据包的处理(适用于加解密、爆破等),类似mitmproxy,不同点在于经过了burp中转,在自动加解密的基础上,不影响APP、网站加解密正常逻辑等。

Java 1,356 97 Updated Mar 20, 2026

远程调用(rpc)浏览器方法,免去抠代码补环境

Go 2,232 450 Updated Jan 9, 2026

Community curated list of templates for the nuclei engine to find security vulnerabilities.

JavaScript 12,104 3,410 Updated Apr 1, 2026