Skip to content
View honoki's full-sized avatar

Block or report honoki

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Agentic pentest tooling. Currently achieving 81% (KIMI K2.5) on XBOW's benchmark in full black-box. Completely Self-hosted. Every model available on LiteLLM (Ollama, anthropic, openai...)

Python 292 50 Updated Aug 7, 2026

Abuse trust-boundaries to bypass firewalls and network controls

Go 431 76 Updated Jul 10, 2026
Python 197 30 Updated Apr 23, 2025

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Python 1,503 148 Updated Jul 14, 2025

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting) vulnerabilities on sites where injections are blocke…

JavaScript 712 121 Updated Aug 12, 2026

A scheduler for GPU/CPU tasks

C 437 43 Updated Mar 6, 2024

A small command-line utility to artificially limit the input rate to STDIN.

Go 18 1 Updated Feb 14, 2024

Blazing fast, advanced Padding Oracle exploit

Go 280 28 Updated Dec 12, 2025
Shell 11 Updated Apr 1, 2023

Unleash the power of cloud

Python 818 115 Updated Nov 19, 2024

A fast, simple, recursive content discovery tool written in Rust.

Rust 8,012 631 Updated Apr 15, 2026

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Python 5,304 792 Updated May 19, 2026

Simple DNS Rebinding Service

C 757 88 Updated Jan 16, 2020

.NET debugger and assembly editor

C# 29,691 5,612 Updated Dec 20, 2020

Real-world infosec wordlists, updated regularly

1,782 207 Updated Aug 14, 2026

A cheatsheet for exploiting server-side SVG processors.

802 102 Updated Jul 2, 2020

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

Go 1,100 137 Updated Aug 5, 2026

MassDNS wrapper written in go to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard filtering and easy input-output support.

Go 1,659 218 Updated Aug 10, 2026

Generates permutations, alterations and mutations of subdomains and then resolves them

Python 2,504 447 Updated Jan 9, 2025

PwnFox is a Firefox/Burp extension that provide usefull tools for your security audit.

JavaScript 1,337 124 Updated Aug 7, 2024

RCE 0-day for GhostScript 9.50 - Payload generator

Python 543 106 Updated Sep 8, 2021

Self contained htaccess shells and attacks

Shell 1,077 195 Updated Feb 17, 2022

A Burp Suite extension made to automate the process of finding reverse proxy path based SSRF.

Python 184 32 Updated Nov 22, 2021

This repository includes a set of scripts to install a Burp Collaborator Server in a docker environment, using a LetsEncrypt wildcard certificate. The objective is to simplify as much as possible t…

Shell 302 44 Updated Apr 9, 2026

A high performance TCP SYN port scanner.

Rust 317 26 Updated Mar 2, 2024

BBT - Bug Bounty Tools (examples💡)

Python 1,906 467 Updated Apr 5, 2024

Base64-based encryption oracle exploit for CVE-2017-9248 (Telerik UI for ASP.NET AJAX dialog handler)

Python 177 49 Updated Dec 22, 2020

Enables full-text searching of CouchDB documents using Lucene

Java 772 144 Updated Mar 27, 2022

Easily turn single threaded command line applications into a fast, multi-threaded application with CIDR and glob support.

Python 1,294 188 Updated Sep 12, 2025
Python 9 1 Updated Mar 29, 2021
Next