Skip to content
View joohoi's full-sized avatar
🦨
🦨

Sponsors

@Snownull
@projectdiscovery

Organizations

@certbot @TurkuSec @ffuf @citysecs @kybervpk @visma-prodsec

Block or report joohoi

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Rust tool to detect cell site simulators on an orbic mobile hotspot

Rust 3,054 223 Updated Oct 9, 2025

A proof-of-concept of a self-replicating malware for Maven build environments.

Java 5 Updated Mar 27, 2025

Webhood is a privately hosted URL scanner used by threat hunters and security analysts for analyzing phishing and malicious sites.

CSS 29 4 Updated Oct 7, 2024

🔎Searches Hash APIs to crack your hash quickly🔎 If hash is not found, automatically pipes into HashCat⚡

Python 1,382 95 Updated Mar 5, 2025

Fast web fuzzer written in Go

Go 14,871 1,472 Updated Apr 24, 2025

Check which CDN providers an IP list belongs to

Go 194 36 Updated May 10, 2023

Rockyou for web fuzzing

Shell 2,917 522 Updated Aug 28, 2025

DLL Hijack Search Order Enumeration BOF

C 150 21 Updated Nov 3, 2021

Fake Protocol Server

Python 1,596 182 Updated Jan 2, 2025

Target practice for ffuf

PHP 69 12 Updated Aug 10, 2021

An OOB interaction gathering server and client library

Go 3,977 417 Updated Oct 6, 2025

Fraktal's Ransomware Emulator

C# 101 22 Updated Apr 5, 2024

REST API Fuzz Testing (RAFT): Source code for self-hosted service developed for Azure, including the API, orchestration engine, and default set of security tools (including MSR's RESTler), that ena…

F# 264 43 Updated Jan 13, 2022

zero-trust remote firewall instrumentation

Go 251 31 Updated Jul 13, 2024

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

PowerShell 524 113 Updated Jan 21, 2022

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and Git friendly.

Python 854 123 Updated Sep 1, 2023

Tool to check for dependency confusion vulnerabilities in NuGet package management systems

C# 15 5 Updated Mar 6, 2021

Tool to check for dependency confusion vulnerabilities in multiple package management systems

Go 761 105 Updated Aug 19, 2024

Data exfiltration over DNS request covert channel

JavaScript 872 192 Updated Apr 29, 2024

A client software for https://github.com/joohoi/acme-dns

Go 131 23 Updated Jun 29, 2023

PwnMachine is a self hosting solution based on docker aiming to provide an easy to use pwning station for bug hunters.

Vue 319 53 Updated Jul 31, 2024

qsinject (Query String Inject) is a tool that allows you to quickly substitute query string values with regex matches, one-at-a-time.

Go 30 8 Updated May 6, 2020

HackerOne "in scope" domains

Python 478 131 Updated Oct 9, 2025

Frida Scripts

JavaScript 639 136 Updated Sep 26, 2022

A thorough library database to assist with binary exploitation tasks.

Python 196 16 Updated Aug 1, 2022

Make temporary edits to your Go module dependencies

Go 905 20 Updated Jun 3, 2025

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Go 29,363 2,773 Updated Oct 9, 2025

CodiMD - Realtime collaborative markdown notes on all platforms.

JavaScript 9,825 1,108 Updated Oct 2, 2025

Private keys that have become public ...

PHP 183 30 Updated Sep 9, 2025

A tool that can help detect and takeover subdomains with dead DNS records

Go 767 137 Updated Jan 3, 2021
Next