Skip to content
View kefkahacks's full-sized avatar

Block or report kefkahacks

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
105 stars written in Python
Clear filter

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 71,423 16,178 Updated Nov 2, 2025

The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.

Python 47,475 2,160 Updated Apr 18, 2024

Automatic SQL injection and database takeover tool

Python 35,700 6,096 Updated Oct 19, 2025

SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

Python 15,771 2,673 Updated Dec 15, 2024

E-mails, subdomains and names Harvester - OSINT

Python 14,873 2,337 Updated Nov 4, 2025

The Rogue Access Point Framework

Python 14,230 2,707 Updated Feb 4, 2025

Web path scanner

Python 13,603 2,403 Updated Oct 20, 2025

Exploitation Framework for Embedded Devices

Python 12,800 2,369 Updated Jun 10, 2025

Incredibly fast crawler designed for OSINT.

Python 12,356 1,652 Updated Mar 31, 2025

Fast subdomains enumeration tool for penetration testers

Python 10,677 2,194 Updated Aug 2, 2024

Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C

Python 8,858 1,845 Updated Mar 22, 2024

Rewrite of the popular wireless network auditor, "wifite"

Python 7,365 1,533 Updated Aug 20, 2024

Game Agent Framework. Helping you create AIs / Bots that learn to play any game you own!

Python 6,936 806 Updated Nov 7, 2022

Infection Monkey - An open-source adversary emulation platform

Python 6,886 810 Updated May 1, 2025

HTTP parameter discovery suite.

Python 5,916 836 Updated Feb 20, 2025

Automated All-in-One OS Command Injection Exploitation Tool.

Python 5,507 898 Updated Oct 27, 2025

w3af: web application attack and audit framework, the open source web vulnerability scanner.

Python 4,811 1,230 Updated Feb 22, 2023

Email OSINT & Password breach hunting tool, locally or using premium services. Supports chasing down related email

Python 4,709 561 Updated Aug 15, 2023

A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.

Python 4,377 846 Updated Feb 15, 2024

The Leading Security Assessment Framework for Android.

Python 4,360 816 Updated Jun 24, 2025

Continuously jam all wifi clients/routers

Python 4,177 798 Updated Jul 20, 2024

Printer Exploitation Toolkit - The tool that made dumpster diving obsolete.

Python 4,165 641 Updated Aug 2, 2024

Knock Subdomain Scan

Python 4,087 886 Updated Oct 26, 2025

Server-Side Template Injection and Code Injection Detection and Exploitation Tool

Python 4,063 687 Updated Apr 21, 2024

Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique present…

Python 3,878 823 Updated Jan 24, 2024

Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, co…

Python 3,830 668 Updated Nov 5, 2025

Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.

Python 3,789 827 Updated May 20, 2025

PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others.

Python 3,654 937 Updated Sep 13, 2023

A DNS meta-query spider that enumerates DNS records, and subdomains.

Python 3,470 662 Updated Jan 13, 2022

Detect and bypass web application firewalls and protection systems

Python 2,848 467 Updated Aug 11, 2024
Next