Skip to content
View korang's full-sized avatar

Block or report korang

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Fully autonomous AI hacker to find actual exploits in your web apps. Shannon has achieved a 96.15% success rate on the hint-free, source-aware XBOW Benchmark.

JavaScript 3,093 423 Updated Dec 22, 2025

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

Python 12,481 1,890 Updated Dec 24, 2025

Mass Hunting & Exploitation PoC for CVE-2025-55182 & CVE-2025-66478

Python 35 10 Updated Dec 7, 2025

A C# tool for requesting certificates from ADCS using DCOM over SMB. This tool allows you to remotely request X.509 certificates from CA server using the MS-WCCE protocol over DCOM and It bypasses …

C# 162 22 Updated Nov 2, 2025

Explanation and full RCE PoC for CVE-2025-55182

Python 1,282 183 Updated Dec 8, 2025

RSC/Next.js RCE Vulnerability Detector & PoC Chrome Extension – CVE-2025-55182 & CVE-2025-66478

JavaScript 300 53 Updated Dec 6, 2025

Original Proof-of-Concepts for React2Shell CVE-2025-55182

JavaScript 966 106 Updated Dec 5, 2025

Pre-auth RCE in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0.

JavaScript 59 14 Updated Dec 9, 2025

CVE-2025-55182

Python 81 32 Updated Dec 13, 2025

Inspec validation profile for CIS Microsoft Azure Foundations Benchmark v3.0.0 - 09-05-2024

Ruby 6 2 Updated Dec 14, 2025
Go 243 21 Updated Nov 21, 2024

hashcat fork with SCCM hash support

C 5 1 Updated Apr 14, 2024

Make everyone in your VLAN ASRep roastable

Python 243 30 Updated Oct 7, 2025

Pipal, THE password analyser

Ruby 659 120 Updated Aug 27, 2023

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

Shell 7,011 1,108 Updated Dec 11, 2025

A small tool built to find and fix common misconfigurations in Active Directory Certificate Services.

PowerShell 1,399 131 Updated Nov 28, 2025

Escalation of Privilege to the root through sudo binary with chroot option. CVE-2025-32463

Shell 504 96 Updated Nov 19, 2025

ZigStrike, a powerful Payload Delivery Pipeline developed in Zig, offering a variety of injection techniques and anti-sandbox features.

Zig 495 80 Updated Oct 19, 2025

The Active Monitoring System

Perl 1,751 204 Updated Dec 10, 2025

Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.

JavaScript 1,669 350 Updated May 24, 2025
JavaScript 121 11 Updated Dec 7, 2024
TypeScript 973 146 Updated Nov 14, 2025

Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With buil…

CSS 814 112 Updated Dec 9, 2025

A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentests

Go 5,601 642 Updated Dec 22, 2025

Installs a comprehensive Android pentesting toolkit on Debian-based systems. Includes tools for static and dynamic analysis, automates setup, paths, and launchers. Perfect for testers who want a co…

Shell 4 1 Updated Jun 16, 2025

wspcoerce coerces a Windows computer account via SMB to an arbitrary target using MS-WSP

Python 131 10 Updated Nov 24, 2025

Windows remote execution multitool

Go 757 69 Updated Oct 1, 2025

Pwdlyser is an all encompassing security auditing tool. This repo serves as the open-source base for the new version of Pwdlyser (previously closed-source).

C# 25 6 Updated Sep 3, 2024

A modern, web-based GUI for Hashcat that provides an intuitive interface for hash cracking operations, featuring real-time monitoring, performance metrics, drag-and-drop functionality, and detailed…

HTML 32 1 Updated Mar 5, 2025
Next