Skip to content
View padowla's full-sized avatar

Block or report padowla

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
44 stars written in Python
Clear filter

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 71,580 16,205 Updated Nov 2, 2025

⏬ Dumb downloader that scrapes the web

Python 56,550 9,806 Updated Apr 27, 2025

YOLOv5 🚀 in PyTorch > ONNX > CoreML > TFLite

Python 56,005 17,326 Updated Nov 9, 2025

Automatic SQL injection and database takeover tool

Python 35,809 6,108 Updated Nov 10, 2025

E-mails, subdomains and names Harvester - OSINT

Python 14,925 2,337 Updated Nov 12, 2025

Fast subdomains enumeration tool for penetration testers

Python 10,690 2,195 Updated Aug 2, 2024

A swiss army knife for pentesting networks

Python 8,969 1,698 Updated Dec 6, 2023

Web application fuzzer

Python 6,334 1,396 Updated Aug 18, 2024

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat…

Python 6,122 843 Updated Oct 30, 2025

AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services.

Python 5,791 967 Updated May 27, 2025

Common User Passwords Profiler (CUPP)

Python 5,057 1,259 Updated Nov 20, 2023

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

Python 3,769 402 Updated Oct 4, 2025

Tool for Active Directory Certificate Services enumeration and abuse

Python 3,239 434 Updated Sep 30, 2025

Fancy reverse and bind shell handler

Python 2,837 282 Updated Aug 9, 2024

BloodyAD is an Active Directory Privilege Escalation Framework

Python 1,984 191 Updated Oct 29, 2025

SMBMap is a handy SMB enumeration tool

Python 1,972 365 Updated Feb 28, 2025

Test tool for CVE-2020-1472

Python 1,795 358 Updated Jun 27, 2025

Orange Cyberdefense mindmaps

Python 1,475 242 Updated Mar 10, 2025

PoC for Zerologon - all research credits go to Tom Tervoort of Secura

Python 1,264 282 Updated Nov 3, 2020

Automatic SSTI detection tool with interactive interface

Python 1,264 142 Updated Aug 19, 2025

Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!

Python 1,245 149 Updated Jul 31, 2025

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Python 1,230 167 Updated Mar 19, 2025

Active Directory Integrated DNS dumping by any authenticated user

Python 1,099 122 Updated Apr 4, 2025

Python version of the C# tool for "Shadow Credentials" attacks

Python 817 100 Updated Sep 16, 2025

command line pastebin for google appengine

Python 723 70 Updated Jul 19, 2015

Advanced Active Directory network topology analyzer with SMB validation, multiple authentication methods (password/NTLM/Kerberos), and comprehensive network discovery. Export results as BloodHound‑…

Python 606 66 Updated Oct 21, 2025

A powerful scanner to scan your Filesystem, S3, MySQL, Redis, Google Cloud Storage and Firebase storage for PII and sensitive data.

Python 454 53 Updated Nov 1, 2025

AD ACL abuse

Python 356 47 Updated Sep 11, 2025

Standalone implementation of a part of the WSUS spec. Built for offensive security purposes.

Python 327 44 Updated Nov 11, 2022

Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel's LDAP Sentinel

Python 325 29 Updated Nov 7, 2025
Next