Skip to content
View r35tart's full-sized avatar
🌴
On vacation
🌴
On vacation

Block or report r35tart

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
80 stars written in Python
Clear filter

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 71,429 16,180 Updated Nov 2, 2025

Impacket is a collection of Python classes for working with network protocols.

Python 15,061 3,814 Updated Oct 22, 2025

Web path scanner

Python 13,602 2,403 Updated Oct 20, 2025

Fast subdomains enumeration tool for penetration testers

Python 10,675 2,194 Updated Aug 2, 2024

Credentials recovery project

Python 10,458 2,105 Updated Sep 18, 2025

OneForAll是一款功能强大的子域收集工具

Python 9,377 1,405 Updated Sep 12, 2025

Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C

Python 8,857 1,845 Updated Mar 22, 2024

You Know, For WEB Fuzzing ! 日站用的字典。

Python 8,135 2,480 Updated Nov 13, 2023

Web application fuzzer

Python 6,324 1,397 Updated Aug 18, 2024

爆破字典

Python 5,199 2,877 Updated Mar 21, 2022

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat…

Python 4,782 1,771 Updated Jun 15, 2020

A python script that finds endpoints in JavaScript files

Python 4,163 648 Updated Apr 13, 2024

巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。

Python 3,586 1,327 Updated Apr 16, 2024

A fast sub domain brute tool for pentesters

Python 3,584 1,011 Updated Sep 15, 2022

A `.git` folder disclosure exploit

Python 3,456 815 Updated Feb 1, 2023

WPA/WPA2 密码字典,用于 wifi 密码暴力破解

Python 3,362 704 Updated Jan 25, 2022

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Python 3,225 397 Updated Apr 18, 2023

The successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn.

Python 3,127 830 Updated Mar 6, 2025

JSFinder is a tool for quickly extracting URLs and subdomains from JS files on a website.

Python 2,871 424 Updated Nov 24, 2021

各种漏洞poc、Exp的收集或编写

Python 2,471 965 Updated Jun 24, 2025

A fast vulnerability scanner helps pentesters pinpoint possibly vulnerable targets from a large number of web servers

Python 2,351 592 Updated Dec 31, 2024

Stealing Signatures and Making One Invalid Signature at a Time

Python 2,331 480 Updated Aug 11, 2021

Firefox Decrypt is a tool to extract passwords from Mozilla (Firefox™, Waterfox™, Thunderbird®, SeaMonkey®) profiles

Python 2,316 328 Updated Oct 31, 2025

渗透测试插件化并发框架 / Open-sourced remote vulnerability PoC/EXP framework

Python 1,954 744 Updated Mar 28, 2022

Windows exploits, mostly precompiled. Not being updated. Check https://github.com/SecWiki/windows-kernel-exploits instead.

Python 1,895 587 Updated Sep 7, 2020

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

Python 1,834 234 Updated May 20, 2024

Test tool for CVE-2020-1472

Python 1,794 358 Updated Jun 27, 2025

在线cms识别|信息泄露|工控|系统|物联网安全|cms漏洞扫描|nmap端口扫描|子域名获取|待续..

Python 1,783 348 Updated Mar 31, 2023

A .DS_Store file disclosure exploit. It parses .DS_Store file and downloads files recursively.

Python 1,695 297 Updated May 6, 2023

🕷️ A `.git` folder exploiting tool that is able to restore the entire Git repository, including stash, common branches and common tags.

Python 1,577 236 Updated Oct 31, 2025
Next