Skip to content
View r35tart's full-sized avatar
🌴
On vacation
🌴
On vacation

Block or report r35tart

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
80 stars written in Python
Clear filter

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 71,474 16,190 Updated Nov 2, 2025

Impacket is a collection of Python classes for working with network protocols.

Python 15,072 3,814 Updated Nov 7, 2025

Web path scanner

Python 13,613 2,402 Updated Oct 20, 2025

Fast subdomains enumeration tool for penetration testers

Python 10,683 2,195 Updated Aug 2, 2024

Credentials recovery project

Python 10,464 2,105 Updated Sep 18, 2025

OneForAll是一款功能强大的子域收集工具

Python 9,383 1,406 Updated Sep 12, 2025

Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C

Python 8,863 1,845 Updated Mar 22, 2024

You Know, For WEB Fuzzing ! 日站用的字典。

Python 8,138 2,480 Updated Nov 13, 2023

Web application fuzzer

Python 6,327 1,396 Updated Aug 18, 2024

爆破字典

Python 5,201 2,878 Updated Mar 21, 2022

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat…

Python 4,782 1,773 Updated Jun 15, 2020

A python script that finds endpoints in JavaScript files

Python 4,164 649 Updated Apr 13, 2024

巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。

Python 3,586 1,327 Updated Apr 16, 2024

A fast sub domain brute tool for pentesters

Python 3,584 1,011 Updated Sep 15, 2022

A `.git` folder disclosure exploit

Python 3,459 814 Updated Feb 1, 2023

WPA/WPA2 密码字典,用于 wifi 密码暴力破解

Python 3,364 708 Updated Jan 25, 2022

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Python 3,226 397 Updated Apr 18, 2023

The successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn.

Python 3,129 830 Updated Mar 6, 2025

JSFinder is a tool for quickly extracting URLs and subdomains from JS files on a website.

Python 2,871 424 Updated Nov 24, 2021

各种漏洞poc、Exp的收集或编写

Python 2,471 965 Updated Jun 24, 2025

A fast vulnerability scanner helps pentesters pinpoint possibly vulnerable targets from a large number of web servers

Python 2,351 592 Updated Dec 31, 2024

Stealing Signatures and Making One Invalid Signature at a Time

Python 2,334 480 Updated Aug 11, 2021

Firefox Decrypt is a tool to extract passwords from Mozilla (Firefox™, Waterfox™, Thunderbird®, SeaMonkey®) profiles

Python 2,316 327 Updated Oct 31, 2025

渗透测试插件化并发框架 / Open-sourced remote vulnerability PoC/EXP framework

Python 1,955 744 Updated Mar 28, 2022

Windows exploits, mostly precompiled. Not being updated. Check https://github.com/SecWiki/windows-kernel-exploits instead.

Python 1,897 587 Updated Sep 7, 2020

A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.

Python 1,834 234 Updated May 20, 2024

Test tool for CVE-2020-1472

Python 1,795 358 Updated Jun 27, 2025

在线cms识别|信息泄露|工控|系统|物联网安全|cms漏洞扫描|nmap端口扫描|子域名获取|待续..

Python 1,784 348 Updated Mar 31, 2023

A .DS_Store file disclosure exploit. It parses .DS_Store file and downloads files recursively.

Python 1,695 297 Updated May 6, 2023

🕷️ A `.git` folder exploiting tool that is able to restore the entire Git repository, including stash, common branches and common tags.

Python 1,577 236 Updated Oct 31, 2025
Next