Skip to content
View stop-a's full-sized avatar

Block or report stop-a

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Git All the Payloads! A collection of web attack payloads.

Shell 3,867 986 Updated May 15, 2023

This publication is a collection of various common attack scenarios on Microsoft Entra ID (formerly known as Azure Active Directory) and how they can be mitigated or detected.

PowerShell 2,447 353 Updated Nov 8, 2025

Notes about attacking Jenkins servers

Python 2,087 333 Updated Jul 10, 2024

WADComs is an interactive cheat sheet, containing a curated list of offensive security tools and their respective commands, to be used against Windows/AD environments.

HTML 1,622 191 Updated Aug 29, 2025

A standalone Java Decompiler GUI

Java 14,940 2,469 Updated Jul 8, 2024

The dynamic infrastructure framework for everybody! Distribute the workload of many different scanning tools with ease, including nmap, ffuf, masscan, nuclei, meg and many more!

Shell 4,316 712 Updated Sep 30, 2024

Zuul is a gateway service that provides dynamic routing, monitoring, resiliency, security, and more.

Java 13,962 2,434 Updated Dec 17, 2025

A code-searching tool similar to ack, but faster.

C 27,175 1,437 Updated Jun 16, 2024

Fetch many paths for many hosts - without killing the hosts

Go 1,688 267 Updated Feb 3, 2024

A wrapper around grep, to help you grep for things

Go 2,052 336 Updated Jun 8, 2024

A python script that finds endpoints in JavaScript files

Python 4,220 649 Updated Apr 13, 2024

Free, libre, effective, and data-driven wordlists for all!

641 89 Updated Sep 10, 2021

A collection of wordlists

4 2 Updated Jul 19, 2019

CORS Misconfiguration Scanner

Python 1,484 186 Updated Sep 17, 2022

A python based blind SQL injection exploitation script

Python 141 51 Updated Jan 26, 2020

The Web Security Testing Guide is a comprehensive Open Source guide to testing the security of web applications and web services.

Dockerfile 8,656 1,516 Updated Dec 15, 2025

A fast tool to scan client-side prototype pollution vulnerability written in Rust. 🦀

Rust 647 69 Updated Aug 28, 2025

Prototype Pollution and useful Script Gadgets

1,553 216 Updated Jan 27, 2024

A list of interesting payloads, tips and tricks for bug bounty hunters.

6,333 1,607 Updated Sep 14, 2023

PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)

C# 18,992 3,323 Updated Dec 22, 2025

CloudMapper helps you analyze your Amazon Web Services (AWS) environments.

JavaScript 6,244 843 Updated Jul 15, 2024

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

PowerShell 9,641 2,543 Updated Apr 25, 2024

List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

Shell 9,363 1,575 Updated Oct 16, 2025

A curated list of resources for learning about application security

PHP 6,757 775 Updated Feb 22, 2025

A curated list of CTF frameworks, libraries, resources and softwares

JavaScript 11,077 1,578 Updated Jul 22, 2024

🐶 A curated list of Web Security materials and resources.

12,891 1,745 Updated May 2, 2025

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Python 30,961 4,311 Updated Dec 24, 2025
Next