Skip to content
View secfb's full-sized avatar
🎯
Focusing
🎯
Focusing

Block or report secfb

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and automated reconnaissance. Supports REST/GraphQL/SOAP…

Python 63 7 Updated Apr 23, 2026

Codex skill for safe codebase complexity analysis and performance optimization reports

Python 308 11 Updated May 15, 2026

Autonomous Hacking Agent for Red Team

Python 3,864 769 Updated May 17, 2026

Hefaistos is a powerful Burp Suite extension designed for hackers

5 1 Updated Apr 5, 2026

A tool for detecting subdomain takeover vulnerabilities by checking DNS records

HTML 30 1 Updated May 2, 2026

A Burp Extension to test Authorization and Broken Access Control!

Java 9 3 Updated Apr 11, 2022

针对于红队攻击思维做出的red team模式(让你的codex像红队一样思考!),可在单对话使用(目前只支持5.4,5.5需要过cyber认证,可自行适配其他AI)

Python 155 21 Updated May 15, 2026

Autonomous Bug Bounty Hunting Framework powered by Claude Code. 20 AI agents, state-machine orchestration, Burp Suite MCP, credential vault, LLM security track. Type 'hunt target.com' and let AI fi…

TypeScript 16 4 Updated May 13, 2026

Scan the world (for secrets)

Go 953 60 Updated May 16, 2026

Light, fluffy, and always free - The AWS Local Emulator alternative

Java 11,603 1,013 Updated May 17, 2026

OpenAnt from Knostic is the leading open source LLM-based vulnerability discovery product, helping defenders proactively find verified security flaws while minimizing both false positives and false…

Python 556 83 Updated May 14, 2026
TypeScript 1,059 185 Updated May 16, 2026

承影,愿你在光影之间,找到属于自己的锋芒。开源的类 BurpSuite 应用 ChYing — may you find your own edge between light and shadow. An open-source, BurpSuite-like application.

Go 677 61 Updated Mar 31, 2026

An open-source long-horizon SuperAgent harness that researches, codes, and creates. With the help of sandboxes, memories, tools, skill, subagents and message gateway, it handles different levels of…

Python 68,024 9,060 Updated May 17, 2026

r3ngine is the rebirth of the automated reconnaissance framework for web applications with a focus on dynamic streamlined recon process, backed by a database, & simple yet intuitive User Interface.…

TypeScript 1 Updated May 17, 2026

A desktop home for your CLI agent. Wraps claude / copilot / codex / aider in a clean Electron window with PTY, MCP, drag-drop context, sessions, voice, and a live status panel. PAI reasoning bundled.

TypeScript 5 Updated May 11, 2026

Hephaestus(火神)在原有客户端基础上更改为Web的安全工具,更优秀的功能,更好看的界面,希望可以带给你新的体验

25 1 Updated May 14, 2026

Mach is a fast, reliable, and extensible web fuzzing tool built for security researchers, bug bounty hunters, and penetration testers. Designed with performance and simplicity in mind, it helps unc…

Rust 120 5 Updated Aug 16, 2025

一个新的安全服务工具集

11 Updated May 14, 2026

安全服务集成化工具集

Go 1,062 141 Updated Apr 29, 2026

A curated list of awesome OpenAI Codex plugins, skills, and resources. The #1 Codex Marketplace. See live plugins at: https://hol.org/registry/plugins

Python 220 83 Updated May 16, 2026

High-performance subdomain prober written in Rust. Like httpx, but faster.

Rust 4 1 Updated May 7, 2026

Give me your APK, I will give you framework name

Rust 9 1 Updated May 6, 2026

Skill de Pentesting para Android

JavaScript 181 36 Updated May 5, 2026

Free Active Directory pentesting tool and Linux CLI for AD enumeration, BloodHound, Kerberoasting, ADCS, DCSync, and attack paths.

Python 299 36 Updated Apr 26, 2026

Passive source code Vulnerability Scanner that flags 76+ security vulnerabilities and weak coding practices in JS, HTML, and JSON responses — with linter-style output, CWE references, and fix guida…

Python 1 Updated Mar 20, 2026

Pentest Coverage Tracker is a Burp Suite extension that helps penetration testers monitor testing coverage in real time. It logs discovered endpoints and tracks whether their parameters are actuall…

Python 30 3 Updated Mar 16, 2026

渗透测试Payload速查平台 | Pentest Payload Quick Reference | XSS/SQLi/SSRF/RCE | React+TypeScript

TypeScript 375 100 Updated Mar 11, 2026

SSRFHunter

Python 16 Updated Jan 17, 2026

HowToLogin is a tool that tests web application login pages for login page vulnerabilities and impelementations.

Python 27 3 Updated Apr 8, 2026
Next