Skip to content
View tillson's full-sized avatar

Highlights

  • Pro

Organizations

@ireallydontcare

Block or report tillson

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 71,419 16,178 Updated Nov 2, 2025

The Swift Programming Language

C++ 69,248 10,571 Updated Nov 5, 2025

A command-line benchmarking tool

Rust 26,631 427 Updated Oct 1, 2025

The Swiss Army knife for 802.11, BLE, HID, CAN-bus, IPv4 and IPv6 networks reconnaissance and MITM attacks.

Go 18,323 1,584 Updated Oct 27, 2025

Evals is a framework for evaluating LLMs and LLM systems, and an open-source registry of benchmarks.

Python 17,230 2,830 Updated Nov 3, 2025

Atmosphère is a work-in-progress customized firmware for the Nintendo Switch.

C++ 17,132 1,339 Updated Oct 8, 2025

Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@mandiant.com

PowerShell 7,394 1,336 Updated Oct 16, 2025

A static analysis security vulnerability scanner for Ruby on Rails applications

Ruby 7,160 758 Updated Nov 4, 2025

Reconnaissance tool for GitHub organizations

Go 6,083 844 Updated Sep 20, 2022

The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power schedules, MOpt mutators, unicorn_mode, and a lot more!

C 6,061 1,183 Updated Nov 5, 2025

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

5,876 1,165 Updated Aug 14, 2024

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Python 5,430 775 Updated Feb 8, 2025

Graph database optimized for fast analysis and real-time data processing. It is provided as an extension to PostgreSQL.

C 3,961 458 Updated Oct 17, 2025

Keep track of internships for Summer 2020 for undergraduates interested in tech./SWE/related fields

Python 1,787 240 Updated Oct 12, 2020

Fast GitHub recon tool. Scans for leaked secrets across all of GitHub, not just known repos and orgs. Support for GitHub dorks.

Go 1,355 196 Updated Oct 24, 2025

Fast DNS Lookup Library and CLI Tool

Go 1,039 143 Updated Nov 3, 2025

🎄Visualization and annotation of phylogenetic trees

R 892 180 Updated Oct 30, 2025

Train Tesseract LSTM with make

Python 701 215 Updated Apr 18, 2025

A command-line utility designed to discover URLs for a given domain in a simple, efficient way. It works by gathering information from a variety of passive sources, meaning it doesn't interact dire…

Go 646 73 Updated Oct 20, 2025

A set of Zeek scripts to detect ATT&CK techniques.

Zeek 616 83 Updated Jun 26, 2024

A suite of secret scanners built in Rust for performance. Based on TruffleHog (https://github.com/dxa4481/truffleHog) which is written in Python.

Rust 533 64 Updated Jun 28, 2025

A fast Go Avro codec

Go 488 122 Updated Oct 20, 2025

An automated approach to performing recon for bug bounty hunting and penetration testing.

Shell 454 103 Updated Jul 21, 2020

Brosec - An interactive reference tool to help security professionals utilize useful payloads and commands.

JavaScript 355 89 Updated Jan 12, 2023

An up-to-date export of cloud provider IP address ranges

343 48 Updated Jul 25, 2025

Collection of Meta's DNS Libraries

Go 283 30 Updated Oct 24, 2025

Student submissions for the WWDC 2019 Scholarship

282 148 Updated Jul 20, 2021

Poor (rich?) man's bug bounty pipeline https://dubell.io

Shell 276 60 Updated Apr 24, 2023

Visualization tool for Graph Neural Networks

TypeScript 254 29 Updated Sep 20, 2022

This is an intentionally vulnerable smart contract truffle deployment aimed at allowing those interested in smart contract security to exploit a wide variety of issues in a safe environment.

JavaScript 119 30 Updated Oct 24, 2018
Next