Skip to content
View webhak's full-sized avatar

Block or report webhak

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

MCP server that connects AI assistants to HackerOne for bug bounty hunting

Python 334 47 Updated Apr 7, 2026

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Go 867 113 Updated Jul 22, 2026

Raptor turns Claude Code into a general-purpose AI offensive/defensive security agent. By using Claude.md and creating rules, sub-agents, and skills, and orchestrating security tool usage, we confi…

Python 3,621 564 Updated Aug 14, 2026

📱 objection - runtime mobile exploration

Python 9,313 994 Updated Jul 23, 2026

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Python 7,576 1,177 Updated Mar 26, 2026

Orbis is an full spectrum automated external attack surface intelligent toolkit.

HTML 398 87 Updated Aug 12, 2026

The only GraphQL wordlist you'll ever need. Operations, field names, type names... Collected on more than 60k distinct GraphQL schemas.

TypeScript 483 53 Updated Oct 3, 2023

This app runs various webview tests to explore the attack surface and exploit techniques

HTML 34 3 Updated Jan 14, 2025

A lightweight GPT model, trained to discover subdomains.

Python 387 23 Updated Dec 18, 2025

🔭 Reverse engineering JavaScript and CSS sources from sourcemaps

JavaScript 338 45 Updated Jul 25, 2018

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Python 794 85 Updated Nov 11, 2025

💀 Generate malicious PDF test files for testing phone-home callbacks, SSRF, XSS, NTLM credential theft, and data exfiltration in PDF viewers, converters, and web applications. Can be used with Burp…

Python 4,129 548 Updated Jun 4, 2026

If you found this, you are among the truly lucky, to be given providence to my curated and often custom wordlists. Enjoy, buddy, you've earned it.

TypeScript 69 24 Updated Jun 20, 2025

CSS injection requires an attacker to load a standalone CSS file to leak HTML tag attributes.

Python 21 Updated Apr 19, 2024

CeWLeR - Custom Word List generator Redefined. CeWL alternative in Python, based on the Scrapy framework.

Python 161 19 Updated Mar 1, 2026

An IIS short filename enumeration tool

Go 1,214 115 Updated Nov 25, 2024

A command line Curses based json viewer and tabulator

Python 30 3 Updated Aug 3, 2025

Bambdas collection for Burp Suite Professional and Community.

Java 529 85 Updated Jun 16, 2026

Secrets Ninja is an GUI tool for validating & investigating API keys discovered during pentesting & bug bounty hunting.

JavaScript 177 23 Updated Mar 5, 2026

Autoswagger by Intruder - detect API auth weaknesses

Python 1,958 181 Updated Aug 8, 2025

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

Go 1,100 137 Updated Aug 5, 2026

fuzzuli is a url fuzzing tool that aims to find critical backup files by creating a dynamic wordlist based on the domain.

Go 942 95 Updated Aug 24, 2023

MapperPlus facilitates the extraction of source code from a collection of targets that have publicly exposed .js.map files.

JavaScript 298 28 Updated Oct 5, 2024

AI-powered ffuf wrapper

Python 801 95 Updated Dec 4, 2025

Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.

Go 5,060 520 Updated Mar 20, 2026

Gospider - Fast web spider written in Go

Go 2,992 334 Updated Apr 21, 2024

Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing

Python 3,149 480 Updated Mar 7, 2026

Subdomain takeover vulnerability checker

Go 1,586 203 Updated Sep 10, 2024

TheHulk is a dynamic analysis tool designed to detect and exploit DOM Clobbering vulnerabilities.

JavaScript 95 6 Updated Aug 25, 2025
Next