Skip to content
View wflk's full-sized avatar

Block or report wflk

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Semantic analysis engine for detecting vulnerability fixes in Windows kernel driver patches — 58 YAML rules, Ghidra decompilation, reachability tracing, and scoring

Python 59 3 Updated Feb 26, 2026

This repository contains various media files for known attacks on web applications processing media files. Useful for penetration tests and bug bounty.

PostScript 352 85 Updated Jun 13, 2021

A tool for exploring each layer in a docker image

Go 53,670 1,972 Updated Dec 15, 2025

Extract JavaScript source trees from Sourcemap files

Go 1,296 129 Updated Mar 22, 2024

ssh jump host appliance

Makefile 26 2 Updated Mar 23, 2022

Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face. #nolockdown

1,413 105 Updated Jun 24, 2025

A python script to merge multiple jar files for easier debugging via JD-Eclipse

Python 62 12 Updated Jan 13, 2023

JDBC Connection URL Attack

Java 443 44 Updated Sep 10, 2021

Reverse proxies cheatsheet

Python 1,856 222 Updated Nov 4, 2023

collect for learning cases

VBScript 594 77 Updated Jun 16, 2024
Python 251 57 Updated Sep 26, 2020

Detectify Crowdsource Challenge

Shell 73 17 Updated Apr 26, 2022

SSRF (Server Side Request Forgery) testing resources

Python 2,481 493 Updated Oct 12, 2024

⌨️ Wordlists, Dictionaries and Other Data Sets for Writing Software Security Test Cases

HTML 362 96 Updated Aug 14, 2024

Trying to make automated recon for bug bounties

Shell 255 52 Updated May 3, 2021

API Fuzzer which allows to fuzz request attributes using common pentesting techniques and lists vulnerabilities

Ruby 407 80 Updated Jul 16, 2017

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

6,129 1,202 Updated Aug 14, 2024

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Python 5,117 777 Updated Mar 28, 2026

Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets.

Python 1,554 217 Updated Mar 7, 2024

bXSS is a utility which can be used by bug hunters and organizations to identify Blind Cross-Site Scripting.

JavaScript 570 64 Updated Mar 4, 2023

A list of private and public (more or less) blackhat boards

276 67 Updated Mar 9, 2019

A Bring Your Own Land Toolkit that Doubles as a WMI Provider

C# 289 59 Updated Oct 31, 2018

A tool for checking the security hardening options of the Linux kernel

Python 2,049 183 Updated Feb 28, 2026

A fuzzing framework for network servers

Python 122 25 Updated Oct 22, 2018

Here you can find write ups for iOS Vulnerabilities that have been released.

Shell 1,049 253 Updated May 17, 2022

Active Directory Assessment and Privilege Escalation Script

PowerShell 1,129 213 Updated Dec 7, 2022

.NET deobfuscator and unpacker.

C# 7,373 2,800 Updated Aug 29, 2020

Steal Net-NTLM Hash using Bad-PDF

Python 1,142 224 Updated Oct 20, 2025

Arbitrary code execution with kernel privileges using CVE-2018-8897.

C++ 421 98 Updated May 18, 2018

Fetch all public IP addresses tied to your AWS account. Works with IPv4/IPv6, Classic/VPC networking, and across all AWS services

Ruby 641 88 Updated Apr 29, 2021
Next