Skip to content
View 0x48756773's full-sized avatar

Block or report 0x48756773

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
264 stars written in Python
Clear filter

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 71,449 16,187 Updated Nov 2, 2025

The Python programming language

Python 69,699 33,304 Updated Nov 7, 2025

The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.

Python 47,478 2,160 Updated Apr 18, 2024

Portable file server with accelerated resumable uploads, dedup, WebDAV, FTP, TFTP, zeroconf, media indexer, thumbnails++ all in one file, no deps

Python 33,937 1,349 Updated Nov 2, 2025

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Python 30,620 4,275 Updated Oct 31, 2025

A Lightweight Face Recognition and Facial Attribute Analysis (Age, Gender, Emotion and Race) Library for Python

Python 20,974 2,852 Updated Oct 21, 2025

SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

Python 15,777 2,675 Updated Dec 15, 2024

Impacket is a collection of Python classes for working with network protocols.

Python 15,068 3,814 Updated Oct 22, 2025

E-mails, subdomains and names Harvester - OSINT

Python 14,880 2,337 Updated Nov 6, 2025

The Rogue Access Point Framework

Python 14,232 2,708 Updated Feb 4, 2025

Web path scanner

Python 13,606 2,403 Updated Oct 20, 2025

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWA…

Python 12,538 2,544 Updated Nov 3, 2025

Prowler is the Open Cloud Security for AWS, Azure, GCP, Kubernetes, M365 and more. As agent-less, it helps for continuous monitoring, security assessments & audits, incident response, compliance, h…

Python 12,288 1,839 Updated Nov 6, 2025

Universal Radio Hacker: Investigate Wireless Protocols Like A Boss

Python 11,924 945 Updated Jul 31, 2025

MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise.

Python 11,835 1,144 Updated Nov 7, 2025

Fast subdomains enumeration tool for penetration testers

Python 10,676 2,195 Updated Aug 2, 2024

Credentials recovery project

Python 10,460 2,105 Updated Sep 18, 2025

The recursive internet scanner for hackers. 🧡

Python 9,100 751 Updated Nov 6, 2025

A GPT-empowered penetration testing tool

Python 9,031 1,211 Updated Jul 29, 2025

A swiss army knife for pentesting networks

Python 8,963 1,696 Updated Dec 6, 2023

Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C

Python 8,859 1,845 Updated Mar 22, 2024

📱 objection - runtime mobile exploration

Python 8,612 938 Updated Oct 30, 2025

Multi-Cloud Security Auditing Tool

Python 7,411 1,157 Updated Sep 23, 2025

Infection Monkey - An open-source adversary emulation platform

Python 6,886 810 Updated May 1, 2025

Automated Adversary Emulation Platform

Python 6,526 1,254 Updated Oct 30, 2025

WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

Python 5,970 1,005 Updated Sep 13, 2025

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

Python 5,959 982 Updated Nov 4, 2025

The FLARE team's open-source tool to identify capabilities in executable files.

Python 5,641 627 Updated Nov 5, 2025

EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.

Python 5,503 896 Updated Nov 6, 2025

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Python 5,432 775 Updated Feb 8, 2025
Next