Skip to content
View HiitCat's full-sized avatar
🛡️
Debugging from home
🛡️
Debugging from home

Highlights

  • Pro

Block or report HiitCat

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

netshell features all in version 2 powershell

PowerShell 2,179 476 Updated Mar 5, 2024

A collection of PDF/books about the modern web application security and bug bounty.

1,185 338 Updated Dec 14, 2023

Search for sensitive data in Postman public library.

Python 194 29 Updated Jan 3, 2025

Automatically install some web hacking/bug bounty tools.

Shell 367 90 Updated Feb 15, 2024

A list of Google Dorks for Bug Bounty, Web Application Security, and Pentesting

1,110 179 Updated Nov 12, 2024

A python tool to automate KeePass discovery and secret extraction.

Python 464 44 Updated Dec 12, 2024

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wis…

Go 4,333 834 Updated Jan 23, 2025

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 62,873 14,933 Updated Jan 25, 2025

how to look for Leaked Credentials !

778 99 Updated May 6, 2024

Checklist of the most important security countermeasures when designing, testing, and releasing your API

22,609 2,616 Updated Nov 22, 2024

Weaponized web shell

Python 3,237 608 Updated Oct 18, 2024

🐍 A toolkit for testing, tweaking and cracking JSON Web Tokens

Python 5,574 686 Updated Aug 1, 2024

Security Testing Scripts for JWT

Python 311 57 Updated Jun 30, 2022

Simple HS256, HS384 & HS512 JWT token brute force cracker.

JavaScript 1,072 165 Updated Jul 13, 2024

An extension for checking if .git is exposed in visited websites

JavaScript 396 34 Updated Aug 18, 2024

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…

PHP 60,433 24,110 Updated Jan 31, 2025

A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to …

958 154 Updated Jun 24, 2024

A repository with 3 tools for pwn'ing websites with .git repositories available

Shell 3,905 631 Updated Jun 14, 2023

Single-file PHP shell

PHP 2,262 649 Updated May 16, 2024

Creazione d'identità Fake - Impostazione Privacy Profili Social - Creazione Ambiente di Lavoro

425 42 Updated Apr 17, 2023

Arsenal is a Simple shell script (Bash) used to install tools and requirements for Bug Bounty

Shell 273 42 Updated Jun 3, 2024

Obfuscate Python Programs

Python 141 31 Updated Mar 29, 2024

Collection of methodology and test case for various web vulnerabilities.

6,222 1,757 Updated Aug 4, 2024

One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password 🛡️

Python 5,869 709 Updated Jan 17, 2025