Skip to content
View highchoice's full-sized avatar

Block or report highchoice

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Automatic SSTI detection tool with interactive interface

Python 907 111 Updated Oct 14, 2024

A curated list of various bug bounty tools

4,438 714 Updated Dec 30, 2024

⚡ XSSuccessor is a powerful, asynchronous Cross-Site Scripting (XSS) detection tool.

Python 39 16 Updated Dec 30, 2024

🪄 XSSDynaGen is a tool designed to analyze URLs with parameters, identify the characters allowed by the server, and generate advanced XSS payloads based on the analysis results.

Python 42 12 Updated Dec 30, 2024

subdomain bruteforce list

99 35 Updated Oct 12, 2024

Go script for bypassing 403 forbidden

Go 147 25 Updated Aug 6, 2021

HTTP parameter discovery suite.

Python 5,355 802 Updated Dec 17, 2024

jshunter is a command-line tool designed for analyzing JavaScript files and extracting endpoints. This tool specializes in identifying sensitive data, such as API endpoints and potential security v…

Go 300 38 Updated Dec 20, 2024
Python 2,192 415 Updated Dec 8, 2023

A Firefox Web Extension to improve the discovery of DOM XSS.

JavaScript 265 37 Updated Nov 13, 2024

Complete list of LPE exploits for Windows (starting from 2023)

C++ 686 94 Updated Dec 24, 2024

Extract and execute a PE embedded within a PNG file using an LNK file.

Python 296 45 Updated Nov 2, 2024

FaceDancer is an exploitation tool aimed at creating hijackable, proxy-based DLLs by taking advantage of COM-based system DLL image loading

Rust 230 24 Updated Sep 26, 2024

This repository is primarily maintained by Omar Santos (@santosomar) and includes thousands of resources related to ethical hacking, bug bounties, digital forensics and incident response (DFIR), ar…

Jupyter Notebook 19,393 3,521 Updated Dec 21, 2024

A wordlist of API names for web application assessments

768 218 Updated Jan 20, 2023

A collection of malwares found on the internet.

57 14 Updated May 16, 2023

Stealer + Clipper + Keylogger

C# 1,237 267 Updated Dec 29, 2024

Collection of Cyber Threat Intelligence sources from the deep and dark web

4,655 807 Updated Jan 2, 2025

Zimbra - Remote Command Execution (CVE-2024-45519)

Python 117 18 Updated Nov 5, 2024
Python 1,148 414 Updated Dec 17, 2024

Evasive shellcode loader

C++ 305 54 Updated Oct 17, 2024

A simple tool for bypassing file upload restrictions.

Python 803 124 Updated Jul 22, 2024

a burp extension for dynamic payload generation to detect injection flaws (RCE, LFI, SQLi), creates access matrix based user sessions to spot authentication/authorization issues, and converts Http …

Python 14 4 Updated Apr 25, 2022

Contextual Content Discovery Tool

Go 2,700 304 Updated Apr 29, 2024

Client-Side Prototype Pollution Tools

JavaScript 84 14 Updated Sep 21, 2021

Prototype Pollution and useful Script Gadgets

1,415 204 Updated Jan 27, 2024

Content-Type Research

547 56 Updated Feb 8, 2024

A comprehensive curated list of available Bug Bounty & Disclosure Programs and Write-ups.

4,720 928 Updated Jan 15, 2024

hexadecimal & URL encoder + decoder

Perl 74 20 Updated Sep 28, 2017
Next