Skip to content
View hland's full-sized avatar

Block or report hland

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Fast passive subdomain enumeration tool.

Go 11,292 1,339 Updated Mar 3, 2025

Help secure Express apps with various HTTP headers

TypeScript 10,342 374 Updated Feb 13, 2025

Slide deck and demo code for my DEFCON 26 talk

Ruby 11 7 Updated Aug 17, 2018

A container repository for my public web hacks!

JavaScript 1,978 275 Updated Oct 12, 2022

Exploit written in Python for CVE-2018-15473 with threading and export formats

Python 521 184 Updated Jul 12, 2024

A Collection of Scripts Which Disable / Remove Windows 10 Features and Apps

PowerShell 6,146 841 Updated Nov 4, 2024

A collection of software installations scripts for Windows systems that allows you to easily setup and maintain a reverse engineering environment on a VM.

PowerShell 6,997 971 Updated Mar 7, 2025

DARKSURGEON is a Windows packer project to empower incident response, digital forensics, malware analysis, and network defense.

PowerShell 466 67 Updated Jul 21, 2020

Go ODM for MongoDB

Go 490 39 Updated Jan 1, 2021

Probe a rendering engine for vulnerabilities and other features

JavaScript 367 55 Updated Oct 13, 2021

DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:

JavaScript 14,722 765 Updated Mar 5, 2025

Proof-of-concept codes created as part of security research done by Google Security Team.

C++ 1,863 249 Updated Mar 12, 2021

A Tool for Domain Flyovers

Go 5,729 886 Updated May 22, 2022

Automatically exported from code.google.com/p/unix-privesc-check

Shell 1,052 221 Updated Feb 7, 2021

VMware Escape Exploit before VMware WorkStation 12.5.5

C 914 351 Updated Nov 7, 2023

A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstripe.

HTML 1,319 256 Updated Jan 19, 2024

Open source obfuscation tool for .NET assemblies

C# 2,599 417 Updated Mar 4, 2025

A PowerShell script for helping to find vulnerable settings in AD Group Policy. (deprecated, use Grouper2 instead!)

PowerShell 739 120 Updated Feb 5, 2019

Tool to scan for secret files on HTTP servers

Python 2,083 231 Updated Dec 2, 2024

💀Proof-of-Concept for CVE-2018-7600 Drupal SA-CORE-2018-002

Python 351 108 Updated Mar 29, 2019

Websockify is a WebSocket to TCP proxy/bridge. This allows a browser to connect to any application/server/service.

Python 4,023 789 Updated Feb 12, 2025

Distributed alerting for the masses!

Python 995 111 Updated Nov 1, 2018

A forensic evidence collection & analysis toolkit for OS X

Python 1,878 243 Updated Jun 19, 2019

Low-Budget Password Strength Estimation

CoffeeScript 15,304 956 Updated Aug 19, 2024

Automatically exported from code.google.com/p/cpassman

PHP 1 Updated Aug 23, 2015

The Bug Hunters Methodology

4,017 811 Updated Aug 1, 2023

Using a pre-commit hook, Talisman validates the outgoing changeset for things that look suspicious — such as tokens, passwords, and private keys.

Go 1,960 246 Updated Dec 11, 2024

Simple DNS Rebinding Service

C 646 78 Updated Jan 16, 2020

A reviewed list of useful PHP static analysis tools

2,834 245 Updated Jan 28, 2025

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…

PHP 61,277 24,180 Updated Mar 9, 2025
Next