Skip to content
View kernux's full-sized avatar

Block or report kernux

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
74 stars written in Python
Clear filter

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 74,739 16,559 Updated Jan 21, 2026

⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡

Python 20,977 1,384 Updated Mar 5, 2025

A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.

Python 12,643 2,689 Updated Nov 19, 2025

An easy and fast way to create a Python GUI 🐍

Python 10,172 937 Updated Aug 21, 2024

OneForAll是一款功能强大的子域收集工具

Python 9,566 1,416 Updated Sep 12, 2025

A swiss army knife for pentesting networks

Python 9,045 1,701 Updated Dec 6, 2023

📱 objection - runtime mobile exploration

Python 8,848 949 Updated Jan 27, 2026

You Know, For WEB Fuzzing !

Python 8,229 2,486 Updated Nov 13, 2023

The most powerful Android RPA agent framework, next generation of mobile automation robots.

Python 7,583 1,017 Updated Dec 13, 2025

本项目集成了全网优秀的攻防武器工具项目,包含自动化利用,子域名、目录扫描、端口扫描等信息收集工具,各大中间件、cms、OA漏洞利用工具,爆破工具、内网横向、免杀、社工钓鱼以及应急响应、甲方安全资料等其他安全攻防资料。

Python 7,287 1,362 Updated Jan 26, 2026

RSA attack tool (mainly for ctf) - retrieve private key from weak public key and/or uncipher data

Python 6,739 981 Updated Dec 3, 2025

One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

Python 6,383 756 Updated Dec 20, 2025

Scanning APK file for URIs, endpoints & secrets.

Python 5,793 562 Updated Aug 20, 2025

Top disclosed reports from HackerOne

Python 5,244 951 Updated Jan 3, 2026

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Python 5,048 769 Updated Nov 8, 2025

Stalk your Friends. Find their Instagram, FB and Twitter Profiles using Image Recognition and Reverse Image Search.

Python 5,000 667 Updated Apr 25, 2024

一个攻防知识库。A knowledge base for red teaming and offensive security.

Python 4,055 712 Updated Jan 5, 2026

Symbolic execution tool

Python 3,832 488 Updated Nov 21, 2025

Arsenal is just a quick inventory and launcher for hacking programs

Python 3,673 554 Updated Nov 29, 2024

Vulmap 是一款 web 漏洞扫描和验证工具, 可对 webapps 进行漏洞扫描, 并且具备漏洞验证功能

Python 3,507 572 Updated Apr 26, 2023

Automatic SSRF fuzzer and exploitation tool

Python 3,476 563 Updated Sep 4, 2025

Ghost Framework is an Android post-exploitation framework that exploits the Android Debug Bridge to remotely access an Android device.

Python 3,271 1,051 Updated Nov 1, 2025

Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.

Python 3,197 323 Updated May 24, 2024

渗透测试报告/资料文档/渗透经验文档/安全书籍

Python 2,924 695 Updated Jul 4, 2024

RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and reliability bugs in these services.

Python 2,864 324 Updated Jan 14, 2026

各种漏洞poc、Exp的收集或编写

Python 2,482 968 Updated Jun 24, 2025

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

Python 2,480 444 Updated Aug 3, 2024

Open source vulnerability DB and triage service.

Python 2,466 276 Updated Jan 29, 2026

利用大量高威胁poc/exp快速获取目标权限,用于渗透和红队快速打点

Python 2,360 390 Updated Jun 9, 2023

🐈Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

Python 2,220 342 Updated Mar 3, 2024
Next