Skip to content
View tarunkant's full-sized avatar

Highlights

  • Pro

Organizations

@7aSecurity @teambi0s @IoT-Appliance-Automation @hotstar

Block or report tarunkant

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

A utility for arming (creating) many bees (micro EC2 instances) to attack (load test) targets (web applications).

Python 6,624 627 Updated Mar 28, 2024
Python 2 Updated Apr 24, 2026

Common User Passwords Profiler (CUPP)

Python 5,900 1,967 Updated Dec 26, 2025

Awesome free cloud native security learning labs. Includes CTF, self-hosted workshops, guided vulnerability labs, and research labs.

1,948 292 Updated Oct 1, 2025

List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

Shell 9,441 1,576 Updated Apr 17, 2026
TypeScript 390 53 Updated Feb 28, 2026

Damn Vulnerable Bank is designed to be an intentionally vulnerable android application. This provides an interface to assess your android application security hacking skills.

Java 750 234 Updated Dec 13, 2023

"Can I take over DNS?" — a list of DNS providers and how to claim vulnerable domains.

1,088 102 Updated Mar 3, 2025

Automatically install some web hacking/bug bounty tools.

Shell 529 108 Updated Feb 15, 2024

Prototype Pollution and useful Script Gadgets

1,616 223 Updated Jan 27, 2024

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 6,131 1,319 Updated Mar 10, 2021

For basic researches, top 25 vulnerability parameters that can be used in automation tools or manual recon. 🛡️⚔️🧙

1,832 280 Updated Jun 9, 2024

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

6,197 1,218 Updated Aug 14, 2024

This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports

3,717 652 Updated May 2, 2026

A collection of awesome one-liner scripts especially for bug bounty tips.

3,115 621 Updated Jul 29, 2024

Pwn stuff.

PHP 1,809 391 Updated May 31, 2022

A collection of tools to perform searches on GitHub.

Python 1,487 359 Updated Feb 9, 2023

Magic hashes – PHP hash "collisions"

831 104 Updated Mar 23, 2025

Checklist of the most important security countermeasures when designing, testing, and releasing your API

23,225 2,666 Updated Feb 10, 2026

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Python 31,897 4,437 Updated Apr 28, 2026

Browser's XSS Filter Bypass Cheat Sheet

1,152 214 Updated May 6, 2017

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Python 7,458 1,172 Updated Mar 26, 2026

The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.

Python 47,632 2,160 Updated Apr 18, 2024

Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication

Go 15,022 2,639 Updated Oct 6, 2025

Bypassing disabled exec functions in PHP (c) CRLF

PHP 405 63 Updated Oct 2, 2020

Web CTF CheatSheet 🐈

Ruby 2,958 576 Updated Oct 28, 2025

Stealing Wi-Fi passwords via browser's cache poisoning.

Shell 150 23 Updated Feb 19, 2022

JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool

Python 2,515 640 Updated Jan 21, 2020

Perform a MitM attack and extract clear text credentials from RDP connections

Python 1,453 322 Updated Nov 20, 2025

A list of interesting payloads, tips and tricks for bug bounty hunters.

6,466 1,618 Updated Sep 14, 2023
Next