Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings
@to016
to016
Follow

to^ to016

πŸ˜‰
Student, CTFer, Web Warrior

Block or report to016

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Content-Type Research

654 66 Updated Jun 29, 2025

Scan for secrets in dangling commits on GitHub using GH Archive data.

Python 443 35 Updated Jul 3, 2025

Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.

569 49 Updated Jan 28, 2026

Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows

Python 2,329 186 Updated Feb 1, 2026

A dev container for rapid prototyping of binary exploits.

Shell 2 Updated Jun 23, 2025

A docker environment for pwn in ctf

Dockerfile 797 143 Updated Sep 15, 2025

Burp Extension to find potential endpoints, parameters, and generate a custom target wordlist

Python 1,492 157 Updated Jan 8, 2026

GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep

1,396 304 Updated Sep 13, 2024

A ready to use JSONP endpoints/payloads to help bypass content security policy (CSP) of different websites.

PHP 742 113 Updated May 6, 2024

πŸŒ™πŸ¦Š Dalfox is a powerful open-source XSS scanner and utility focused on automation.

Go 4,822 511 Updated Jan 25, 2026

Deserialization payload generator for a variety of .NET formatters

C# 176 21 Updated Dec 2, 2025

An autonomous LLM-agent for large-scale, repository-level code auditing

Python 326 40 Updated Dec 4, 2025

Proxylogon & Proxyshell & Proxyoracle & Proxytoken & All exchange server history vulns summarization :)

C# 559 115 Updated Dec 7, 2023

Chrome browser extension-based Command & Control

HTML 230 31 Updated Jul 2, 2025

share some useful archives about vm and qemu escape exploit.

581 78 Updated Apr 12, 2024

qemu vulnerablity.

C 54 6 Updated May 25, 2021

An ongoing & curated collection of awesome software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidel...

28 8 Updated Jul 9, 2022

GitHub Actions Goat: Deliberately Vulnerable GitHub Actions CI/CD Environment

JavaScript 493 304 Updated Jun 27, 2025

Udemy – Linux Heap Exploitation

Python 54 11 Updated Jun 14, 2021

A repository for learning various heap exploitation techniques.

C 8,410 1,245 Updated Jan 15, 2026

Course materials for Modern Binary Exploitation by RPISEC

C 5,912 908 Updated Dec 9, 2021

Octoscan is a static vulnerability scanner for GitHub action workflows.

Go 241 20 Updated Dec 8, 2025

GitHub Attack Toolkit - Extreme Edition - A static analysis and exploit toolkit for GitHub Actions.

Python 478 46 Updated Jan 5, 2026

The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, ...

Rust 3,672 389 Updated Jan 29, 2026

Burp Plugin to Bypass WAFs through the insertion of Junk Data

Python 1,413 140 Updated Jul 14, 2025

Materials for the workshop "Red Team Ops: Havoc 101"

C# 393 52 Updated Oct 6, 2024

Find, verify, and analyze leaked credentials

Go 24,357 2,215 Updated Feb 2, 2026

A flexible tool for redirecting a given program's TCP traffic to SOCKS5 or HTTP proxy.

C 2,410 194 Updated Jan 20, 2026
Next

AltStyle γ«γ‚ˆγ£γ¦ε€‰ζ›γ•γ‚ŒγŸγƒšγƒΌγ‚Έ (->γ‚ͺγƒͺγ‚ΈγƒŠγƒ«) /