Skip to content
View dondenz's full-sized avatar

Block or report dondenz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

CORS Misconfiguration Scanner

Python 1,475 188 Updated Sep 17, 2022

GraphQLmap is a scripting engine to interact with a graphql endpoint for pentesting purposes. - Do not use for illegal testing ;)

Python 1,568 214 Updated Mar 11, 2024

A user-friendly, lightweight TUI for disk imaging

Rust 1,491 24 Updated Oct 27, 2025

Try to find the origin IP of a webapp protected by Cloudflare.

Python 352 70 Updated Aug 8, 2024

X-Forwarded-For [403 forbidden] enumeration

Python 95 31 Updated May 3, 2024

Bypass CDN and WAF restrictions using CDN re-fronting.

Python 260 23 Updated Aug 25, 2022

An all-in-one hacking tool to remotely exploit Android devices using ADB and Metasploit-Framework to get a Meterpreter session.

Python 5,427 738 Updated Apr 19, 2024

⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)

Shell 900 169 Updated May 21, 2025

🛰️ Represent any GraphQL API as an interactive graph

TypeScript 8,029 538 Updated Oct 27, 2025

Automated Security Testing For REST API's

Python 2,618 414 Updated Jun 5, 2024

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Go 708 97 Updated Sep 19, 2025

Web Security Scanner

Python 341 63 Updated Sep 16, 2025

An automation tool that enumerates subdomains then filters out xss, sqli, open redirect, lfi, ssrf and rce parameters and then scans for vulnerabilities.

Shell 1,261 209 Updated Jul 18, 2024

一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。

Go 12,933 1,815 Updated Nov 8, 2025

Wordlists handcrafted (and automated) with ♥

Python 221 24 Updated Aug 1, 2025

Arsenal is just a quick inventory and launcher for hacking programs

Python 3,609 550 Updated Nov 29, 2024

CRLFMap is a tool to find HTTP Splitting vulnerabilities

Go 33 15 Updated Oct 11, 2020

OSINT tool to crawl a site and extract useful recon info.

Python 445 52 Updated Aug 13, 2025

A very (very) FAST and simple subdomain finder based on online & free services. Without any configuration requirements.

Shell 115 31 Updated Nov 1, 2024

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWA…

Python 12,546 2,550 Updated Nov 11, 2025

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…

PHP 66,864 24,762 Updated Nov 11, 2025

All about bug bounty (bypasses, payloads, and etc)

6,502 1,233 Updated Sep 8, 2023

An LLM agent that conducts deep research (local and web) on any given topic and generates a long report with citations.

Python 24,115 3,190 Updated Nov 7, 2025

One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

Python 6,287 749 Updated Nov 6, 2025