Skip to content
View ghsec's full-sized avatar

Block or report ghsec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

rep+ — Burp-style HTTP Repeater for Chrome DevTools with built‑in AI to explain requests and suggest attacks

JavaScript 155 16 Updated Nov 24, 2025

Penetration Testing For - Web | Mobile | API | Thick Client | Source Code Review | DevSecOps | Wireless | Network Pentesting, etc...

1,393 314 Updated Nov 16, 2025

Writeups for PortSwigger WebSecurity Academy

Python 343 118 Updated Feb 5, 2023

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

Python 3,783 405 Updated Oct 4, 2025

My useful files for penetration tests, security assessments, bug bounty and other security related stuff

Shell 188 22 Updated Nov 24, 2025

All about bug bounty (bypasses, payloads, and etc)

6,518 1,233 Updated Sep 8, 2023

IP Lookups for Open Ports and Vulnerabilities from internetdb.shodan.io

Go 132 19 Updated Mar 10, 2022

Little Bug Bounty & Hacking Tools⚔️

Go 370 62 Updated Nov 10, 2024

Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration

Go 1,107 137 Updated Nov 19, 2025

Remove duplicate urls from input

Go 59 20 Updated Nov 11, 2025

EPSS & VEDAS Score Aggregator for CVEs

253 37 Updated Nov 23, 2025

This script grab public report from hacker one and make some folders with poc videos

Shell 902 223 Updated Oct 10, 2025
Python 51 9 Updated Aug 16, 2021

HopLa Burp Suite Extender plugin - Brings AI capabilities, autocompletion support, and a set of useful payloads to Burp Suite

Java 790 83 Updated Aug 13, 2025

SSRF (Server Side Request Forgery) testing resources

Python 1 1 Updated Jan 14, 2021

Collection of methodology and test case for various web vulnerabilities.

6,851 1,875 Updated Jun 25, 2025

Gospider - Fast web spider written in Go

Go 2,820 332 Updated Apr 21, 2024

Pass in a list of URLs with query strings, get back a unique list of URLs and query string combinations

C++ 386 62 Updated Jun 17, 2020

httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.

Go 9,198 991 Updated Nov 24, 2025

A curated list of bugbounty writeups (Bug type wise) , inspired from https://github.com/ngalongc/bug-bounty-reference

Python 5,425 1,107 Updated Aug 6, 2023

qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.

Go 300 38 Updated Feb 12, 2023

You Know, For WEB Fuzzing ! 日站用的字典。

Python 8,164 2,479 Updated Nov 13, 2023

The Web Application Hacker's Handbook - Extra Content

Java 561 111 Updated Jun 9, 2023

Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application

Go 4,939 534 Updated Dec 21, 2024

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

5,923 1,176 Updated Aug 14, 2024

A list of useful payloads for Web Application Security and Pentest/CTF

Python 309 59 Updated Aug 14, 2024

Default signature for Jaeles Scanner

325 70 Updated Apr 9, 2022

Burp Bounty (Scan Check Builder in BApp Store) is a extension of Burp Suite that allows you, in a quick and simple way, to improve the active and passive scanner by means of personalized rules thro…

Java 1,757 341 Updated Apr 26, 2024

w3af: web application attack and audit framework, the open source web vulnerability scanner.

Python 4,822 1,231 Updated Feb 22, 2023
Next