Skip to content
View helloyw's full-sized avatar
🥰
🥰

Block or report helloyw

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Gain insights into COM/DCOM implementations that may be vulnerable using an automated approach and make it easy to visualize the data. By following this approach, a security researcher will hopeful…

PowerShell 126 12 Updated Oct 30, 2025

Obfuscator for .NET and Mono, with a customizable engine for building your own obfuscators.

C# 478 52 Updated Oct 27, 2025

sideloading PoC using onedrive.exe & version.dll

C++ 60 7 Updated Oct 30, 2025

A domain specific language for matching directories and files in network shares

Python 9 Updated Oct 15, 2025

A python tool to map the access rights of network shares into a BloodHound OpenGraphs easily

Python 203 14 Updated Nov 12, 2025

Simple powershell script to tests for "GHOST" SPN's

PowerShell 13 1 Updated Oct 16, 2025

Helps defenders find their WSUS configurations in the wake of CVE-2025-59287

PowerShell 41 2 Updated Oct 28, 2025

Yet another WeChat miniapp debugger on Windows

TypeScript 511 154 Updated Nov 11, 2025

Beacon Object File (BOF) for Using the BadSuccessor Technique for Account Takeover

C 75 7 Updated Oct 20, 2025

A little tool to play with Windows security

C 27 6 Updated Oct 16, 2025

Turacos 是一款专业的多数据库安全评估工具,支持 PostgreSQL、MySQL、Redis、MSSQL 等多种数据库的后渗透操作。 为安全研究人员提供系统化、模块化的数据库安全测试能力,助力企业进行安全评估与漏洞验证。

Java 46 3 Updated Oct 23, 2025

JSFindAPI是一款自动从html页面中获取js链接,并自动访问js提取js中的api路径,然后自动进行api未授权测试的插件,同时也可被动监听,当访问js时自动提取api进行访问,提取api接口主要根据AJAX,XMLHttpRequest,axios,Vue.js等各种api请求的写法去正则提取,准确性和数量都有提升

25 2 Updated Oct 20, 2025

burp插件,Oss漏洞被动扫描

Java 88 6 Updated Aug 8, 2025

A fast, simple, recursive content discovery tool written in Rust.

Rust 7,177 568 Updated Nov 12, 2025
Python 6 Updated Aug 5, 2025

Unauthenticated start EFS service on remote Windows host (make PetitPotam great again)

Python 108 8 Updated Oct 23, 2025

Proof-of-Concept tool for extracting NTLMv1 hashes from sessions on modern Windows systems.

C 416 33 Updated Oct 27, 2025
Java 31 3 Updated Apr 23, 2023

这是一款对chromium源码进行定制的浏览器,支持爬虫/JS逆向工程师进行辅助分析网页

C++ 321 133 Updated Dec 25, 2024

推理算法助手(降维打击)

Python 982 435 Updated Oct 25, 2024

The DCERPC only printerbug.py version

Python 151 21 Updated Oct 30, 2025

Wonka is a sweet Windows tool that extracts Kerberos tickets from the Local Security Authority (LSA) cache. Like finding a ticket, but for security research and penetration testing! 🎫

C# 104 12 Updated Oct 21, 2025

ICP备案信息查询

Python 1 Updated Oct 31, 2025

让fscan再次伟大

Go 276 28 Updated Oct 28, 2025

A email bomb/fake email tool, by Python

Python 338 79 Updated Feb 8, 2023

Nexus Maven私服内容下载

Python 1 Updated Oct 19, 2025

DiffRays is a research-oriented tool for binary patch diffing, designed to aid in vulnerability research, exploit development, and reverse engineering.

Python 265 17 Updated Nov 2, 2025

🚀 Free HTTP, SOCKS4, & SOCKS5 Proxy List * Updated every 5 minutes *

2,865 326 Updated Nov 12, 2025
Next