Skip to content
View hoxerz's full-sized avatar

Block or report hoxerz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

FlowMate, a BurpSuite extension that brings taint analysis to web applications, by tracking all parameters send to a target application and matches their occurrences in the responses.

Java 165 10 Updated Oct 28, 2025
PowerShell 75 6 Updated Feb 3, 2026

Simple DNS Rebinding Service

C 723 88 Updated Jan 16, 2020
1 Updated Aug 31, 2025

unleashed ffuf

Go 246 28 Updated Oct 29, 2025

Pack/Encrypt/Obfuscate ELF + SHELL scripts

Shell 431 51 Updated Dec 9, 2025

Smuggler - An HTTP Request Smuggling / Desync testing tool written in Python 3

Python 2,060 330 Updated Jan 2, 2024
Python 1,490 313 Updated Dec 31, 2022

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

6,492 1,319 Updated Jan 18, 2026

ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting.

PHP 2,240 377 Updated Jan 8, 2026

I-Espresso is a tool that enables users to generate Portable Executable (PE) files from batch scripts. Leveraging IExpress, it demonstrates how file extension spoofing can be used to evade detection.

Batchfile 83 13 Updated Oct 17, 2024

Probe a rendering engine for vulnerabilities and other features

JavaScript 367 56 Updated Oct 13, 2021

Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

Go 1,264 176 Updated Feb 13, 2026

Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!

Go 973 121 Updated Jan 12, 2024

Content-Type Research

656 66 Updated Jun 29, 2025

A streamlined tool for discovering private TLDs for security research.

Go 312 11 Updated Feb 9, 2026

project-blacklist3r

C# 635 97 Updated Oct 3, 2025

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Go 721 97 Updated Feb 3, 2026

A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.

JavaScript 767 81 Updated Dec 9, 2025

completely ridiculous API (crAPI)

Java 1,421 513 Updated Feb 15, 2026

Maintains a list of IPv4 DNS servers by verifying them against baseline servers, and ensuring accurate responses.

Python 727 115 Updated Jan 16, 2024

The most exhaustive list of reliable DNS resolvers.

950 104 Updated Feb 15, 2026

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…

PHP 68,857 24,900 Updated Feb 16, 2026

HTTPLeaks - All possible ways, a website can leak HTTP requests

HTML 2,097 207 Updated Jan 3, 2026

HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors

JavaScript 3,000 420 Updated Feb 23, 2022

Top disclosed reports from HackerOne

Python 5,315 954 Updated Jan 31, 2026

A huge chunk of my personal notes since I started playing CTFs and working as a Red Teamer.

3,166 427 Updated Feb 3, 2026

A curated list of awesome privilege escalation

1,510 169 Updated Aug 20, 2025

Config files for my GitHub profile.

27 5 Updated Feb 21, 2023
Next