Skip to content
View joohoi's full-sized avatar
🦨
🦨

Sponsors

@Snownull
@projectdiscovery

Organizations

@certbot @TurkuSec @ffuf @citysecs @kybervpk @visma-prodsec

Block or report joohoi

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Rust tool to detect cell site simulators on an orbic mobile hotspot

Rust 3,940 289 Updated Dec 28, 2025

A proof-of-concept of a self-replicating malware for Maven build environments.

Java 5 Updated Mar 27, 2025

Webhood is a privately hosted URL scanner used by threat hunters and security analysts for analyzing phishing and malicious sites.

CSS 31 5 Updated Oct 7, 2024

🔎Searches Hash APIs to crack your hash quickly🔎 If hash is not found, automatically pipes into HashCat⚡

Python 1,393 95 Updated Mar 5, 2025

Fast web fuzzer written in Go

Go 15,349 1,498 Updated Apr 24, 2025

Check which CDN providers an IP list belongs to

Go 193 36 Updated May 10, 2023

Rockyou for web fuzzing

Shell 2,988 521 Updated Aug 28, 2025

DLL Hijack Search Order Enumeration BOF

C 152 21 Updated Nov 3, 2021

Fake Protocol Server

Python 1,608 184 Updated Jan 2, 2025

Target practice for ffuf

PHP 69 12 Updated Aug 10, 2021

An OOB interaction gathering server and client library

Go 4,104 435 Updated Dec 29, 2025

Fraktal's Ransomware Emulator

C# 101 23 Updated Apr 5, 2024

REST API Fuzz Testing (RAFT): Source code for self-hosted service developed for Azure, including the API, orchestration engine, and default set of security tools (including MSR's RESTler), that ena…

F# 265 42 Updated Jan 13, 2022

zero-trust remote firewall instrumentation

Go 254 31 Updated Jul 13, 2024

Toolbox containing research notes & PoC code for weaponizing .NET's DLR

PowerShell 525 112 Updated Jan 21, 2022

Scan is a free & Open Source DevSecOps tool for performing static analysis based security testing of your applications and its dependencies. CI and Git friendly.

Python 861 121 Updated Sep 1, 2023

Tool to check for dependency confusion vulnerabilities in NuGet package management systems

C# 15 5 Updated Mar 6, 2021

Tool to check for dependency confusion vulnerabilities in multiple package management systems

Go 773 104 Updated Aug 19, 2024

Data exfiltration over DNS request covert channel

JavaScript 878 191 Updated Apr 29, 2024

A client software for https://github.com/joohoi/acme-dns

Go 134 24 Updated Jun 29, 2023

PwnMachine is a self hosting solution based on docker aiming to provide an easy to use pwning station for bug hunters.

Vue 322 53 Updated Jul 31, 2024

qsinject (Query String Inject) is a tool that allows you to quickly substitute query string values with regex matches, one-at-a-time.

Go 30 8 Updated May 6, 2020

HackerOne "in scope" domains

Python 493 131 Updated Jan 2, 2026

Frida Scripts

JavaScript 652 139 Updated Sep 26, 2022

A thorough library database to assist with binary exploitation tasks.

Python 194 16 Updated Aug 1, 2022

Make temporary edits to your Go module dependencies

Go 910 20 Updated Jun 3, 2025

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Go 30,772 2,864 Updated Jan 1, 2026

CodiMD - Realtime collaborative markdown notes on all platforms.

JavaScript 9,928 1,116 Updated Oct 2, 2025

Private keys that have become public ...

PHP 184 30 Updated Nov 17, 2025

A tool that can help detect and takeover subdomains with dead DNS records

Go 772 138 Updated Jan 3, 2021
Next