Skip to content
View xomcoom's full-sized avatar

Block or report xomcoom

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

Automation Recon tool which works with Large & Medium scopes. It performs a lot of tasks and gets back all the results in separated files.

Shell 686 134 Updated Jul 15, 2024

Notes from OSCP, CTF, security adventures, etc...

Python 64 22 Updated Feb 6, 2024

Subdomain Enumerator and Simple Crawler

Rust 300 76 Updated Dec 22, 2025

OSINT Extension — Chrome extension for quick reconnaissance

JavaScript 10 3 Updated Jan 9, 2026

CVE-2025-55182 POC

JavaScript 791 206 Updated Dec 8, 2025

Reverse proxies cheatsheet

Python 1,854 221 Updated Nov 4, 2023
Shell 36 14 Updated Jan 8, 2026

Tools and Techniques for Red Team / Penetration Testing

8,072 1,109 Updated Mar 18, 2025

Latest CVEs with their Proof of Concept exploits.

Python 1,066 129 Updated Jan 12, 2026

DockerSpy searches for images on Docker Hub and extracts sensitive information such as authentication secrets, private keys, and more.

Go 243 31 Updated Jul 31, 2024

Mind-Maps of Several Things

2,621 547 Updated Jun 29, 2023

Frogy 2.0 is an automated external reconnaissance and Attack Surface Management (ASM) toolkit

HTML 324 74 Updated Oct 25, 2025

The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, …

Rust 3,656 390 Updated Jan 6, 2026

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wis…

Go 5,054 919 Updated Jan 1, 2026

Bug Bounty Hunting Framework Designed to Help Beginners Compete w/ the Pros

JavaScript 506 109 Updated Jan 12, 2026

POC for CVE-2024-23897 Jenkins File-Read

Python 38 5 Updated Nov 20, 2025

Notes of the book System Desgin Interview - An Insider's Guide

1,141 225 Updated Feb 23, 2025

Shell 169 53 Updated Sep 7, 2025

Multi-cloud OSINT tool. Enumerate public resources in AWS, Azure, and Google Cloud.

Python 1,988 290 Updated Jul 12, 2025

Quickly discover exposed hosts on the internet using multiple search engines.

Go 2,772 251 Updated Jan 7, 2026

A curated list of Android Security materials and resources For Pentesters and Bug Hunters

1,847 276 Updated May 5, 2025

One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️

Python 6,367 755 Updated Dec 20, 2025

Awesome XSS Payloads

84 44 Updated Feb 24, 2016

Awesome list of step by step techniques to achieve Remote Code Execution on various apps!

Dockerfile 1,934 224 Updated Oct 7, 2023

A python script to scan for Apache Tomcat server vulnerabilities.

Python 887 107 Updated Nov 1, 2025

bXSS is a utility which can be used by bug hunters and organizations to identify Blind Cross-Site Scripting.

JavaScript 563 66 Updated Mar 4, 2023

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Shell 10,009 949 Updated Jan 8, 2026

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

Shell 7,044 1,116 Updated Jan 5, 2026

Community curated list of templates for the nuclei engine to find security vulnerabilities.

JavaScript 11,778 3,294 Updated Jan 12, 2026

Collection of Scripts for shodan searching stuff.

Python 1,134 344 Updated Dec 10, 2025
Next