Skip to content
View zer0x07's full-sized avatar
:atom:
:atom:

Highlights

  • Pro

Block or report zer0x07

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

A simple splunk package for obtaining reverse shells on both Windows and most *nix systems.

PowerShell 123 17 Updated Aug 20, 2018

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

PowerShell 9,691 2,547 Updated Apr 25, 2024

Tomcat-Ajp协议文件读取漏洞

Python 794 341 Updated Mar 3, 2020

A super small jsp webshell with file upload capabilities.

Java 316 135 Updated Aug 20, 2021

A Tool for Domain Flyovers

Go 5,891 911 Updated May 22, 2022

Joomla! Core 1.5.0 - 3.9.4 - Directory Traversal / Authenticated Arbitrary File Deletion in Python3

Python 21 3 Updated Feb 27, 2023

EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.

Python 5,600 904 Updated Jan 5, 2026

Local file inclusion exploitation tool

Python 915 113 Updated Oct 1, 2025

Words categorized by topic.

JavaScript 331 134 Updated Sep 2, 2025

Security Auditor Utility for GraphQL APIs

Python 584 84 Updated Nov 20, 2025

InQL - A Burp Extension for GraphQL Security Testing

Kotlin 47 5 Updated Jan 15, 2026

graphw00f is GraphQL Server Engine Fingerprinting utility for software security professionals looking to learn more about what technology is behind a given GraphQL endpoint.

Python 794 90 Updated Jun 9, 2025

GraphQL threat framework used by security professionals to research security gaps in GraphQL implementations

339 33 Updated Jul 1, 2025

A platform to create documentation/wiki content built with PHP & Laravel

PHP 18,080 2,317 Updated Jan 13, 2026

SCADA StrangeLove Default/Hardcoded Passwords List

513 190 Updated Nov 14, 2016

Exposing CharmingKitten's malicious activity for IRGC-IO Counterintelligence division (1500)

C# 422 98 Updated Oct 27, 2025

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Python 3,274 401 Updated Apr 18, 2023

A semi-interactive PHP shell compressed into a single file.

PHP 1,021 200 Updated Feb 14, 2018

Blind WAF identification tool

Python 710 129 Updated Jun 25, 2024

Automatic SQL injection and database takeover tool

Python 36,312 6,161 Updated Jan 14, 2026

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 74,392 16,508 Updated Jan 3, 2026

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…

PHP 68,174 24,861 Updated Jan 15, 2026

OpenFuck exploit updated to linux 2018 - Apache mod_ssl < 2.8.7 OpenSSL - Remote Buffer Overflow

C 196 79 Updated Oct 20, 2025

Take a list of domains and probe for working HTTP and HTTPS servers

Go 3,078 527 Updated Jun 22, 2024

In-depth attack surface mapping and asset discovery

Go 13,989 2,074 Updated Jan 16, 2026

Sample pentest report provided by TCM Security

1,309 327 Updated Mar 18, 2022

Another Windows Local Privilege Escalation from Service Account to System

C 1,139 135 Updated Jan 9, 2021

Abusing impersonation privileges through the "Printer Bug"

C 2,162 366 Updated Sep 10, 2020

A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM.

C++ 2,715 487 Updated Dec 18, 2021
Next