Skip to content
View 0x1git's full-sized avatar
pwn
pwn

Highlights

  • Pro

Block or report 0x1git

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

This repo contains useful scripts that AI created for me which I would have been too lazy for

Python 85 7 Updated Feb 10, 2026

A wordlist of API names for web application assessments

865 224 Updated Jun 17, 2025

GQLSpection - parses GraphQL introspection schema and generates possible queries

Python 99 14 Updated Mar 6, 2025

Generate queries from graphql schema, used for writing api test.

JavaScript 388 94 Updated Nov 15, 2025

A streamlined tool for discovering private TLDs for security research.

Go 312 11 Updated Feb 16, 2026

Nuclei templates written by geeknik. Claude is my co-pilot. 🤖

292 70 Updated Aug 8, 2025

REcollapse is a helper tool for black-box regex fuzzing to bypass validations and discover normalizations in web applications

Python 1,288 147 Updated Aug 7, 2025

CSPBypass.com, a tool designed to help ethical hackers bypass restrictive Content Security Policies (CSP) and exploit XSS (Cross-Site Scripting) vulnerabilities on sites where injections are blocke…

HTML 565 89 Updated Feb 7, 2026

Take a list of domains and probe for working HTTP and HTTPS servers

Go 3,086 528 Updated Jun 22, 2024

Recon MindMap (RMM)

Go 179 18 Updated May 26, 2024

Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network

Python 2,508 496 Updated Mar 26, 2024

DNSTake — A fast tool to check missing hosted DNS zones that can lead to subdomain takeover

Go 851 76 Updated Feb 13, 2023

"Can I take over DNS?" — a list of DNS providers and how to claim vulnerable domains.

1,082 100 Updated Mar 3, 2025

Mass Hunting & Exploitation PoC for CVE-2025-55182 & CVE-2025-66478

Python 38 10 Updated Dec 7, 2025

Burp Suite extension that adds built-in MCP tooling, AI-assisted analysis, privacy controls, passive and active scanning and more

Kotlin 633 102 Updated Feb 11, 2026

List of XSS Vectors/Payloads

1,361 269 Updated Jan 14, 2026

Scope aggregation tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!

Go 1,264 176 Updated Feb 13, 2026

Tool to find the real IP behind CDNs/WAFs like cloudflare using passive recon by retrieving the favicon hash. For the same hash value, all the possible IPs, PORTs and SSL/TLS Certs are searched to …

Shell 184 35 Updated Jan 6, 2021

Use favicons to improve your target recon phase. Quickly detect technologies, WAF, exposed panels, known services.

Go 231 31 Updated Feb 2, 2026

Making Favicon.ico based Recon Great again !

Python 1,264 176 Updated Aug 29, 2023

A build tool for GraphQL projects.

TypeScript 427 55 Updated Feb 24, 2019

Web Fuzzing Box - Web 模糊测试字典与一些Payloads

HTML 2,443 404 Updated May 28, 2025

Daily target monitoring system

Python 2 1 Updated May 25, 2025

compute favicon hashes of your target, generates shodan dork too.

Go 2 Updated Nov 29, 2025

Practical setup guides and helpers to connect Burp Suite MCP Server to multiple AI backends (Codex, Gemini, Ollama, ...).

Python 188 34 Updated Jan 19, 2026

InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.

Kotlin 1,733 178 Updated Feb 16, 2026

Firepwn is a tool made for testing the Security Rules of a firebase application.

TypeScript 623 39 Updated Feb 8, 2026

📜 Yet another collection of wordlists

2,136 359 Updated Feb 14, 2026

A Python script that queries a list of IPs and returns useful or interesting information (for externals/webapps)

Python 7 Updated Jul 15, 2025
Next