Skip to content
View 0xmafan's full-sized avatar
  • Turin, Italy
  • 19:13 (UTC +01:00)
  • X @0mafan

Highlights

  • Pro

Block or report 0xmafan

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results
JavaScript 426 10 Updated Jan 7, 2026

Book Example Code for Hands-On Network Programming with C

C 693 178 Updated Jun 24, 2025

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Go 712 97 Updated Nov 25, 2025

a security scanner for custom LLM applications

Python 1,082 115 Updated Dec 1, 2025

JavaScript Change Monitor for Bug Bounty Hunting - High-performance Go rewrite

Go 20 Updated Nov 9, 2025

A powerful JavaScript monitoring tool for bug bounty hunters. Track changes in JavaScript files across websites, detect new attack surfaces, and stay ahead of security vulnerabilities.

Go 87 14 Updated Apr 19, 2025

New ways of breaking app-integrated LLMs

Jupyter Notebook 2,036 141 Updated Jul 17, 2025

MapperPlus facilitates the extraction of source code from a collection of targets that have publicly exposed .js.map files.

JavaScript 286 29 Updated Oct 5, 2024

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Go 1,711 132 Updated May 22, 2024

A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target

Python 1,460 181 Updated Jan 8, 2026

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

5,994 1,189 Updated Aug 14, 2024

A Chrome extension that automatically scans web pages and internal links for user-defined keywords, storing results and sending notifications or alerts.

JavaScript 25 4 Updated Sep 28, 2025

Scanning APK file for URIs, endpoints & secrets.

Python 5,773 560 Updated Aug 20, 2025

Frogy 2.0 is an automated external reconnaissance and Attack Surface Management (ASM) toolkit

HTML 323 72 Updated Oct 25, 2025

AI Red Teaming playground labs to run AI Red Teaming trainings including infrastructure.

TypeScript 1,776 263 Updated Jan 9, 2026

A list of Google Dorks for Bug Bounty, Web Application Security, and Pentesting

1,716 243 Updated Sep 29, 2025

An open-source AI agent that lives in your terminal.

TypeScript 17,210 1,490 Updated Jan 9, 2026

Awesome-LLM: a curated list of Large Language Model

25,976 2,249 Updated Jul 31, 2025

List of XSS Vectors/Payloads

1,354 269 Updated Jan 2, 2025

Here are the challenges (including sources) of the GreHack CTF.

C 107 28 Updated May 18, 2024

Cybersecurity AI (CAI), the framework for AI Security

Python 6,660 918 Updated Dec 23, 2025

Conference presentation slides

2,347 414 Updated Nov 15, 2025

Just A list Of Some Multilingual XSS Payloads and other weird ones i made

122 13 Updated Sep 28, 2025

Beyond XSS: Explore the Web Front-end Security Universe. A series about front-end security

JavaScript 170 37 Updated Oct 27, 2025

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wis…

Go 5,047 920 Updated Jan 1, 2026

BackupFinder discovers backup files on web servers by generating intelligent patterns.

Go 100 19 Updated Jul 29, 2025

jxscout superpowers JavaScript analysis for security researchers

JavaScript 327 30 Updated Sep 17, 2025

🐛 A list of writeups from the Google VRP Bug Bounty program

Python 1,426 240 Updated Nov 11, 2025

✂️ Removing CDN IPs from the list of IP addresses

Go 343 52 Updated Jul 22, 2025

Contextual Content Discovery Tool

Go 3,056 330 Updated Apr 29, 2024
Next