Skip to content
View 0xmafan's full-sized avatar
  • Turin, Italy
  • 16:26 (UTC +01:00)
  • X @0mafan

Highlights

  • Pro

Block or report 0xmafan

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results
JavaScript 427 10 Updated Jan 7, 2026

Book Example Code for Hands-On Network Programming with C

C 694 178 Updated Jun 24, 2025

A tool for auditing endpoints defined in exposed (Swagger/OpenAPI) definition files.

Go 712 97 Updated Nov 25, 2025

a security scanner for custom LLM applications

Python 1,084 115 Updated Dec 1, 2025

JavaScript Change Monitor for Bug Bounty Hunting - High-performance Go rewrite

Go 20 Updated Nov 9, 2025

A powerful JavaScript monitoring tool for bug bounty hunters. Track changes in JavaScript files across websites, detect new attack surfaces, and stay ahead of security vulnerabilities.

Go 87 14 Updated Apr 19, 2025

New ways of breaking app-integrated LLMs

Jupyter Notebook 2,035 141 Updated Jul 17, 2025

MapperPlus facilitates the extraction of source code from a collection of targets that have publicly exposed .js.map files.

JavaScript 286 29 Updated Oct 5, 2024

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Go 1,712 131 Updated May 22, 2024

A python tool used to discover endpoints, potential parameters, and a target specific wordlist for a given target

Python 1,461 180 Updated Jan 8, 2026

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

5,996 1,189 Updated Aug 14, 2024

A Chrome extension that automatically scans web pages and internal links for user-defined keywords, storing results and sending notifications or alerts.

JavaScript 25 4 Updated Sep 28, 2025

Scanning APK file for URIs, endpoints & secrets.

Python 5,776 560 Updated Aug 20, 2025

Frogy 2.0 is an automated external reconnaissance and Attack Surface Management (ASM) toolkit

HTML 323 73 Updated Oct 25, 2025

AI Red Teaming playground labs to run AI Red Teaming trainings including infrastructure.

TypeScript 1,778 263 Updated Jan 9, 2026

A list of Google Dorks for Bug Bounty, Web Application Security, and Pentesting

1,717 243 Updated Sep 29, 2025

An open-source AI agent that lives in your terminal.

TypeScript 17,233 1,494 Updated Jan 10, 2026

Awesome-LLM: a curated list of Large Language Model

25,979 2,249 Updated Jul 31, 2025

List of XSS Vectors/Payloads

1,354 269 Updated Jan 2, 2025

Here are the challenges (including sources) of the GreHack CTF.

C 107 28 Updated May 18, 2024

Cybersecurity AI (CAI), the framework for AI Security

Python 6,670 920 Updated Dec 23, 2025

Conference presentation slides

2,349 414 Updated Nov 15, 2025

Just A list Of Some Multilingual XSS Payloads and other weird ones i made

122 13 Updated Sep 28, 2025

Beyond XSS: Explore the Web Front-end Security Universe. A series about front-end security

JavaScript 170 37 Updated Oct 27, 2025

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wis…

Go 5,053 920 Updated Jan 1, 2026

BackupFinder discovers backup files on web servers by generating intelligent patterns.

Go 100 19 Updated Jul 29, 2025

jxscout superpowers JavaScript analysis for security researchers

JavaScript 326 30 Updated Sep 17, 2025

🐛 A list of writeups from the Google VRP Bug Bounty program

Python 1,422 240 Updated Nov 11, 2025

✂️ Removing CDN IPs from the list of IP addresses

Go 343 52 Updated Jul 22, 2025

Contextual Content Discovery Tool

Go 3,056 329 Updated Apr 29, 2024
Next