Skip to content
View BHaFSec's full-sized avatar

Block or report BHaFSec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
25 stars written in Python
Clear filter

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 74,629 16,537 Updated Jan 21, 2026

A swiss army knife for pentesting networks

Python 9,037 1,702 Updated Dec 6, 2023

Wrong project! You should head over to http://github.com/sshuttle/sshuttle

Python 8,883 621 Updated Feb 15, 2018

Create *beautiful* command-line interfaces with Python

Python 8,010 559 Updated Jun 23, 2025

Dshell is a network forensic analysis framework.

Python 5,488 1,141 Updated May 7, 2024

A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications

Python 2,203 251 Updated Dec 25, 2020

A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.

Python 2,183 461 Updated Dec 11, 2022

Miscellaneous exploit code

Python 1,571 585 Updated Oct 6, 2023

Security Tool to Look For Interesting Files in S3 Buckets

Python 1,453 248 Updated Apr 10, 2024

The iOS Security Testing Framework

Python 1,380 290 Updated Oct 25, 2020

A framework for wireless pentesting.

Python 1,228 164 Updated Oct 14, 2020

Lightweight Python utilities for working with Redis

Python 1,202 92 Updated Jan 15, 2026

Exploits written by the Rhino Security Labs team

Python 1,092 295 Updated Jan 23, 2021

Poc, Presentation of Monitor OSD Exploitation, and shenanigans of high quality.

Python 917 133 Updated Jun 27, 2017

The 'exploitable' GDB plugin

Python 744 123 Updated Aug 13, 2022

BFAC (Backup File Artifacts Checker): An automated tool that checks for backup artifacts that may disclose the web-application's source code.

Python 562 103 Updated Aug 25, 2022

Various PoCs

Python 502 202 Updated Jan 27, 2020

An exploit for Apache Struts CVE-2017-5638

Python 441 135 Updated May 21, 2018

Command-line Google dork tool. This is an early predecessor to dorkbot, which may be more useful: https://github.com/utiso/dorkbot

Python 153 38 Updated Jul 16, 2017

a command-line web scraping tool

Python 150 17 Updated May 23, 2023

A free and open source command-line shell and scripting language designed especially for security testing

Python 128 15 Updated Oct 12, 2013

The NoSQL Honeypot Framework

Python 103 23 Updated Oct 17, 2023

Basic script for monitoring new posts on Pastebin for keywords

Python 12 1 Updated Nov 27, 2016

Scans the local network to discover hosts, and automatically generates the user_config.xml file for Apache Guacamole.

Python 3 1 Updated Nov 1, 2017
Python 2 Updated Feb 8, 2016