Skip to content
View BHaFSec's full-sized avatar

Block or report BHaFSec

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

This repository contains several applications, demonstrating the Meltdown bug.

C 4,164 522 Updated May 30, 2022

A hacked together PHP shell designed to be stealthy and portable

JavaScript 52 17 Updated Apr 1, 2014

Scans the local network to discover hosts, and automatically generates the user_config.xml file for Apache Guacamole.

Python 3 1 Updated Nov 1, 2017

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 74,627 16,536 Updated Jan 21, 2026
Python 2 Updated Feb 8, 2016

NSE script based on Vulners.com API

Lua 3,364 561 Updated Sep 26, 2025

Manage all logistical information for a pentest including clients, contacts, employees, findings, projects, scoping, and vulnerabilities.

PHP 43 20 Updated Apr 18, 2024

Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to execute

PowerShell 2,194 393 Updated Sep 23, 2019

Custom bash scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload creation using Metasploit. For use with Kali Linux.

Shell 3,805 876 Updated Jan 22, 2026

Batch file to help automate Windows enumeration for privilege escalation

Batchfile 91 36 Updated Sep 25, 2016

a cheat-sheet for mathematical notation in code form

15,462 1,102 Updated Mar 8, 2022

Fully functional multiple cryptocurrency and fiat currency exchange.

8 3 Updated Dec 6, 2017

PowerShell Script to Dump Windows Credentials from the Credential Manager

PowerShell 730 118 Updated Dec 12, 2017

Linux rootkit for Ubuntu 16.04 and 10.04 (Linux Kernels 4.4.0 and 2.6.32), both i386 and amd64

C 818 201 Updated Apr 7, 2024

A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.

Python 2,183 461 Updated Dec 11, 2022

⚙️ A curated list of static analysis (SAST) tools and linters for all programming languages, config files, build tools, and more. The focus is on tools which improve code quality.

Rust 14,330 1,416 Updated Jan 23, 2026

A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.

BlitzBasic 3,889 1,191 Updated Sep 27, 2021

Small and highly portable detection tests based on MITRE's ATT&CK.

C 11,516 3,052 Updated Jan 20, 2026

A collection of awesome penetration testing resources, tools and other shiny things

25,016 4,710 Updated Dec 17, 2025

✍️ A curated list of CVE PoCs.

3,476 726 Updated Jan 4, 2022

Dshell is a network forensic analysis framework.

Python 5,488 1,141 Updated May 7, 2024

All in one tool for Information Gathering, Vulnerability Scanning and Crawling. A must have tool for all penetration testers

PHP 3,515 930 Updated Jul 31, 2024

A framework for wireless pentesting.

Python 1,228 164 Updated Oct 14, 2020

This repository is DEPRECATED, please use bettercap as this tool has been ported to its BLE modules.

1,092 145 Updated Feb 19, 2019

Bruteforcing from various scanner output - Automatically attempts default creds on found services.

Go 2,355 427 Updated Jan 19, 2026

Exploits written by the Rhino Security Labs team

Python 1,092 295 Updated Jan 23, 2021

An exploit for Apache Struts CVE-2017-5638

Python 441 135 Updated May 21, 2018

BFAC (Backup File Artifacts Checker): An automated tool that checks for backup artifacts that may disclose the web-application's source code.

Python 562 103 Updated Aug 25, 2022

Remote Recon and Collection

PowerShell 459 98 Updated Nov 23, 2017

OWASP based Web Application Security Testing Checklist is an Excel based checklist which helps you to track the status of completed and pending test cases.

4 2 Updated Feb 6, 2017
Next