Skip to content
View m0chan's full-sized avatar
💭
Hacking
💭
Hacking

Highlights

  • Pro

Block or report m0chan

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
192 stars written in Python
Clear filter

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 76,199 16,769 Updated Mar 16, 2026

Hunt down social media accounts by username across social networks

Python 73,867 8,774 Updated Mar 19, 2026

The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.

Python 31,573 4,411 Updated Mar 19, 2026

Set up a personal VPN in the cloud

Python 30,330 2,360 Updated Mar 18, 2026

⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡

Python 21,255 1,424 Updated Mar 5, 2025

Open-source AI hackers to find and fix your app’s vulnerabilities.

Python 21,045 2,222 Updated Mar 19, 2026

SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.

Python 17,028 2,857 Updated Dec 15, 2024

E-mails, subdomains and names Harvester - OSINT

Python 15,858 2,443 Updated Mar 19, 2026

Impacket is a collection of Python classes for working with network protocols.

Python 15,563 3,883 Updated Mar 19, 2026

Most advanced XSS scanner.

Python 14,826 2,073 Updated Apr 26, 2025

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

Python 13,359 2,051 Updated Mar 19, 2026

Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS tunneling.

Python 13,184 786 Updated Mar 18, 2026

The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWA…

Python 12,786 2,698 Updated Mar 16, 2026

Automated Penetration Testing Agentic Framework Powered by Large Language Models

Python 12,152 2,071 Updated Feb 23, 2026

Credentials recovery project

Python 10,724 2,122 Updated Sep 18, 2025

Library for building powerful interactive command line applications in Python

Python 10,335 771 Updated Mar 17, 2026

A swiss army knife for pentesting networks

Python 9,102 1,698 Updated Dec 6, 2023

📱 objection - runtime mobile exploration

Python 8,958 958 Updated Mar 12, 2026

Nginx configuration static analyzer

Python 8,547 447 Updated Jul 28, 2024

Multi-Cloud Security Auditing Tool

Python 7,581 1,193 Updated Sep 23, 2025

HexStrike AI MCP Agents is an advanced MCP server that lets AI agents (Claude, GPT, Copilot, etc.) autonomously run 150+ cybersecurity tools for automated pentesting, vulnerability discovery, bug b…

Python 7,560 1,666 Updated Mar 6, 2026

Everything about Web Application Firewalls (WAFs) from Security Standpoint! 🔥

Python 7,396 1,168 Updated Aug 28, 2025

Web application fuzzer

Python 6,446 1,403 Updated Jan 21, 2026

🐍 A toolkit for testing, tweaking and cracking JSON Web Tokens

Python 6,436 770 Updated May 1, 2025

WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

Python 6,242 1,036 Updated Jan 27, 2026

Scanning APK file for URIs, endpoints & secrets.

Python 5,999 567 Updated Aug 20, 2025

Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

Python 5,614 845 Updated Apr 15, 2025

The Network Execution Tool

Python 5,349 675 Updated Mar 19, 2026

Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wis…

Python 5,253 956 Updated Mar 13, 2026

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Python 5,099 774 Updated Mar 17, 2026
Next