Skip to content
View tomnomnom's full-sized avatar
☺️
Taking it easy
☺️
Taking it easy

Sponsors

@zaerald
@M0dred
@amterp
@eugneigoaxae
Private Sponsor
@danielmiessler
@projectdiscovery

Sponsoring

@Wasted-Audio

Highlights

  • Pro

Block or report tomnomnom

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
67 stars written in Python
Clear filter

A collective list of free APIs

Python 393,134 42,076 Updated Nov 4, 2025

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Python 74,613 16,532 Updated Jan 21, 2026

Hunt down social media accounts by username across social networks

Python 72,113 8,544 Updated Jan 24, 2026

⏬ Dumb downloader that scrapes the web

Python 56,704 9,807 Updated Apr 27, 2025

The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.

Python 47,569 2,161 Updated Apr 18, 2024

⚡ Automatically decrypt encryptions without knowing the key or cipher, decode encodings, and crack hashes ⚡

Python 20,844 1,375 Updated Mar 5, 2025

Web path scanner

Python 13,872 2,423 Updated Jan 17, 2026

CTF framework and exploit development library

Python 13,200 1,809 Updated Jan 23, 2026

Prowler is the world’s most widely used open-source cloud security platform that automates security and compliance across any cloud environment.

Python 12,795 1,943 Updated Jan 23, 2026

Record terminal sessions as SVG animations

Python 9,756 444 Updated Jun 16, 2020

OneForAll是一款功能强大的子域收集工具

Python 9,561 1,415 Updated Sep 12, 2025

🐸 Identify anything. pyWhat easily lets you identify emails, IP addresses, and more. Feed it a .pcap file or some text and it'll tell you what it is! 🧙‍♀️

Python 7,135 387 Updated Oct 31, 2023

Web application fuzzer

Python 6,382 1,402 Updated Jan 21, 2026

WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

Python 6,137 1,028 Updated Jan 20, 2026

HTTP parameter discovery suite.

Python 6,032 849 Updated Feb 20, 2025

Scanning APK file for URIs, endpoints & secrets.

Python 5,781 559 Updated Aug 20, 2025

EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.

Python 5,615 904 Updated Jan 5, 2026

"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.

Python 5,522 790 Updated Feb 8, 2025

The Python error steamroller.

Python 5,284 179 Updated Aug 12, 2023

An enterprise friendly way of detecting and preventing secrets in code.

Python 4,388 537 Updated Mar 13, 2025

Server-Side Template Injection and Code Injection Detection and Exploitation Tool

Python 4,106 688 Updated Apr 21, 2024

File upload vulnerability scanner and exploitation tool.

Python 3,293 517 Updated May 8, 2025

A collection of custom security tools for quick needs.

Python 3,284 800 Updated May 1, 2023

SSRF (Server Side Request Forgery) testing resources

Python 2,481 491 Updated Oct 12, 2024

A Python program to scrape secrets from GitHub through usage of a large repository of dorks.

Python 2,478 444 Updated Aug 3, 2024

Generates permutations, alterations and mutations of subdomains and then resolves them

Python 2,462 449 Updated Jan 9, 2025
Python 2,312 430 Updated Dec 8, 2023

gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...

Python 2,233 356 Updated Jun 10, 2025

Index your Gmail Inbox with Elasticsearch

Python 2,057 160 Updated May 21, 2025

Another piece of your extended mind

Python 1,855 78 Updated Jan 13, 2026
Next