Highlights
Stars
A Caido plugin to monitor, intercept, and debug JavaScript sinks based on customizable configurations.
A modern platform for visual, flexible, and extensible graph-based investigations. For cybersecurity analysts and investigators.
Per-component Internationalisation solution for JS application. Type-Safe. Translate with AI. Edit Visually.
This repository is a collection of JavaScript gadgets that can be used to bypass XSS mitigations such as Content Security Policy (CSP) and HTML sanitizers like DOMPurify.
A cross platform library to write offensive and defensive security tools in Go
Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR / APK applications.
Cross-platform username reconnaissance tool built for OSINT investigators, cyber threat analysts, red teamers, and CTF enthusiasts.
The ldapconsole script allows you to perform custom LDAP requests to a Windows domain.
Offensive Web is a documentation website about web security research, bypass and new exploitation techniques.
A browser extension that allows you to monitor, intercept, and debug JavaScript sinks based on customizable configurations.
Visualize and manage your Flipper Zero animations directly from your computer - Flipper Animation Manager
Awesome list of step by step techniques to achieve Remote Code Execution on various apps!
A python script to dump all the challenges locally of a CTFd-based Capture the Flag.
Discord Root-Me bot - built with Discord.js
This tool allows to automatically test for Content Security Policy bypass payloads.
A python script to extract information from a Microsoft Remote Desktop Web Access (RDWA) application
Proof of concept of CVE-2022-21907 Double Free in http.sys driver, triggering a kernel crash on IIS servers
Repository for miscellaneous repository management and discussions: https://github.com/revoltchat/revolt/discussions
This Python script can be used to bypass IP source restrictions using HTTP headers.
dead-simple blog template powered by Markdown and PHP
