Skip to content
View amzza0x00's full-sized avatar

Block or report amzza0x00

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

A curated list of awesome things related to Telegram Mini Apps (TMA).

1,300 106 Updated Mar 11, 2025

APIKit 是Burp Suite 的一个API接口扫描插件,该版本APIKit是对API-Security项目的APIKit1.0进行的二开,增加了扫描开关,避免直接打开burp乱扫被抓起来

Java 92 3 Updated Dec 19, 2025

`Raw Files Server`(简称 RFS)是一个支持 HTTP/自定义TCP 协议双栈的文件分发服务端,适用于内网文件分发、免杀落地等场景。

Go 7 1 Updated May 11, 2025

APIKit:Discovery, Scan and Audit APIs Toolkit All In One.

Java 2,250 181 Updated Apr 2, 2024

Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

Java 1,777 115 Updated Mar 24, 2026

A terminal for a more modern age

TypeScript 69,830 3,923 Updated Mar 20, 2026

MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It ca…

PowerShell 3,221 601 Updated Aug 7, 2025

Windows Local Privilege Escalation Cookbook

PowerShell 1,287 198 Updated Feb 5, 2026

A tool matrix for Russian APTs based on the Ransomware Tool Matrix

232 44 Updated Aug 20, 2025

Automatic SQL injection and database takeover tool

Python 36,932 6,226 Updated Mar 20, 2026

🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks

Java 950 138 Updated Jan 15, 2022

Open-source engine for Heroes of Might and Magic III

C++ 5,546 594 Updated Mar 26, 2026

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Python 5,110 775 Updated Mar 24, 2026

Powerful+Fast+Low Privilege Kubernetes discovery tools

Go 268 18 Updated Jul 29, 2025

FastJson全版本Docker漏洞环境(涵盖1.2.47/1.2.68/1.2.80等版本),主要包括JNDI注入及高版本绕过、waf绕过、文件读写、原生反序列化、利用链探测绕过、不出网利用等。从黑盒的角度覆盖FastJson深入利用

Python 1,188 155 Updated Jul 12, 2024

📦 Make security testing of K8s, Docker, and Containerd easier.

Go 4,594 599 Updated Feb 23, 2026

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

Java 6,127 1,321 Updated Mar 10, 2021

WeChatOpenDevTool 微信小程序强制开启开发者工具

Python 4,066 926 Updated Sep 15, 2024

A red team tool that assists into extracting/dumping master credentials and/or entries from different password managers.

C++ 790 95 Updated Jan 9, 2025

红蓝对抗:钓鱼演练资源汇总&备忘录

1,160 121 Updated Nov 6, 2024

域内自动化信息搜集利用工具

Go 468 38 Updated Oct 24, 2023

Obfuscate Go builds

Go 5,368 344 Updated Mar 21, 2026

Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters

C 4,514 735 Updated Jul 8, 2025

CobaltStrike Beacon written in .Net 4 用.net重写了stager及Beacon,其中包括正常上线、文件管理、进程管理、令牌管理、结合SysCall进行注入、原生端口转发、关ETW等一系列功能

C# 729 148 Updated Sep 1, 2021

DavRelayUp - a universal no-fix local privilege escalation in domain-joined windows workstations where LDAP signing is not enforced (the default settings).

C# 568 78 Updated Jun 5, 2023

x64 binary obfuscator

C++ 1,963 270 Updated Jul 14, 2023

基于golang实现的impacket

Go 245 21 Updated Aug 28, 2023

RedGuard is a C2 front flow control tool,Can avoid Blue Teams,AVs,EDRs check.

Go 1,560 213 Updated Aug 20, 2024
Next