1-day current streak·9-day longest streak
Hey 👋, I am Ajin, a security engineer with strong proficiency in computer security and applied security research. Profile / Social / Blog / Services
-
Mobile-Security-Framework-MobSF ★ PINNED ⑂
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
★ 48 2y agoExplain → -
nodejsscan ★ PINNED
nodejsscan is a static security code scanner for Node.js applications.
CSS ★ 2.6k 9mo agoExplain → -
Droid-Application-Fuzz-Framework ★ PINNED
Android application fuzzing framework with fuzzers and crash monitor.
HTML ★ 295 5y agoExplain → -
libsast ★ PINNED
Generic SAST Library
Python ★ 138 2mo agoExplain → -
njsscan ★ PINNED
njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.
JavaScript ★ 435 1y agoExplain → -
CMSScan
CMS Scanner: Scan Wordpress, Drupal, Joomla, vBulletin websites for Security issues
CSS ★ 1.1k 5y agoExplain → -
OWASP-Xenotix-XSS-Exploit-Framework
OWASP Xenotix XSS Exploit Framework is an advanced Cross Site Scripting (XSS) vulnerability detection and exploitation framework.
Python ★ 547 6y agoExplain → -
Xenotix-Python-Keylogger
Xenotix Python Keylogger for Windows.
Python ★ 462 7y agoExplain → -
Node.Js-Security-Course
Contents for Node.Js Security Course
JavaScript ★ 346 5y agoExplain → -
WebAppSec
Web Application Security
Python ★ 133 6mo agoExplain → -
Static-DOM-XSS-Scanner
Static DOM XSS Scanner is a Static Analysis tool written in python that will iterate through all the JavaScript and HTML files under the given directory and will list out all the possible sources and sinks that may cause DOM XSS. At the end of the scan, the tool will generate an HTML report.
Python ★ 119 11y agoExplain → -
Xenotix-APK-Reverser
Xenotix APK Reverser is an OpenSource Android Application Package (APK) decompiler and disassembler powered by dex2jar, baksmali and jd-core.
Python ★ 80 11y agoExplain → -
aws_security_tools
Scripts and tools for AWS Pentest
Python ★ 54 5y agoExplain → -
PoC
Proof of Concepts, Exploits
Python ★ 29 1y agoExplain → -
Xenotix-xBOT
Xenotix xBOT is a Cross Platform PoC Bot that abuse certain Google Services to implement it's C&C
Python ★ 28 8y agoExplain → -
njsscan-action
nodejsscan Github Action
Dockerfile ★ 28 1y agoExplain → -
WhatsApp-AutoClean
WhatsApp AutoClean is an android app that removes all WhatsApp media (images, videos, sound etc) and hide them from being shown in Gallery
Java ★ 16 11y agoExplain → -
tizen-security
Tools made for Tizen Security Analysis
Python ★ 15 11y agoExplain → -
Exploit-Research-Ported
Exploit Research & Development - Ported Exploits
Python ★ 12 9y agoExplain → -
package_scan
PoC: Python package static and dynamic analysis to detect environment variable stealing
Python ★ 11 5y agoExplain → -
MobileApp-Pentest-Cheatsheet ⑂
The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.
★ 10 10y agoExplain → -
bugbounty-cheatsheet ⑂
A list of interesting payloads, tips and tricks for bug bounty hunters.
★ 10 8y agoExplain → -
Android-SSL-Certificate-Pinning
A sample android application implementing Moxie's Certificate Pinning Library
Java ★ 9 11y agoExplain → -
JSComm-API-Hooker
Tool to hook all communication APIs including XHR/XHR2, WebSockets, Web Workers, PostMessage and Server Sent Events
JavaScript ★ 9 11y agoExplain → -
OpSec-Firefox-Addon-Exploit-Suite
OpSec Firefox Addon Exploit Suite is a POC application that demonstrate various flaws in the Firefox Add-on Security Model.
Visual Basic ★ 8 12y agoExplain → -
OAuth-Request-Crafter
OAuth Request Crafter
Visual Basic ★ 8 12y agoExplain → -
node.js-simple-https-server
A simple HTTPS server that uses self signed certificate. Useful for PoC purposes
JavaScript ★ 8 9y agoExplain → -
PayloadsAllTheThings ⑂
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
Python ★ 8 9y agoExplain → -
bad_python_extract
A vulnerable web application written in Python Flask to demonstrate insecure file extraction
Python ★ 8 8y agoExplain → -
awesome-web-security ⑂
🐶 A curated list of Web Security materials and resources.
★ 8 8y agoExplain → -
API-Security-Checklist ⑂
Checklist of the most important security countermeasures when designing, testing, and releasing your API
★ 7 9y agoExplain → -
Vulnerable_Tornado_App
An intentionally vulnerable web application written in Python using Tornado
CSS ★ 7 8y agoExplain → -
iSpy ⑂
A reverse engineering framework for iOS
Logos ★ 5 11y agoExplain → -
usbkill ⑂
usbkill waits for a change on your usb ports, then immediately kills your computer. Anti forensic, usb -> kill
Python ★ 5 11y agoExplain → -
AuditDroid ⑂
AduitDroid
Java ★ 5 10y agoExplain → -
CSS-Keylogging ⑂
Chrome extension and Express server that exploits keylogging abilities of CSS.
CSS ★ 5 8y agoExplain → -
WindowsExploits ⑂
Windows exploits, mostly precompiled.
Python ★ 5 9y agoExplain → -
AutomatingWindowsPrivilegeEscalation ⑂
No description.
Python ★ 5 9y agoExplain → -
proxy2 ⑂
HTTP/HTTPS proxy in a single python script
Python ★ 4 9y agoExplain → -
airgeddon ⑂
This is a multi-use bash script for Linux systems to audit wireless networks.
Shell ★ 4 8y agoExplain → -
poc-rogue
No description.
Python ★ 4 5y agoExplain → -
android-unpacker ⑂
Android Unpacker presented at Defcon 22: Android Hacker Protection Level 0
C ★ 3 11y agoExplain → -
iloot ⑂
OpenSource tool for iCloud backup extraction
Python ★ 3 11y agoExplain → -
lobotomy ⑂
Android Reverse Engineering Framework & Toolkit
Python ★ 3 10y agoExplain → -
ActiveScanPlusPlus ⑂
ActiveScan++ Burp Suite Plugin
Python ★ 3 9y agoExplain → -
injectAllTheThings ⑂
Seven different DLL injection techniques in one single project.
C ★ 3 9y agoExplain → -
dvna ⑂
Damn Vulnerable NodeJS Application
SCSS ★ 3 1y agoExplain → -
python-hash-calculator
Python Hash Calculator
★ 3 12y agoExplain → -
keychaindump ⑂
A proof-of-concept tool for reading OS X keychain passwords
C ★ 2 14y agoExplain → -
android-ssl-bypass ⑂
Black box tool to bypass SSL verification on Android, even when pinning is used.
Java ★ 2 13y agoExplain → -
simple-php-browser-detection
Simple PHP script to get browser details.
★ 2 13y agoExplain → -
injecthtml ⑂
injecthtml
Python ★ 2 12y agoExplain → -
nimbostratus ⑂
Tools for fingerprinting and exploiting Amazon cloud infrastructures
Python ★ 2 12y agoExplain → -
dumpdecrypted ⑂
Dumps decrypted mach-o files from encrypted iPhone applications from memory to disk. This tool is necessary for security researchers to be able to look under the hood of encryption.
C ★ 2 12y agoExplain → -
Xposed-Keylogger ⑂
No description.
Java ★ 2 12y agoExplain → -
Android-InsecureBankv2 ⑂
Vulnerable Android application for developers and security enthusiasts to learn about Android insecurities
Java ★ 2 11y agoExplain → -
lisa.py ⑂
-An Exploit Dev Swiss Army Knife.
Python ★ 2 11y agoExplain → -
scanjs ⑂
Static analysis tool for javascript code based. Scanjs uses Acorn to convert sources to AST, then walks AST looking for patterns.
JavaScript ★ 2 11y agoExplain → -
hookish ⑂
Hooks in to interesting functions and helps reverse the web app faster.
CSS ★ 2 11y agoExplain → -
JustTrustMe ⑂
An xposed module that disables SSL certificate checking for the purposes of auditing and app with cert pinning
Java ★ 2 11y agoExplain → -
tiny-mitm-proxy ⑂
Probably one of the smallest SSL MITM proxies you can make
Shell ★ 2 11y agoExplain → -
commix ⑂
Automated All-in-One OS Command Injection and Exploitation Tool
Python ★ 2 11y agoExplain → -
secure-mobile-development ⑂
Secure Mobile Development - A collection of best practices
★ 2 10y agoExplain → -
fuzzdb ⑂
Official FuzzDB project repository
Java ★ 2 10y agoExplain → -
ADBI ⑂
Android Dynamic Binary Instrumentation tool for tracing Android native layer
C ★ 2 10y agoExplain → -
s2-032-exploit ⑂
Another struts2 S2-032 vulnerability exploit
Python ★ 2 10y agoExplain → -
SecLists ⑂
SecLists is the security tester's companion. It is a collection of multiple types of lists used during security assessments. List types include usernames, passwords, URLs, sensitive data grep strings, fuzzing payloads, and many more.
PHP ★ 2 10y agoExplain → -
Nosql-Exploitation-Framework ⑂
A Python Framework For NoSQL Scanning and Exploitation
Python ★ 2 10y agoExplain → -
tplmap ⑂
Automatic Server-Side Template Injection Detection and Exploitation Tool
Python ★ 2 9y agoExplain → -
InsecureProgramming ⑂
mirror of gera's insecure programming examples | http://community.coresecurity.com/~gera/InsecureProgramming/
C ★ 2 9y agoExplain → -
pymiproxy ⑂
A small and sweet man-in-the-middle proxy capable of doing HTTP and HTTP over SSL.
Python ★ 2 9y agoExplain → -
apache-struts2-CVE-2017-5638 ⑂
Demo Application and Exploit
Python ★ 2 9y agoExplain → -
PentestCommands ⑂
Some Handy Command For Network/Web Pentest
★ 2 9y agoExplain → -
ssl_logger ⑂
Decrypts and logs a process's SSL traffic.
Python ★ 2 9y agoExplain → -
how2heap ⑂
A repository for learning various heap exploitation techniques.
C ★ 2 9y agoExplain → -
altdns ⑂
Generates permutations, alterations and mutations of subdomains and then resolves them
Python ★ 2 9y agoExplain → -
awesome-windows-exploitation ⑂
A curated list of awesome Windows Exploitation resources, and shiny things. Inspired by awesom
★ 2 9y agoExplain → -
blackhat-arsenal-tools ⑂
Official Black Hat Arsenal Security Tools Repository
★ 2 9y agoExplain → -
bootcamp ⑂
A open contribute bootcamp to develop DevSecOps skills...
Shell ★ 2 9y agoExplain → -
afl-fuzz ⑂
Non-official repository for lcamtuf's American Fuzzy Lop http://lcamtuf.coredump.cx/afl/
C ★ 2 9y agoExplain → -
PRET ⑂
Printer Exploitation Toolkit - The tool that made dumpster diving obsolete.
Python ★ 2 8y agoExplain → -
hangoutsbot ⑂
Google Hangouts bot
Python ★ 2 8y agoExplain → -
CodeMirror ⑂
In-browser code editor
★ 2 6y agoExplain → -
www-community ⑂
OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.
★ 2 6y agoExplain → -
juice-shop ⑂
OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
JavaScript ★ 2 5y agoExplain → -
play-scraper ⑂
A web scraper to retrieve application data from the Google Play Store.
Python ★ 2 7y agoExplain → -
minhook ⑂
The Minimalistic x86/x64 API Hooking Library for Windows
C ★ 2 11y agoExplain → -
exploits ⑂
Some exploits and exploit development stuff.
Python ★ 1 13y agoExplain → -
java-pinning ⑂
TLS pinning for Java
Java ★ 1 11y agoExplain → -
Dir-Xcan ⑂
Python version of OWASP's DirBuster Application.
Python ★ 1 11y agoExplain → -
HTTPLeaks ⑂
HTTPLeaks
HTML ★ 1 11y agoExplain → -
inject-some-sql ⑂
Have fun injecting SQL into a Ruby on Rails application!
Ruby ★ 1 11y agoExplain → -
AndroidEagleEye ⑂
An Xposed based module which is capable of hooking both Android system APIs and applications' methods.
Java ★ 1 11y agoExplain → -
peda ⑂
PEDA - Python Exploit Development Assistance for GDB
Python ★ 1 11y agoExplain → -
commix-testbed ⑂
A collection of web pages, vulnerable to command injection flaws.
PHP ★ 1 11y agoExplain → -
anti-csrf-plugin ⑂
Chrome extension for blocking x-origin cookies
JavaScript ★ 1 10y agoExplain → -
immunio-xss-fuzzer-1 ⑂
Immunio's XSS Fuzzer tool
Python ★ 1 10y agoExplain → -
Javascript-Backdoor ⑂
Learn from Casey Smith @subTee
PowerShell ★ 1 10y agoExplain → -
PebbleWatch-LocateMe
Pebble App that Locates You
JavaScript ★ 1 10y agoExplain → -
vLokal_TheOracle_APISamples ⑂
No description.
Python ★ 1 10y agoExplain → -
wafw00f ⑂
WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.
Python ★ 1 10y agoExplain → -
SafeDOM
A failed attempt to prevent DOM XSS.
JavaScript ★ 1 10y agoExplain → -
enjarify ⑂
No description.
Python ★ 1 10y agoExplain → -
NoSQLi-Vulnerable-App
NoSQLi Vulnerable App
HTML ★ 1 10y agoExplain → -
CTF_WRITEUPS ⑂
CTF Writeups
Python ★ 1 10y agoExplain → -
diff-gui ⑂
GUI for Frida -Scripts
JavaScript ★ 1 9y agoExplain → -
Java-Deserialization-Cheat-Sheet ⑂
The cheat sheet about Java Deserialization vulnerabilities
★ 1 9y agoExplain → -
jPurify ⑂
jPurify
JavaScript ★ 1 9y agoExplain → -
startbootstrap-clean-blog ⑂
A clean Bootstrap blog theme created by Start Bootstrap
JavaScript ★ 1 9y agoExplain → -
formatStringExploiter ⑂
Helper script for working with format string bugs
Python ★ 1 9y agoExplain → -
writeups ⑂
CTF writeups
Python ★ 1 9y agoExplain → -
railsgoat ⑂
A vulnerable version of Rails that follows the OWASP Top 10
JavaScript ★ 1 9y agoExplain → -
markdown-here ⑂
Google Chrome, Firefox, and Thunderbird extension that lets you write email in Markdown and render it before sending.
JavaScript ★ 1 9y agoExplain → -
EdgeDbg ⑂
A simple command line exe to start and debug the Microsoft Edge browser.
C++ ★ 1 9y agoExplain → -
libdheap ⑂
A shared (dynamic) library that can be transparently injected into different processes to detect memory corruption in glibc heap
C ★ 1 9y agoExplain → -
domato ⑂
DOM fuzzer
Python ★ 1 8y agoExplain → -
session ⑂
Simple session middleware for Express
★ 1 6y agoExplain → -
ptrace-redirect ⑂
Example code for changing syscall arguments using ptrace
★ 1 6y agoExplain → -
mobsf-action ⑂
GitHub Actions for MobSF
★ 1 5y agoExplain → -
bcc ⑂
BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more
★ 1 5y agoExplain → -
owasp-mstg ⑂
The Mobile Security Testing Guide (MSTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes the technical processes for verifying the controls listed in the OWASP Mobile Application Security Verification Standard (MASVS).
★ 1 4y agoExplain → -
scanner-registry ⑂
No description.
★ 1 3y agoExplain → -
cdn
No description.
JavaScript ★ 1 1y agoExplain → -
go-sdk ⑂
No description.
Go ★ 1 5mo agoExplain → -
Signal-iOS ⑂
A private messenger for iOS.
★ 1 5y agoExplain → -
YouPlay
Media Server that dumps youtube playlist into mp3
Python ★ 1 7y agoExplain → -
PacSec2014 ⑂
Demo at PacSec2014
Python ★ 1 11y agoExplain → -
ctf
No description.
HTML ★ 1 3y agoExplain → -
semgrep-rules ⑂
semgrep rules registry
★ 1 6y agoExplain → -
codeql-uboot
No description.
CodeQL ★ 1 6y agoExplain → -
HtmlJsCrawler ⑂
Simple html and javascript files crawler
Python ★ 1 12y agoExplain → -
Google-Voice-on-Zenwatch-3-button
Google Voice on ZenWatch 3 crown button
Java ★ 0 9y agoExplain → -
pusher-http-ruby ⑂
Ruby library for Pusher Channels HTTP API
Ruby ★ 0 3y agoExplain → -
simplemde-markdown-editor ⑂
A simple, beautiful, and embeddable JavaScript Markdown editor. Delightful editing for beginners and experts alike. Features built-in autosaving and spell checking.
★ 0 5y agoExplain → -
ajin-abraham-starsoft-xtreme-ultravires-file-encryption__1-70285 ⑂
No description.
★ 0 5y agoExplain → -
ajin-abraham-starsoft-xtreme-icon-studio-pro-2008__1-70438 ⑂
No description.
★ 0 5y agoExplain → -
ajin-abraham-starsoft-xtreme-os-home-edition__1-70272 ⑂
No description.
★ 0 5y agoExplain → -
ajinabraham
Profile
★ 0 5y agoExplain → -
semgrep ⑂
Fast and syntax-aware semantic code pattern search for many languages: like grep but for code
OCaml ★ 0 5y agoExplain → -
care ⑂
Care is a single point to link Hospitals, Corona Care Centers and Volunteers to the unified Corona Safe Network so that the Kerala Chief Minister's Office has direct access to live reports of health data v/s our total. healthcare capacity
★ 0 6y agoExplain → -
pattern ⑂
Python implementation of pattern_create and pattern_offset from Metasploit Framework
Python ★ 0 11y agoExplain → -
woocommerce ⑂
An open source eCommerce plugin for WordPress.
PHP ★ 0 9y agoExplain → -
Markup.js ⑂
Powerful JavaScript templates
JavaScript ★ 0 9y agoExplain → -
gomo ⑂
Wiki pages about Android internals
★ 0 12y agoExplain → -
ysoserial ⑂
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
Java ★ 0 10y agoExplain → -
Clean-Blog ⑂
Clean Blog Theme for Bolt
JavaScript ★ 0 10y agoExplain → -
IGLogger ⑂
Class to help with adding logging function in smali output from 3rd party Android apps.
Smali ★ 0 13y agoExplain → -
async-requests ⑂
No description.
Python ★ 0 11y agoExplain → -
steelcon-python-injection ⑂
Python Process Injection PoC Code from my SteelCon talk in 2014
Python ★ 0 12y agoExplain → -
paws-on-es6 ⑂
Minimalist examples of ES6 functionalities.
JavaScript ★ 0 11y agoExplain → -
AndroidUnusedPermissions ⑂
Detect unused permissions in an Android application.
Python ★ 0 12y agoExplain → -
nitcbot ⑂
the code that powers @nitcbot
★ 0 12y agoExplain →
No repos match these filters.