Skip to content
@doyensec

Doyensec

Doyensec works at the intersection of software development and offensive engineering. We discover vulnerabilities others cannot, and help mitigate the risk.

Popular repositories Loading

  1. inql inql Public

    InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.

    Kotlin 1.6k 164

  2. electronegativity electronegativity Public

    Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications.

    JavaScript 989 68

  3. regexploit regexploit Public

    Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

    Python 806 57

  4. awesome-electronjs-hacking awesome-electronjs-hacking Public

    A curated list of awesome resources about Electron.js (in)security

    615 63

  5. burpdeveltraining burpdeveltraining Public

    Material for the training "Developing Burp Suite Extensions – From Manual Testing to Security Automation"

    Java 350 70

  6. wsrepl wsrepl Public

    WebSocket REPL for pentesters

    Python 218 15

Repositories

Showing 10 of 57 repositories
  • CSPTPlayground Public

    CSPTPlayground is an open-source playground to find and exploit Client-Side Path Traversal (CSPT).

    doyensec/CSPTPlayground’s past year of commit activity
    JavaScript 111 Apache-2.0 11 0 0 Updated Mar 31, 2025
  • osv-scalibr Public Forked from google/osv-scalibr
    doyensec/osv-scalibr’s past year of commit activity
    Go 0 Apache-2.0 36 0 1 Updated Mar 31, 2025
  • inql Public

    InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.

    doyensec/inql’s past year of commit activity
    Kotlin 1,604 Apache-2.0 164 23 (5 issues need help) 8 Updated Mar 18, 2025
  • malicious-devfile-registry Public

    Exploit for CVE-2024-0402 in Gitlab

    doyensec/malicious-devfile-registry’s past year of commit activity
    Dockerfile 12 5 0 0 Updated Mar 18, 2025
  • GQLSpection Public

    GQLSpection - parses GraphQL introspection schema and generates possible queries

    doyensec/GQLSpection’s past year of commit activity
    Python 81 Apache-2.0 11 10 (2 issues need help) 2 Updated Mar 6, 2025
  • SSHNuke_info Public

    SSH Nuke Info

    doyensec/SSHNuke_info’s past year of commit activity
    C 4 0 0 0 Updated Mar 4, 2025
  • doyensec/ComfyUI-tsunami-payload’s past year of commit activity
    Python 0 0 0 0 Updated Mar 3, 2025
  • awesome-electronjs-hacking Public

    A curated list of awesome resources about Electron.js (in)security

    doyensec/awesome-electronjs-hacking’s past year of commit activity
    615 63 0 0 Updated Mar 1, 2025
  • tsunami-security-scanner-plugins Public Forked from google/tsunami-security-scanner-plugins

    This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.

    doyensec/tsunami-security-scanner-plugins’s past year of commit activity
    Java 0 Apache-2.0 209 0 0 Updated Feb 28, 2025
  • doyensec/security-testbeds’s past year of commit activity
    Python 0 Apache-2.0 36 0 1 Updated Feb 28, 2025