awesome-repositories.com
المدونة
MCP
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعخادم MCPحولكيفية ترتيب النتائجالصحافة
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

27 مستودعات

Awesome GitHub RepositoriesAttack Payloads

Collections of malicious strings and vectors for web application testing.

Explore 27 awesome GitHub repositories matching part of an awesome list · Attack Payloads. Refine with filters or upvote what's useful.

Awesome Attack Payloads GitHub Repositories

اعثر على أفضل المستودعات باستخدام الذكاء الاصطناعي.سنبحث عن أفضل المستودعات المطابقة باستخدام الذكاء الاصطناعي.
  • swisskyrepo/payloadsallthethingsالصورة الرمزية لـ swisskyrepo

    swisskyrepo/PayloadsAllTheThings

    78,434عرض على GitHub↗

    This project is a comprehensive, community-sourced knowledge base designed for security professionals and researchers. It functions as a centralized repository of offensive security techniques, providing a structured collection of exploit payloads, attack vectors, and methodologies for conducting vulnerability assessments and penetration testing. The repository distinguishes itself through a cross-platform payload taxonomy that categorizes exploitation methods by vulnerability type and target environment, enabling rapid lookup during security assessments. It maintains high standards of data i

    Curated repository of payloads for various web security vulnerabilities.

    Pythonbountybugbountybypass
    عرض على GitHub↗78,434
  • danielmiessler/seclistsالصورة الرمزية لـ danielmiessler

    danielmiessler/SecLists

    71,596عرض على GitHub↗

    SecLists is a centralized library of security assessment data designed to support vulnerability discovery and penetration testing. It functions as a comprehensive repository of wordlists, payloads, and testing methodologies used to audit software, firmware, and internet-connected hardware for technical vulnerabilities. The project distinguishes itself through a standardized taxonomy and a language-agnostic data format, which allows security tools to predictably ingest and utilize its assets regardless of the underlying programming environment. By decoupling raw testing data from execution log

    Extensive collection of wordlists for security assessment and penetration testing.

    PHP
    عرض على GitHub↗71,596
  • minimaxir/big-list-of-naughty-stringsالصورة الرمزية لـ minimaxir

    minimaxir/big-list-of-naughty-strings

    47,686عرض على GitHub↗

    This project is a standardized repository of malicious and malformed character sequences designed to stress-test data parsing and sanitization routines. It serves as a security testing corpus and a language-neutral reference for auditing software robustness against injection flaws and unexpected data handling errors across diverse platforms. The dataset functions as a benchmark for input validation, providing a curated collection of edge-case strings that allow developers to identify potential crashes and security vulnerabilities. By decoupling these test vectors from application logic, the r

    Collection of edge-case strings that cause unexpected application behavior.

    Python
    عرض على GitHub↗47,686
  • fuzzdb-project/fuzzdbالصورة الرمزية لـ fuzzdb-project

    fuzzdb-project/fuzzdb

    8,819عرض على GitHub↗

    fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a fuzzing payload dictionary, a resource discovery wordlist, and a fault injection dataset containing corrupted Unicode, null bytes, and escape codes to trigger application crashes and logic errors. The project includes a security filter bypass list featuring polyglots and encoded strings to evade web application firewalls and input validation filters. It also provides a comprehensive web application penetration testing dataset specifically for identifying flaws such as cross-s

    Comprehensive database of attack patterns for fuzzing web applications.

    PHP
    عرض على GitHub↗8,819
  • xmendez/wfuzzالصورة الرمزية لـ xmendez

    xmendez/wfuzz

    6,519عرض على GitHub↗

    Wfuzz is a web application fuzzing framework that automates the injection of payloads into HTTP requests to discover hidden resources, parameters, and vulnerabilities. It functions as a content discovery scanner, a brute-force tool for credential guessing, and a plugin-based vulnerability scanner, all within a single modular system. The tool distinguishes itself through its plugin-based extensibility, allowing custom Python modules to add new payload sources, output printers, or scanning logic without modifying core code. It supports concurrent request dispatch using thread-based parallelism

    Tool and payload collection for web application brute-forcing and fuzzing.

    Python
    عرض على GitHub↗6,519
  • therook/subbruteالصورة الرمزية لـ TheRook

    TheRook/subbrute

    3,515عرض على GitHub↗

    A DNS meta-query spider that enumerates DNS records, and subdomains.

    DNS meta-query tool for subdomain enumeration and discovery.

    Python
    عرض على GitHub↗3,515
  • terjanq/tiny-xss-payloadsالصورة الرمزية لـ terjanq

    terjanq/Tiny-XSS-Payloads

    2,370عرض على GitHub↗

    A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me

    Minimalist cross-site scripting payloads for bypass testing.

    JavaScriptbugbountyctfhtml
    عرض على GitHub↗2,370
  • 0xsobky/hackvaultالصورة الرمزية لـ 0xsobky

    0xsobky/HackVault

    2,025عرض على GitHub↗

    A container repository for my public web hacks!

    Repository containing various security research and attack payloads.

    JavaScript
    عرض على GitHub↗2,025
  • danielmiessler/robotsdisallowedالصورة الرمزية لـ danielmiessler

    danielmiessler/RobotsDisallowed

    1,485عرض على GitHub↗

    List of sensitive paths often found in robots.txt files.

    Shell
    عرض على GitHub↗1,485
  • wireghoul/dotdotpwnالصورة الرمزية لـ wireghoul

    wireghoul/dotdotpwn

    1,109عرض على GitHub↗

    DotDotPwn - The Directory Traversal Fuzzer

    Tool for testing directory traversal vulnerabilities.

    Perl
    عرض على GitHub↗1,109
  • cujanovic/open-redirect-payloadsالصورة الرمزية لـ cujanovic

    cujanovic/Open-Redirect-Payloads

    661عرض على GitHub↗

    Open Redirect Payloads

    Specific vectors for testing open redirect vulnerabilities.

    Shell
    عرض على GitHub↗661
  • cujanovic/content-bruteforcing-wordlistالصورة الرمزية لـ cujanovic

    cujanovic/content-bruteforcing-wordlist

    219عرض على GitHub↗

    Wordlist for content(directory) bruteforce discovering with Burp or dirsearch

    Wordlists for discovering hidden files and directories on web servers.

    Python
    عرض على GitHub↗219
  • 7iosecurity/xss-payloadsالصورة الرمزية لـ 7ioSecurity

    7ioSecurity/XSS-Payloads

    49عرض على GitHub↗

    XSS Payloads

    Focused collection of cross-site scripting attack vectors.

    عرض على GitHub↗49
  • ismailtasdelen/command-injection-payload-listI

    ismailtasdelen/command-injection-payload-list

    0عرض على GitHub↗

    Payloads for testing command injection on various operating systems.

    عرض على GitHub↗0
  • camoufl4g3/sqli-payload-fuzz3rC

    camoufl4g3/SQLi-payload-Fuzz3R

    0عرض على GitHub↗

    Payloads and tools for fuzzing SQL injection vulnerabilities.

    عرض على GitHub↗0
  • nicksanzotta/burpintruderN

    NickSanzotta/BurpIntruder

    0عرض على GitHub↗

    Payloads and configurations designed for use with Burp Suite Intruder.

    عرض على GitHub↗0
  • xsuperbug/payloadsX

    xsuperbug/payloads

    0عرض على GitHub↗

    Repository containing various web attack and injection payloads.

    عرض على GitHub↗0
  • hybrisdisaster/asphashdosH

    HybrisDisaster/aspHashDoS

    0عرض على GitHub↗

    Payloads specifically targeting ASP.NET hash collision vulnerabilities.

    عرض على GitHub↗0
  • firefart/hashcollision-dos-pocF

    FireFart/HashCollision-DOS-POC

    0عرض على GitHub↗

    Proof of concept for hash collision denial of service attacks.

    عرض على GitHub↗0
  • xsscx/commodity-injection-signaturesX

    xsscx/Commodity-Injection-Signatures

    0عرض على GitHub↗

    Signatures and payloads for testing common injection vulnerabilities.

    عرض على GitHub↗0
السابق12التالي
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Attack Payloads