GitHunt

Paolo Perego

thesp0nge

Application security guy | OSCE | OSCP | πŸ’ | πŸ‘¨β€πŸ‘©β€πŸ‘§β€πŸ‘¦ | Security Engineer @ SUSE🦎 | Chaotic good Elistraee drow cleric | Content creator. @codiceinsicuro

@SUSE
Gessate, Milan, Italy

Organizations

Languages

Python43%Ruby26%C9%Java4%Shell4%JavaScript4%C++4%Lua4%

Loading contributions...

Top Repositories

Repositories

145
TH
thesp0nge/aj_cli

The Audit Journal - a tool to help you doing journaling with your security audit finest findings

Python00Updated 2 months ago
TH
thesp0nge/dr_source

DRSource is an extensible, multi-language static analysis tool designed to detect vulnerabilities in source code. It uses a pluggable architecture to combine multiple detection techniquesβ€”from simple regex matching to advanced AST-based taint analysisβ€”all driven by a central, user-configurable knowledge base.

Python173Updated 1 week ago
codereviewsastsecuritysecurity-analysissecurity-auditsecurity-tools
TH
thesp0nge/nightcrawler-mitm

A python program that crawls a website and tries to stress it, polluting forms with bogus data

Python261Updated 3 weeks ago
crawleroffensive-scriptsoffensive-securitystress-testweb-crawlerweb-crawling
TH
thesp0nge/thesp0nge

No description provided.

00Updated 1 month ago
TH
thesp0nge/mvp_semgrep

Semgrep MVP: Aggregate, Rank & Cluster Your Findings

Python10Updated 1 month ago
TH
thesp0nge/ama

Ask me anything

00Updated 6 years ago
amaask-me-anything
TH
thesp0nge/dawnscanner

Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.

Ruby74884Updated 2 years ago
codereviewcybersecurityhanamipadrinorailsrubysecuritysecurity-auditsinatravulnerabilities
TH
thesp0nge/owasp-orizonArchived

Owasp Orizon is a source code static analyzer tool designed to spot security issues in Java applications.

Java14635Updated 8 years ago
code-reviewj2eejavaowaspstatic-code-analysisvulnerability-scanners
TH
thesp0nge/casky

Your Lightweight C Key-Value Engine with Crash Recovery

C50Updated 3 months ago
TH
thesp0nge/recon.sh

This is the reconnaissance script I wrote for my OSCP journey

Shell149Updated 8 years ago
cyber-securityoffensive-securityoscppenetration-testingreconnaissance
TH
thesp0nge/enchant

Enchant is is tool aimed to discover web application directory and pages by fuzzing the requests using a dictionary approach.

Ruby2510Updated 10 years ago
TH
thesp0nge/pixeldb

A lightweight, embeddable vector similarity search library in C.

C00Updated 4 months ago
TH
thesp0nge/rune

Rune is a lightweight, rule-based static analysis security testing (SAST) tool designed to find security vulnerabilities in source code.

Python00Updated 5 months ago
TH
thesp0nge/tarpedo

Tarpedo is a security tool for offline NPM workflows. It scans local .tgz package archives, finds known vulnerabilities, and generates clear, aggregated reports. Perfect for securing air-gapped environments and managing your software supply chain by turning audit data into actionable intelligence.

00Updated 5 months ago
TH
thesp0nge/shellerate

A shellcode generator with encryption, encoding and polymorphism facilities built-in

Python348Updated 3 years ago
TH
thesp0nge/dotfiles

My dotfile config

Python00Updated 6 months ago
TH
thesp0nge/codiceinsicuro.github.io

A responsive Jekyll theme with clean typography and support for large full page images.

JavaScript10Updated 7 months ago
TH
thesp0nge/WispDB

No description provided.

00Updated 1 year ago
TH
thesp0nge/links

A swiss army knife to leverage your webapp attack surface

Ruby144Updated 12 years ago
TH
thesp0nge/ZeusFork

NOT MY CODE! Zeus trojan horse - leaked in 2011, I am not the author, I have created this repo to simplify access to those who want to study it.

C++00Updated 12 years ago
TH
thesp0nge/dawnscanner_knowledge_base

No description provided.

Python23Updated 2 years ago
TH
thesp0nge/owasp-esapi-ruby

The Owasp Esapi Ruby is a port for outstanding release quality Owasp Esapi project to the Ruby programming language. The idea is to build a Ruby gem (the standard ruby library archive format) containing the Esapi concepts implemented in Ruby classes so people using Ruby in their Rails application can have security into them.

Ruby4614Updated 14 years ago
TH
thesp0nge/omakubFork

Opinionated Ubuntu Setup

00Updated 1 year ago
TH
thesp0nge/uyuni-hardening-guide

No description provided.

30Updated 1 year ago
TH
thesp0nge/secboxFork

Secbox is a toolbox that provides an out-of-the-box working setup for your daily work in the SUSE Security Team.

00Updated 2 years ago
TH
thesp0nge/permissionsFork

No description provided.

Python00Updated 2 years ago
TH
thesp0nge/spot_the_vuln

No description provided.

Python20Updated 2 years ago
TH
thesp0nge/advent_of_code

No description provided.

Ruby00Updated 2 years ago
TH
thesp0nge/cvssArchived

cvss is a rubygem for parsing cvss vector and calculate cvss score given some parameter.

Ruby00Updated 12 years ago
TH
thesp0nge/config-nvim

My NeoVIM configuration

Lua00Updated 2 years ago

Gists

Recent Activity