Doyensec (doyensec)

Doyensec

doyensec

Organization data from Github https://github.com/doyensec

Doyensec works at the intersection of software development and offensive engineering. We discover vulnerabilities others cannot, and help mitigate the risk.

Location:San Francisco / Warsaw

Home Page:https://doyensec.com

GitHub:@doyensec

Doyensec's repositories

inql

InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.

Language:KotlinLicense:Apache-2.0Stargazers:1693Issues:25Issues:132

electronegativity

Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications.

Language:JavaScriptLicense:Apache-2.0Stargazers:1022Issues:24Issues:58

regexploit

Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

Language:PythonLicense:Apache-2.0Stargazers:838Issues:11Issues:16

awesome-electronjs-hacking

A curated list of awesome resources about Electron.js (in)security

wsrepl

WebSocket REPL for pentesters

Session-Hijacking-Visual-Exploitation

Session Hijacking Visual Exploitation

CSPTBurpExtension

CSPT is an open-source Burp Suite extension to find and exploit Client-Side Path Traversal.

Language:JavaLicense:Apache-2.0Stargazers:153Issues:5Issues:2

CSPTPlayground

CSPTPlayground is an open-source playground to find and exploit Client-Side Path Traversal (CSPT).

Language:JavaScriptLicense:Apache-2.0Stargazers:145Issues:3Issues:1

safeurl

A Server Side Request Forgery (SSRF) protection library. Made with 🖤 by Doyensec LLC.

Language:GoLicense:Apache-2.0Stargazers:107Issues:3Issues:3

PESD-Exporter-Extension

PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams

Language:JavaLicense:Apache-2.0Stargazers:106Issues:4Issues:6

GQLSpection

GQLSpection - parses GraphQL introspection schema and generates possible queries

Language:PythonLicense:Apache-2.0Stargazers:94Issues:2Issues:17

PoiEx

🌐 Visualize and explore IaC ✒️ Create and share notes in VS Code 🤝 Sync notes and findings in real-time with friends

Language:TypeScriptStargazers:73Issues:3Issues:0

Unsafe-Unpacking

Unsafe Unpacking Vulnerability: Lab Code, Semgrep Rules and Secure Implementation Guide

Language:HTMLStargazers:42Issues:2Issues:0

KSMBD-CVE-2025-37947

Blog Post: https://blog.doyensec.com/2025/10/08/ksmbd-3.html

Language:CStargazers:17Issues:0Issues:0

malicious-devfile-registry

Exploit for CVE-2024-0402 in Gitlab

Language:DockerfileStargazers:13Issues:0Issues:0

burp-rest-api

REST/JSON API to the Burp Suite security tool.

Language:JavaLicense:BSD-2-ClauseStargazers:11Issues:8Issues:0

SSHNuke_info

SSH Nuke Info

Language:CStargazers:11Issues:1Issues:0

db-race-conditions-playground

Database Race Condition Playground. Made with 🧡 by Doyensec LLC.

Language:JavaScriptStargazers:8Issues:1Issues:0

libajp13

AJPv1.3 Java Library

Language:JavaLicense:Apache-2.0Stargazers:4Issues:9Issues:0
Language:PythonLicense:MITStargazers:4Issues:0Issues:0

exploitable-IoT-solution

!Exploitable IoT Exploit

Language:CStargazers:3Issues:0Issues:0

csharp_rand_py

Optimized C# `Random` for security testing

Language:PythonStargazers:2Issues:0Issues:0

outline

The fastest knowledge base for growing teams. Beautiful, realtime collaborative, feature packed, and markdown compatible.

License:NOASSERTIONStargazers:1Issues:0Issues:0
Language:TclLicense:Apache-2.0Stargazers:0Issues:1Issues:0

tsunami-security-scanner

Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.

Language:JavaLicense:Apache-2.0Stargazers:0Issues:1Issues:0

tsunami-security-scanner-plugins

This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.

Language:JavaLicense:Apache-2.0Stargazers:0Issues:1Issues:0
Language:PythonStargazers:0Issues:0Issues:0
Language:GoLicense:Apache-2.0Stargazers:0Issues:0Issues:0

ruby-unsafe-deserialization

Proof of Concepts for unsafe deserialization in Ruby

Language:RubyLicense:MITStargazers:0Issues:0Issues:0