Doyensec's repositories
electronegativity
Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications.
regexploit
Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)
awesome-electronjs-hacking
A curated list of awesome resources about Electron.js (in)security
Session-Hijacking-Visual-Exploitation
Session Hijacking Visual Exploitation
CSPTBurpExtension
CSPT is an open-source Burp Suite extension to find and exploit Client-Side Path Traversal.
CSPTPlayground
CSPTPlayground is an open-source playground to find and exploit Client-Side Path Traversal (CSPT).
PESD-Exporter-Extension
PESD (Proxy Enriched Sequence Diagrams) Exporter converts Burp Suite's proxy traffic into interactive diagrams
GQLSpection
GQLSpection - parses GraphQL introspection schema and generates possible queries
Unsafe-Unpacking
Unsafe Unpacking Vulnerability: Lab Code, Semgrep Rules and Secure Implementation Guide
KSMBD-CVE-2025-37947
Blog Post: https://blog.doyensec.com/2025/10/08/ksmbd-3.html
malicious-devfile-registry
Exploit for CVE-2024-0402 in Gitlab
burp-rest-api
REST/JSON API to the Burp Suite security tool.
SSHNuke_info
SSH Nuke Info
db-race-conditions-playground
Database Race Condition Playground. Made with 🧡 by Doyensec LLC.
exploitable-IoT-solution
!Exploitable IoT Exploit
csharp_rand_py
Optimized C# `Random` for security testing
tsunami-security-scanner
Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.
tsunami-security-scanner-plugins
This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.
ruby-unsafe-deserialization
Proof of Concepts for unsafe deserialization in Ruby