A list of useful payloads and bypass for Web Application Security and Pentest/CTF
-
Updated
Aug 27, 2026 - Python
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
The all-in-one browser extension for offensive security professionals 🛠
All about bug bounty (bypasses, payloads, and etc)
The Official USB Rubber Ducky Payload Repository
Git All the Payloads! A collection of web attack payloads.
A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.
Active Directory and Internal Pentest Cheatsheets
A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me
Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.
A proxy aware C2 framework used to aid red teamers with post-exploitation and lateral movement.
Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。
A container repository for my public web hacks!
BurpCrypto is a collection of burpsuite encryption plug-ins, support AES/RSA/DES/ExecJs(execute JS encryption code in burpsuite). 支持多种加密算法或直接执行JS代码的用于爆破前端加密的BurpSuite插件
Undetectable Windows Payload Generation
Chimera is a PowerShell obfuscation script designed to bypass AMSI and commercial antivirus solutions.
Image Payload Creating/Injecting tools
AppSec Payloads Arsenal for Pentration Tester and Bug Bounty Hunters
To associate your repository with the payloads topic, visit your repo's landing page and select "manage topics."