All 42 repositories
Offensive tooling
| Repository | What it does | |
|---|---|---|
| 12β | endpointhunter | Bug-bounty endpoint discovery |
| 12β | villain | Undetectable payload/shell generator |
| 10β | CredStalker- | Automated credential hunting |
| 9β | vulnx | Auto vulnerability finder + shell injector |
| 6β | Fucker | Web application vulnerability scanner |
| 3β | WPGhost | WordPress scanner/exploiter |
| 2β | ALL_IN_ONE | Multi-tool launcher |
| 2β | EmailSpoofer | SMTP spoofing |
| 1β | SQLZ | SQL injection toolkit |
| 1β | HashDog | Hash cracking |
| 1β | DIONAEA_FTP_SCANNER | Honeypot FTP testing |
| 1β | God_Scanner | Scanner |
| 0β | ZimPwn | LFI/RFI scanner |
| 0β | JWT-MODIFY | JWT payload tampering |
| 0β | sessionexploit | Cookie/session decoding |
| 0β | XSStriker | XSS testing |
| 0β | CVE-2025-55182 | PoC for the RCE/command-injection CVE |
| 0β | Admin-Finder | Admin panel discovery (Perl) |
| 0β | ZForce | Social-media brute force |
| 0β | wifi_hacker | Wi-Fi auditing (Windows) |
Utilities & platform
| Repository | What it does | |
|---|---|---|
| 2β | MobiToolKit | Android device tooling |
| 2β | Keylogger | C++ keylogger |
| 2β | ufonet | DoS tooling |
| 1β | ZimMux | One-file tmux theme |
| 1β | ZIMTHEGOAT | HyDE desktop theme |
| 0β | git-dumper | Fast .git dumper (Go) |
| 0β | Jarvis_Zim | Text-to-speech assistant |
| 0β | DigitalSparkUsbController | USB Rubber Ducky scripts |
| 0β | PageKite | Reverse proxy for exposing local servers |
Write-ups & coursework
| Repository | Topic |
|---|---|
| 0x41haz-writeup | Reverse-engineering walkthrough |
| XXE-INJECTION | XXE walkthrough (BugForge) |
| phantom-fob-tryhackme | TryHackMe room walkthrough |
| justavpnlogin | TryHackMe room walkthrough |
| cybersecurity_course | Beginner security course |
| course_manual | Course material |
Web & misc
| Repository | What it is |
|---|---|
| ZimShell | Portfolio site |
| portfolio | Portfolio site |
| DarkWeb | HTML/CSS/JS demo page |
| CALCULATOR | Python calculator |
| Ransomware | Ransomware simulation |
| DDos_Zim | DoS tooling |
| FB-Hack | Facebook tooling |
Repos with a zero star count are still listed β the count is a popularity signal, not a quality one, and this list is meant to be complete.
Languages are counted by repository, not by bytes. Byte counts are misleading here: one vendored 15 MB JavaScript tool outweighs every line of Python in the account, which would put JavaScript first. Counting repos answers the more useful question β what does this person actually build?
Open to everyone β questions, collaborations, or just talking shop.
Spamming is not Hacking lil bro [He he]
"Every system has a weakness.
You just have to find it."
How this page works. Every figure above is computed from the live GitHub API and committed daily by a scheduled Action β nothing here is hand-typed, so it cannot drift out of date. The assets are generated by the Python in scripts/. They are self-hosted rather than embedded from third-party badge services, which is why they keep working when those services go down.