Skip to content
@doyensec

Doyensec

Doyensec works at the intersection of software development and offensive engineering. We discover vulnerabilities others cannot, and help mitigate the risk.

Popular repositories Loading

  1. inql inql Public

    InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.

    Kotlin 1.8k 188

  2. electronegativity electronegativity Public

    Electronegativity is a tool to identify misconfigurations and security anti-patterns in Electron applications.

    JavaScript 1.1k 71

  3. regexploit regexploit Public

    Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)

    Python 851 58

  4. awesome-electronjs-hacking awesome-electronjs-hacking Public

    A curated list of awesome resources about Electron.js (in)security

    681 64

  5. burpdeveltraining burpdeveltraining Public

    Material for the training "Developing Burp Suite Extensions – From Manual Testing to Security Automation"

    Java 358 73

  6. wsrepl wsrepl Public

    WebSocket REPL for pentesters

    Python 238 15

Repositories

Showing 10 of 67 repositories
  • osv-scalibr Public Forked from google/osv-scalibr
    doyensec/osv-scalibr's past year of commit activity
    Go 0 Apache-2.0 201 0 2 Updated Sep 10, 2026
  • inql Public

    InQL is a robust, open-source Burp Suite extension for advanced GraphQL testing, offering intuitive vulnerability detection, customizable scans, and seamless Burp integration.

    doyensec/inql's past year of commit activity
    Kotlin 1,813 Apache-2.0 188 19 (4 issues need help) 10 Updated Sep 9, 2026
  • tsunami-security-scanner-plugins Public Forked from google/tsunami-security-scanner-plugins

    This project aims to provide a central repository for many useful Tsunami Security Scanner plugins.

    doyensec/tsunami-security-scanner-plugins's past year of commit activity
    Java 0 Apache-2.0 241 0 3 Updated Aug 27, 2026
  • doyensec/security-testbeds's past year of commit activity
    Tcl 0 Apache-2.0 54 0 1 Updated Aug 21, 2026
  • maSSO Public

    The malicious IdP you were looking for. A weaponized Single Sign-On (SSO) Identity Provider (IdP) for security testing of OIDC and SAML 2.0 Service Providers, also supporting SCIM protocol.

    doyensec/maSSO's past year of commit activity
    Go 65 Apache-2.0 6 7 0 Updated Jul 23, 2026
  • cloudsec-tidbits Public

    Blogpost series showcasing interesting cloud - web app security bugs

    doyensec/cloudsec-tidbits's past year of commit activity
    HCL 76 5 0 0 Updated Jul 20, 2026
  • protospector Public

    Protocol Buffers and gRPC services Burp Extension

    doyensec/protospector's past year of commit activity
    Java 2 Apache-2.0 0 7 0 Updated Jul 8, 2026
  • tsunami-security-scanner Public Forked from google/tsunami-security-scanner

    Tsunami is a general purpose network security scanner with an extensible plugin system for detecting high severity vulnerabilities with high confidence.

    doyensec/tsunami-security-scanner's past year of commit activity
    Java 0 Apache-2.0 954 0 0 Updated Jun 19, 2026
  • burp-session-switcher Public

    A Burp extension that easily allows for switching a request's session (headers, cookies) on the fly

    doyensec/burp-session-switcher's past year of commit activity
    Kotlin 33 Apache-2.0 0 0 0 Updated Jun 17, 2026
  • safeurl Public

    A Server Side Request Forgery (SSRF) protection library. Made with 🖤 by Doyensec LLC.

    doyensec/safeurl's past year of commit activity
    Go 116 Apache-2.0 13 1 0 Updated Jun 11, 2026