HTTP/2 200
date: Tue, 30 Dec 2025 09:22:36 GMT
content-type: text/html; charset=utf-8
vary: X-PJAX, X-PJAX-Container, Turbo-Visit, Turbo-Frame, X-Requested-With,Accept-Encoding, Accept, X-Requested-With
etag: W/"3a44889865a90b345adb31246f8d2b91"
cache-control: max-age=0, private, must-revalidate
strict-transport-security: max-age=31536000; includeSubdomains; preload
x-frame-options: deny
x-content-type-options: nosniff
x-xss-protection: 0
referrer-policy: origin-when-cross-origin, strict-origin-when-cross-origin
content-security-policy: default-src 'none'; base-uri 'self'; child-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/; connect-src 'self' uploads.github.com www.githubstatus.com collector.github.com raw.githubusercontent.com api.github.com github-cloud.s3.amazonaws.com github-production-repository-file-5c1aeb.s3.amazonaws.com github-production-upload-manifest-file-7fdce7.s3.amazonaws.com github-production-user-asset-6210df.s3.amazonaws.com *.rel.tunnels.api.visualstudio.com wss://*.rel.tunnels.api.visualstudio.com github.githubassets.com objects-origin.githubusercontent.com copilot-proxy.githubusercontent.com proxy.individual.githubcopilot.com proxy.business.githubcopilot.com proxy.enterprise.githubcopilot.com *.actions.githubusercontent.com wss://*.actions.githubusercontent.com productionresultssa0.blob.core.windows.net/ productionresultssa1.blob.core.windows.net/ productionresultssa2.blob.core.windows.net/ productionresultssa3.blob.core.windows.net/ productionresultssa4.blob.core.windows.net/ productionresultssa5.blob.core.windows.net/ productionresultssa6.blob.core.windows.net/ productionresultssa7.blob.core.windows.net/ productionresultssa8.blob.core.windows.net/ productionresultssa9.blob.core.windows.net/ productionresultssa10.blob.core.windows.net/ productionresultssa11.blob.core.windows.net/ productionresultssa12.blob.core.windows.net/ productionresultssa13.blob.core.windows.net/ productionresultssa14.blob.core.windows.net/ productionresultssa15.blob.core.windows.net/ productionresultssa16.blob.core.windows.net/ productionresultssa17.blob.core.windows.net/ productionresultssa18.blob.core.windows.net/ productionresultssa19.blob.core.windows.net/ github-production-repository-image-32fea6.s3.amazonaws.com github-production-release-asset-2e65be.s3.amazonaws.com insights.github.com wss://alive.github.com wss://alive-staging.github.com api.githubcopilot.com api.individual.githubcopilot.com api.business.githubcopilot.com api.enterprise.githubcopilot.com; font-src github.githubassets.com; form-action 'self' github.com gist.github.com copilot-workspace.githubnext.com objects-origin.githubusercontent.com; frame-ancestors 'none'; frame-src viewscreen.githubusercontent.com notebooks.githubusercontent.com; img-src 'self' data: blob: github.githubassets.com media.githubusercontent.com camo.githubusercontent.com identicons.github.com avatars.githubusercontent.com private-avatars.githubusercontent.com github-cloud.s3.amazonaws.com objects.githubusercontent.com release-assets.githubusercontent.com secured-user-images.githubusercontent.com/ user-images.githubusercontent.com/ private-user-images.githubusercontent.com opengraph.githubassets.com marketplace-screenshots.githubusercontent.com/ copilotprodattachments.blob.core.windows.net/github-production-copilot-attachments/ github-production-user-asset-6210df.s3.amazonaws.com customer-stories-feed.github.com spotlights-feed.github.com objects-origin.githubusercontent.com *.githubusercontent.com; manifest-src 'self'; media-src github.com user-images.githubusercontent.com/ secured-user-images.githubusercontent.com/ private-user-images.githubusercontent.com github-production-user-asset-6210df.s3.amazonaws.com gist.github.com github.githubassets.com; script-src github.githubassets.com; style-src 'unsafe-inline' github.githubassets.com; upgrade-insecure-requests; worker-src github.githubassets.com github.com/assets-cdn/worker/ github.com/assets/ gist.github.com/assets-cdn/worker/
server: github.com
content-encoding: gzip
accept-ranges: bytes
set-cookie: _gh_sess=LZnz%2FJA%2FdB2KSke0HSKQOFhnyVEJPpt6j%2FWkT1MgiCZcBWxy1gHL3LWMWgM8hvVoLLJD7EsB0LwWKHU90gzbz%2FKB0jLBxE%2B5wzToL7otFbWdceGasW1Rc315VTDoKYeiDjud8%2FD2oC%2FsDccsyotXsl%2FicPU8E6Fz8wXsBTkxAv9XaAQEQJA5jIjRkB6XpJIekT7bq0q33bH3WVIpIXOoqsCYHL2YPbMObTBVd1LthqQ9L5JHXaVuEVBAAX42wQQ17QE3SiDhfjR3arpELnNt3A%3D%3D--Vh108ktm%2FpegB4hF--wN2JqkulVmgkCMyD8Wb7QA%3D%3D; Path=/; HttpOnly; Secure; SameSite=Lax
set-cookie: _octo=GH1.1.511900746.1767086555; Path=/; Domain=github.com; Expires=Wed, 30 Dec 2026 09:22:35 GMT; Secure; SameSite=Lax
set-cookie: logged_in=no; Path=/; Domain=github.com; Expires=Wed, 30 Dec 2026 09:22:35 GMT; HttpOnly; Secure; SameSite=Lax
x-github-request-id: B134:1B271A:5E071C:66F53F:695399DB
Sponsor @vysecurity on GitHub Sponsors · GitHub
You must be logged in to sponsor vysecurity
Authored and maintain Red Team Tips
Develop and share generation frameworks
Share research
1 sponsor
has funded
vysecurity’s work.
@vysecurity's goal is to
have 10 monthly sponsors
Release new tool :)
Featured work
vysecurity/DomLink
A tool to link a domain with registered organisation names and emails, to other domains.
0%
towards
10 monthly sponsors
goal
Be the first to sponsor this goal!
Support Red Team Tips and maintenance.
Support Red Team Tips and maintenance.
Subscribe to mailing list to get regular updates on interesting attack techniques.
Support Red Team Tips and maintenance.
Subscribe to mailing list to get regular updates on interesting attack techniques.
Q&A for any adhoc advice for security testing.
Support Red Team Tips and maintenance.
Subscribe to mailing list to get regular updates on interesting attack techniques.
Q&A for any adhoc advice for security testing.
Obtain access to pre-release code repositories for early access.
You can’t perform that action at this time.