#1General purpose tools for collecting various types of information about targets.
Kitploit recommended

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.
wxpath - declarative web crawling with XPath; a Web Query Language (WQL)

PowerShell script that enumerates running processes, loaded DLLs, services, registry, and drivers to detect the presence of AV, EDR, and logging…

📡🔍Searches for wifi-pineapple traces and calculate wireless network security score 🍍

Azure mindmap for penetration tests

Academic purposes only. Attack against Salesforce lightning with guest privilege.

CVE-2025-30208-EXP

Exploit for Pulse Connect Secure SSL VPN arbitrary file read vulnerability (CVE-2019-11510)

Web-based OSINT framework for social media intelligence gathering, including Twitter and Instagram analysis, account discovery, and metadata…

bash script to facilitate some aspects of an Android application assessment

:broken_heart: Hearbleed exploit to retrieve sensitive information CVE-2014-0160 :broken_heart:

A personal RAG system for offensive security knowledge

Automated OSINT framework for ethical hacking audits. Collects employee emails, password hashes, subdomains, and IPs via BreachDirectory and…

Powerful mutable web directory fuzzer to bruteforce existing and/or hidden files or directories.

🔍NVD exploit & JVN(Japan Vulnerability Notes) easy description

Bash-based DNS enumeration tool performing forward/reverse bruteforce, cache snooping, and zone transfer to extract DNS records and subdomains.

Full duplex 433 MHz Signal jammer, recorder, decoder and hacking multitool device based on ESP32 microcontroller and RFM69HW radios. This version of…

Recon is a script to perform a full recon on a target with the main tools to search for vulnerabilities. Created based on @ofjaaah and @Jhaddix…