
Crawlector
Crawlector is a threat hunting framework designed for scanning websites for malicious objects.
Tools for identifying, assessing, and prioritizing security weaknesses in systems and applications.

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

⚡️ Multiple target ZAP Scanning

Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data.

Linux, macOS and Windows Install scripts for cnquery & cnspec

CVE-2026-20637: AppleSEPKeyStore Use-After-Free — iOS/macOS kernel vulnerability (patched in 26.4)

provides a Firewall Manager API designed to centralize and streamline the management of firewall configurations

A penetration testing tool for bypassing HTTP 401/403 responses using various header manipulation techniques and path fuzzing.

ZCBS/ZBBS/ZPBS v4.14k - Reflected XSS

MongoBleed (CVE-2025-14847) Lab & PoC : A complete educational environment to reproduce the critical unauthenticated memory leak in MongoDB. Includes…

Proof-of-concept exploit code for CVE-2026-54121, adapted and edited for validating the vulnerability in affected environments.

Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.

This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the…

Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

Linux kernel source tree

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Ghidra is a software reverse engineering (SRE) framework