
XSRFProbe
The Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.
Tools for testing, exploiting, and securing web applications and APIs.

The Prime Cross Site Request Forgery (CSRF) Audit and Exploitation Toolkit.

A Chrome extension that demonstrates bypassing Widevine L3 DRM


A fast tool to fetch URLs from HTML attributes by crawl-in.


用于借助FOFA快速测试海康威视的CVE-2017-7921漏洞,并且给出登陆账号和密码,并输出json文件。

Shannon is an autonomous, white-box AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes…

Automated mobile application security testing framework for Android, iOS, and Windows. Performs static and dynamic analysis, malware detection, and…

Automates OSINT data collection and analysis for threat intelligence, attack surface mapping, and reconnaissance. Integrates 200+ modules for DNS,…

Open-source web application security scanner for automated vulnerability detection, manual penetration testing, and API security testing with a…

A collection of hacking tools, resources and references to practice ethical hacking.

Automated penetration testing & attack surface management platform. Recon, scan, exploit, report — 600+ exploits, 90+ integrations, 10K+ detections.

A Domain-Fronting Relay that routes traffic though GAS (Google Apps Script) and forwards it to Cloudflare Workers. Designed to bypass DPI.

NAT Slipstreaming allows an attacker to remotely access any TCP/UDP services bound to a victim machine, bypassing the victim’s NAT/firewall, just by…

Hunt every Endpoint in your code, expose Shadow APIs, map the Attack Surface.

80k+ WordPress Nuclei templates, updated daily from Wordfence intel—filter by severity/tags/CVE and scan in one line. 🚀🔒

Automates HTTP 403 access control bypass techniques using header manipulation, path obfuscation, and HTTP method conversion for web application…

WPScan rewritten in Python + some WPSeku ideas