
Black-Tool
Install the tools and start Attacking , black-tool v5.5.5 ! ⬛
Tools for testing, exploiting, and securing web applications and APIs.

Install the tools and start Attacking , black-tool v5.5.5 ! ⬛

CrackerJack / Hashcat Web Interface / Context Information Security

A better version of my xssfinder tool - scans for different types of xss on a list of urls.

Crawlector is a threat hunting framework designed for scanning websites for malicious objects.

⚡️ Multiple target ZAP Scanning

A penetration testing tool for bypassing HTTP 401/403 responses using various header manipulation techniques and path fuzzing.

ZCBS/ZBBS/ZPBS v4.14k - Reflected XSS

110 offensive security one-liners for authorized testing and CTFs, organized in one markdown notebook by category and kill-chain step. Dual-use…

halo cms plugin 1-request rce from a url, PoC + exploit chain

Reproduces fastjson 1.2.83 @JSONType RCE with a vulnerable Spring Boot target and ASM-based payload generator using HTTP or file protocol jar chains.

Proof of Concept for CVE-2026-19598 affecting Pods <= 3.3.9.

This exploit scans whether the provided target is vulnerable to CVE-2023-49070/CVE-2023-51467 and also exploits it depending on the choice of the…

Public writeup, PoC, and emulation materials for CVE-2026-6837 affecting Zyxel export-cgi PKCS#12 export handling.

Agentic pentest profile for Hermes: 31 playbooks for authorised recon, web/access-control attacks, safe exploit validation, and evidence-driven…

A list of useful payloads and bypass for Web Application Security and Pentest/CTF

Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS

🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!

Curated collection of wordlists for security assessments, including usernames, passwords, URLs, fuzzing payloads, and sensitive data patterns for…