
apex
AI-powered offensive security testing using autonomous agents, directly in your terminal.
Tools for testing, exploiting, and securing web applications and APIs.

AI-powered offensive security testing using autonomous agents, directly in your terminal.

Open Source Link Analysis & OSINT Framework

JumpServer 堡垒机未授权综合漏洞利用, Exploit for CVE-2023-42442 / CVE-2023-42820 / RCE 2021

A modern web browser for Classic Mac OS 9 PowerPC. Real CSS3, ES5 JavaScript, native HTTPS. Built with CodeWarrior on the Carbon API.

Bypass 4xx HTTP response status codes and more. The tool is based on Python Requests, PycURL, and HTTP Client.

Static analysis security rules for vulnerability detection and audit-focused code review across Java, Go, Python, C#, Kotlin, PHP, Kubernetes, and…

peeko – Browser-based XSS C2 for stealthy internal network exploration via infected browser.

A compact guide to network pivoting for penetration testings / CTF challenges.

SQLi scanner to detect SQL vulns

CVE-2025-30208-EXP

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

AI-native code security auditor on AgentField that proves exploitability with verdicts, traces, and actionable evidence.

Wavestone's web interface for password cracking with hashcat


The IoT Security Testing Guide (ISTG) provides a comprehensive methodology for penetration tests in the IoT field, offering flexibility to adapt…

Tool to identify if a domain is a CMS such as Wordpress, Moodle, Joomla, Drupal or Prestashop
