
RedWarden
Cobalt Strike C2 Reverse proxy that fends off Blue Teams, AVs, EDRs, scanners through packet inspection and malleable profile correlation
Tools for testing, exploiting, and securing web applications and APIs.


Proof of concept for CVE-2021-31166, a remote HTTP.sys use-after-free triggered remotely.

Nginxpwner is a simple tool to look for common Nginx misconfigurations and vulnerabilities.

Automated Tool That Generates The Perfect Meterpreter Powershell Payload

🖇 Enumerate git repository URL from list of URL / User / Org. Friendly to pipeline

A python tool to check subdomain takeover vulnerability

automated web assets enumeration & scanning [DEPRECATED]

A Chrome extension that demonstrates bypassing Widevine L3 DRM

A tool to check a bunch of URLs that contain reflecting params.

A fast DOM based XSS vulnerability scanner with simplicity.

Multi Tool Subdomain Enumeration

This experimetal fuzzer is meant to be used for API in-memory fuzzing.

A friend of SQLmap which will do what you always expected from SQLmap.

A browser extension that encrypts your communications with many websites that offer HTTPS but still allow unencrypted connections.

Pentest Tools Framework is a database of exploits, Scanners and tools for penetration testing. Pentest is a powerful framework includes a lot of…

[POC] Asynchronous reverse shell using the HTTP protocol.