
jwt_tool
:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Lightweight Python utility for automated security auditing of GraphQL APIs. Detects misconfigurations, information leaks, and denial-of-service…

A New Microsoft Windows Remote Administrator Tool [RAT] with Python by Sir.4m1R.

Lightweight Python library for obfuscating JWT payload values using XOR encryption with timestamp-based keys, preventing plaintext decoding of…

Minimal Python PoC for CVE-2026-40179: injects a malicious metric name via unauthenticated Prometheus remote_write to trigger stored XSS in the web…

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Proof-of-concept exploit for CVE-2026-11103 demonstrating GraphQL rate-limit bypass through batching and field aliases; includes vulnerable Node.js…

Clone of suds 0.4 + suds-0.4-CVE-2013-2217.patch

HMAC Implementation Example and Explanation

Automatic SQL injection and database takeover tool


List of regex for scraping secret API keys and juicy information.

Vimana is a modular security framework for auditing Python APIs and Web applications. The plugin-based architecture enables security professionals to…

ArmourBird CSF - Container Security Framework

Reverse engineering of the oBike protocol communication (BLE and HTTP)

HTTP proxy bridge for security testing of remote MCP servers, allowing standard HTTP tools to send JSON-RPC messages and manage sessions.

PoC for CVE-2026-18953 — arbitrary file write (CWE-22) in awslabs.aws-transform-mcp-server's get_resource tool via the savePath parameter

Proof-of-concept exploit for CVE-2026-30945, an IDOR in StudioCMS allowing arbitrary API token revocation and denial of service. Includes manual and…