
f5-waf-quick-patch-cve-2021-44228
This tool creates a custom signature set on F5 WAF and apply to policies in blocking mode

This tool creates a custom signature set on F5 WAF and apply to policies in blocking mode

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

AWS API Gateway management tool for creating on the fly HTTP pass-through proxies for unique IP rotation

Advisory and benign PoC for OS command injection in an nmap MCP server, with duplicate CVE tracking, detection guidance, and mitigation.

Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North…

The universal GraphQL API and CSPM tool for AWS, Azure, GCP, K8s, and tencent.

Tool for finding URLs, paths, secrets and generating raw HTTP requests and OpenApi specifications from config files and annotations used in JAR / WAR…

Personal Access Token (PAT) recon tool for bug bounty hunters, pentesters & red teams

A security assessment tool for Hitachi Vantara's Pentaho Business Analytics platform.

Non-destructive detection and precondition-verification tool for CVE-2026-58231, probing SAP Commerce Cloud Data Hub endpoints, default OAuth…

A unified, security-first wire protocol for tool access and agent coordination. UAP eliminates CVE-2025-49596 and MCP tool-poisoning vulnerabilities…

Exploit tool for CVE-2026-1529, demonstrating unauthorized organization registration in Keycloak via JWT token manipulation. Includes token…

An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses

GraphQL server engine fingerprinting tool that sends benign and malformed queries to identify backend technology and assess security defenses via the…

Read-only Azure DevOps enumeration tool that queries the REST API to surface projects, repositories, service connections, builds, pipeline secrets,…

The Symfony PHP framework

Selfhosted alternative to 12ft.io. and 1ft.io. Proxy to remove CORS headers and modify HTML

Automagically reverse-engineer REST APIs via capturing traffic