
poc_salesforce_lightning
Academic purposes only. Attack against Salesforce lightning with guest privilege.

Academic purposes only. Attack against Salesforce lightning with guest privilege.

jsluice++ is a Burp Suite extension designed for passive and active scanning of JavaScript traffic using the CLI tool jsluice

FlowAnalyzer is a tool to help in testing and analyzing OAuth 2.0 Flows, including OpenID Connect (OIDC).

Rust-powered HTTP Request Smuggling Scanner.


AI-driven pentest harness with black-box, white-box, grey-box, host/cloud, and LLM red-team modes; validates findings with cross-model voting and…

Simple JMX RMI scanning tool

A fast WordPress plugin enumeration tool

OAuth Request Crafter

Refactored & improved CredKing password spraying tool, uses FireProx APIs to rotate IP addresses, stay anonymous, and beat throttling

Open-source AI penetration testing tool to find and fix your app’s vulnerabilities.

A PoC exploit for CVE-2021-4191 - GitLab User Enumeration.

A powerful directory brute-force tool that's tailored for recursive/multiplex operations, API discovery and enumeration, JS file scraping, and lists…

An API hooking framework for intercepting and monitoring Windows applications

HTTP Proxy Analysis for reverse engineering protocol communication

Burp Suite extension for API security testing with 15 attack types, 108+ payloads, intelligent fuzzing, BOLA/IDOR detection, AI integration, and…

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…