
Azure-APIM-Dev-Portal-Signup-Bypass
Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…



Simple JMX RMI scanning tool

find sensitive data leaking from ServiceNow instances.

Burp Extension for collaboration in Faraday



Reproducer for CVE-2026-46592: Apache Camel camel-cxf operationName header injection redirecting the invoked SOAP operation (confused deputy) from a…

The collaborative web app pentest suite


Model Context Protocol server for Firefox DevTools - enables AI assistants to inspect and control Firefox browser through the Remote Debugging…

A Test API for testing the POC against CVE-2022-1388

一个轻量级浏览器抓包与安全分析扩展,在浏览器侧边栏中即可完成抓包、拦截、修改、重放、规则检测与AI辅助分析的完整工作流。(A lightweight browser extension for traffic capture and security analysis, enabling…

Advanced recon engine that finds real secrets, validates them live, and builds exploit paths from client-side intelligence.

Capture HTTP/HTTPS traffic from Android apps and send to Proxyman for debugging.

Burp Commander written in Go

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing