
sast-scan-action
GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

MCP server that runs SAST scans on local codebases and returns findings with severity and fixes, enabling AI assistants to perform security analysis…

Proof-of-concept exploit for CVE-2026-68929, demonstrating unauthenticated cross-tenant takeover of FastGPT WeChat channels via public shareId,…

HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac :tada: Open an issue here…

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Proof-of-concept exploit for CVE-2026-11103 demonstrating GraphQL rate-limit bypass through batching and field aliases; includes vulnerable Node.js…

A coverage-guided REST API fuzzer developed on top of LibAFL

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…

A headless , scriptable, command-line based MITM proxy designed for network traffic interception, analysis, and modification on Windows systems.

Vulnerability Assessment Scanner with Report Generation

Zap Extension for collaboration in Faraday

Deliberately vulnerable C# API application for practicing web application exploitation and security testing. Includes Docker setup and documentation…

Damn Vulnerable C# Application (API)

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox