
discover
Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Custom Bash and Python scripts used to automate various penetration testing tasks including recon, scanning, enumeration, and malicious payload…

Go client to communicate with Chaos DB API.

Collaborative application security testing between humans and agents via CLI and MCP

A coverage-guided REST API fuzzer developed on top of LibAFL

PoC for CVE-2026-44848: Portainer missing authorization on Docker plugin endpoints -> host RCE (GHSA-rrmm-9v76-h3p4). Stdlib-only Python.

Proof-of-concept exploit for CVE-2026-11103 demonstrating GraphQL rate-limit bypass through batching and field aliases; includes vulnerable Node.js…

Automated authorization testing tool that detects unauthorized access by scanning URLs with role-based credentials using YAML templates.

A lightweight Python-based security assessment tool for detecting dangerous Cross-Origin Resource Sharing (CORS) misconfigurations - CVE-2025-34291.

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application…

Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…

MAPS cloud scanner and response parser for Microsoft Defender research.

CyberArk Security Audit

A headless , scriptable, command-line based MITM proxy designed for network traffic interception, analysis, and modification on Windows systems.

A web-based vulnerability scanner for CVE-2025-55182, a critical Remote Code Execution (RCE) vulnerability in React Server Components.

g-FFL Cockpit <= 1.7.1 - Improper Authorization to Unauthenticated Product Deletion

This script exploits the CVE-2024-40094 vulnerability in graphql-java

Exploit for CVE-2021-30180 targeting Apache Dubbo RPC framework, enabling remote code execution via crafted RPC requests in vulnerable versions.