
auth_analyzer
Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

Burp Extension for testing authorization issues. Automated request repeating and parameter value extraction on the fly.

GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations

Burp Suite Extension useful to verify OAUTHv2 and OpenID security

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

PoC for CVE-2025-59528 used to achieve remote code execution on the Silentium machine at HTB

GitHub Action for Offensive360 SAST scans and SARIF results. See the open-source program for eligibility and setup.

YAMCS yamcs-core < 5.12.7 lacks rate limiting on POST /auth/token. An unauthenticated attacker can perform unlimited brute-force attempts against any…

Reproduction of a high severty security problem that allows XXE (XML eXternal Entity) attacks on Ktor's XML serialization.

PoC for CVE-2025-29556 creating Security Officer accounts on ExaGrid EX10 backup appliances via a low-privilege API session, enabling privilege…

MCP-Inspector-vulncheck is a Python script that checks if an MCP Inspector server is vulnerable to CVE-2025-49596. It tests whether the /sse endpoint…

Deliberately vulnerable C# API application for practicing web application exploitation and security testing. Includes Docker setup and documentation…

Hackable HTTP proxy for resiliency testing and simulated network conditions

Vulnerable REST API with OWASP top 10 vulnerabilities for security testing

Use Cloudflare to create HTTP pass-through proxies for unique IP rotation, similar to fireprox

Damn Vulnerable C# Application (API)

Vulnerability Assessment Scanner with Report Generation

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

Python script to bypass Azure APIM signup when UI is disabled, this is different from the CVE-2025-66390 as it does not require you to setup anything…