
x8-Burp
Hidden parameters discovery suite

Hidden parameters discovery suite

Multi-threaded scanner for detecting exposed Swagger/OpenAPI endpoints across web domains and subdomains, with automatic XSS detection, PoC…

Automated CORS misconfiguration scanner that tests Origin header injection, wildcard reflection, and credential leakage across web applications and…

Validates Google Maps API keys against 21 endpoints, revealing exposed services with PoC URLs, proxy support, and quiet mode for focused auditing.

MAPS cloud scanner and response parser for Microsoft Defender research.

Moxy is an open-source DAST tool designed for modern web application security testing. It provides an easy-to-use interface with agentic capabilities…

An API hooking framework for intercepting and monitoring Windows applications


A PoC exploit for CVE-2021-4191 - GitLab User Enumeration.

Extracts JMX endpoints from RMI registries and tests for unauthenticated MLet exploitation in Java environments.

Hybrid ML and heuristic-based URL phishing detector with real-time analysis, explainable confidence scores, and REST API for programmatic security…