
apiscope
An API hooking framework for intercepting and monitoring Windows applications

An API hooking framework for intercepting and monitoring Windows applications

A Burp Suite extension that brings full DOM rendering capabilities directly into Burp, enabling effective security testing of modern JavaScript-heavy…

Reproducible A/B lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced)

Burp Suite extension to extract and collect GraphQL API endpoints from HTTP request history for security testing and reconnaissance.

50+ detectors across 10 categories, with continuous monitoring built in: schedule recurring scans, get alerted only on new findings, track your…

Go-based MITM HTTP/HTTPS proxy with HTTP/2 and HTTP/1.1 interception, local CA/per-host cert generation, CONNECT/WebSocket tunneling, disk caching,…

CVE-2026-34910/34909 — UniFi OS unauth RCE + file read via ..%2f auth bypass (CVSS 10.0, KEV, Mirai ITW)

find sensitive data leaking from ServiceNow instances.

Apache APISIX Remote Code Execution (CVE-2022-24112) proof of concept exploit


The Super Vulnerable Java Application (SVJA), as demonstrated in the Roniel and DaRon Podcast Show, is an Apache Struts application designed to…

Code for paper "ActBench: Self-Evolving Benchmark of Behavioral Safety in Cowork Agents"

API Scraper Agent for Web API's

Burp extension for wordpress security scanning

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.

CVE-2018-25031 tests

Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…