
Modules
Modules used by the Havoc Framework

CLI framework for deploying and managing serverless applications on AWS Lambda with YAML infrastructure, local development, and multi-language…

Fork of laravel/framework 10.50.2 with CVE-2026-48019 (CRLF injection in default email rule) backported into ValidatesAttributes::validateEmail.…

OWASP Raider: a novel framework for manipulating the HTTP processes of persistent sessions

CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens.

PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2

The most comprehensive authentication framework

Framework for Man-In-The-Middle attacks

A attempt at cryptographic framework for Baochip-1x .

Advanced phishing tool combining OAuth Device Code authentication flow with QR codes to harvest Microsoft authentication tokens via MFA update…

CVE-2025-1868: Advanced IP Scanner & Advanced Port Scanner NTLM Leakage HTTP Tester

LiquidPoll – Advanced Polls for Creators and Brands <= 3.3.68 - Missing Authorization via activate_addon

CVE-2026-8206: Kirki Customizer Framework - Unauthenticated Account Takeover (CVSS 9.8)

APOLOGEE is a Python script and Metasploit module that enumerates a hidden directory on Siemens APOGEE PXC BACnet Automation Controllers (all…

Bug-bounty audit scripts — API key validation, OAuth misconfig checks, password-reset auditing.

Metasploit module exploiting arbitrary file upload in Greenshift WordPress plugin (CVE-2025-3616) to achieve RCE via MIME spoofing, with…

Implementation of the Google Zero-Knowledge library for Identity Protocols.

The Secure Coding Dojo is a platform for delivering secure coding knowledge.