
alibi
Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

Cross-check the views of your attack surface and find the endpoints that cannot corroborate each other.

PoC — symlink following to out-of-repo content disclosure via search_text in Gortex (GHSA-6vhf-4wcm-2r83, CVE-2026-87003, CVSS 5.5).

AI red-team platform. Autonomous LLM agents run a penetration test end to end inside a Kali container and write the report. LangGraph plan/act…

Tool for advanced mining for content on Github

Automated exploit toolkit and detection template for CVE-2024-21546, an unauthenticated RCE in UniSharp Laravel Filemanager, with WAF evasion and…

A wrapper around grep, to help you grep for things

Mind-Maps of Several Things

[Just for fun] Find exposed AWS keys (VALID KEYS ONLY) on github

NCC Code Navigator

Extract URLs, paths, secrets, and other interesting bits from JavaScript

Scans project dependencies for dependency confusion vulnerabilities and checks package owner email takeover risks across multiple registries (npm,…

PoC reproducer for CVE-2026-49097 (Apache Camel camel-irc): the non-Camel-prefixed irc.sendTo header escapes the HTTP header filter and overrides the…

Black-box WordPress vulnerability scanner that detects security issues, enumerates users, brute-forces logins via XMLRPC, and performs static PHP…

CVE-2026-63030, CVE-2026-60137, wp2shell scanner

Log4j 漏洞本地检测脚本。 Scan all java processes on your host to check whether it's affected by log4j2 remote code execution vulnerability (CVE-2021-45046)

Asset-wide detection tool for identifying jsPDF usage related to CVE-2025-68428 Detection only — no exploitation

Disclosure for CVE-2025-13339

Python script to detect CVE-2018-16858 vulnerability in target systems, enabling rapid identification and assessment of this specific security flaw.