
linux-smart-enumeration
Linux enumeration tool for pentesting and CTFs with verbosity levels

Linux enumeration tool for pentesting and CTFs with verbosity levels

LSB steganography tool for hiding and extracting data in BMP/PNG images and WAV audio files, with built-in steganalysis detection for bitmap images.

Crypto tool for pentest and ctf : try to uncipher data using multiple algorithms and block chaining modes. Usefull for a quick check on unknown…

Educational lab environment demonstrating SAMLStorm (CVE-2025-29775) vulnerability in xml-crypto library. Includes vulnerable SAML service provider,…

a critical Remote Code Execution (RCE) vulnerability in React Server Components (RSC). It also includes a realistic "Lab Environment" to safely test…

Multi-cloud vulnerable-by-design environment deployment tool for practicing detection and exploitation of cloud security misconfigurations across…

GUI-based RCE exploit tool for React Server Components and Next.js (CVE-2025-55182). Supports command execution, memory shell injection, reverse…

Django-based CTF blog platform with integrated CVE-2021-35042 exploit tool for learning web application security and vulnerability exploitation.

Automated JWT security testing tool that exploits known CVEs, tampers with payloads, performs JKU/X5U injection, key confusion attacks, and verifies…

Educational PoC exploit for CVE-2025-55182 (Next.js Prototype Pollution) with interactive web CLI, single-command mode, and reverse shell for CTF and…

Fast firmware analysis tool that identifies, extracts, and analyzes embedded files and data using signature scanning and entropy analysis, re-written…

Proof-of-concept exploit for CVE-2025-8110, a Gogs RCE via symlink file-update API. Authenticates, injects malicious git config, and triggers a…

Proof-of-concept exploit for CVE-2025-8110, a Gogs RCE via symlink file-update API. Authenticated attacker overwrites .git/config to inject…

Automates setup of binary exploitation challenges by patching ELF binaries, fetching matching linkers, unstripping libc, and generating pwntools…

:triangular_flag_on_post: A CLI tool & library to enhance and speed up script/exploit writing with string conversion/manipulation.

Quickly Extracts IP's, Email Addresses, Hashes, Files, Credit Cards, Social Security Numbers and a lot More From Text

:snake: A toolkit for testing, tweaking and cracking JSON Web Tokens

Comprehensive cryptography toolkit implementing classical ciphers, modern symmetric/asymmetric encryption, hash algorithms, encoding schemes, and…