
CVE-2026-1357-POC
Automated exploit tool for CVE-2026-1357, an unauthenticated RCE in WPvivid Backup & Migration. Scans WordPress targets, bypasses WAF/403, uploads a…

Automated exploit tool for CVE-2026-1357, an unauthenticated RCE in WPvivid Backup & Migration. Scans WordPress targets, bypasses WAF/403, uploads a…

Python-based Discord RAT with remote command panel for webcam capture, audio recording, keylogging, file exfiltration, and persistence via Discord…

🔪 Dumper & ripper for Telegram bots by token. Forensic CLI tool with web interface

Searches and parses plaintext passwords from public breach databases (ProxyNova COMB) by keyword (user/domain/password), with proxy support and…

LeakScraper is an efficient set of tools to process and visualize huge text files containing credentials. Theses tools are designed to help…

Reddit OSINT by username. Discover indexed posts, comments, deleted and live content, activity patterns, exposed identifiers, and an overall exposure…

Spider entire networks for juicy files sitting on SMB shares. Search filenames or file content - regex supported!

a recon tool that finds sensitive data inside the screenshots uploaded to prnt.sc

A Powerful Penetration Tool For Automating Penetration Tasks Such As Local Privilege Escalation, Enumeration, Exfiltration and More... Use Or Build…

Find interesting files stored on (System Center) Configuration Manager (SCCM/CM) shares via HTTP(s)

A tool written in python for scraping firebase data

Physmem2profit can be used to create a minidump of a target hosts' LSASS process by analysing physical memory remotely

A CobaltStrike toolkit to write files produced by Beacon to memory instead of disk

OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar

Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports…

Linux post-exploitation agent that uses io_uring to stealthily bypass EDR detection by avoiding traditional syscalls.

PowerShell script to exploit CVE-2023-23397 by sending or saving malicious Outlook calendar invitations that trigger NTLM credential leakage via the…

🎩 🤟🏻 [P1-$10,000] Google Chrome, Microsoft Edge and Opera - vulnerability reported by Maciej Pulikowski - System environment variables leak -…