
pacu
The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

The AWS exploitation framework, designed for testing the security of Amazon Web Services environments.

Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and…

Real-time geospatial OSINT platform aggregating flight, vessel, and satellite data with dark web search, social media dorking, and AI-powered…

Track and analyze Twitter data without API access using web scraping, with support for user, hashtag, and location analysis via a Flask web interface.

Declarative web crawler using XPath expressions for concurrent, deterministic web graph traversal and structured data extraction with streaming…

A Telegram Mass Surveillance Bot in Python

Automated OSINT framework for reconnaissance, data harvesting, and threat intelligence gathering with modular crawlers, scanners, and extraction…

CLI tool for structured Telegram OSINT data collection. Scrapes members, messages, invite links, and user metadata from public/private groups,…

High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.

Hinge Dating App SDK for python for lonely bored SWEs

Monitor large transactions on Polymarket and Kalshi prediction markets with anomaly detection

Scrape and download TikTok video posts, user profiles, hashtag trends, and music feed metadata via CLI or Node.js module. Supports batch downloads,…

A python exploit to automatically dump all the data stored by the auto-completion plugin of Ametys CMS to a local sqlite database file.

CLI scraper for 4chan boards with keyword, date, and reply-count filters. Supports image downloading, proxy connections, and log output for targeted…

Real-time OSINT dashboard aggregating 7 live data sources (aircraft, vessels, seismic, fires, weather, events, news) with correlation engine, scored…

An advanced Twitter scraping & OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a user's followers, following,…

Stored XSS exploit for Roundcube Webmail ≤1.6.6 (CVE-2024-42009) with zero-click email exfiltration via CSS animation event handlers. Includes SMTP…

Unauthenticated RCE exploit for Kestra via auth-bypass; creates malicious flows to execute arbitrary OS commands, with options for reverse shells,…